URLhaus Database

You are currently viewing the URLhaus database entry for http://headwaterslimited.com/wp-admin/NQr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:289934
URL: http://headwaterslimited.com/wp-admin/NQr/
URL Status:Offline
Host: headwaterslimited.com
Date added:2020-01-16 11:07:04 UTC
Last online:2020-01-20 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-16 11:08:05 UTC to abuse{at}hostrocket[dot]com)
Takedown time:4 days, 3 hours, 49 minutes Bad (down since 2020-01-20 14:57:10 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18Invoice-EQAM1_825355933.docdoc 2f90590da13be020cab94f6054224224af5d674bb07964796cbb051cef5dde3aVirustotal results 27.87% Heodo
2020-01-18Invoice UU3_606605551.docdoc c0ddf7ec4f4905aaafd9371d7d00d8bd21bf9f5d9d49403591e1cfbde36925ebVirustotal results 24.59% Heodo
2020-01-18INVOICE_8143_673023693.docdoc db670e32ccf692c3e85cf5a07e047bb337af24ad3de408d8894a3c0ca2b8c505Virustotal results 21.67% Heodo
2020-01-17INVOICE_BXM089_56353584.docdoc f95984ef535315242fca3fc45cb952c5918ca8fecb789f8a803e4e1471a25c94Virustotal results 22.95% Heodo
2020-01-17Invoice-CPP9530_129590071.docdoc b09c1b973c6ca799fe7817c241a0a1c56f907feffe6ecd63daa615be18c7b077Virustotal results 20.00% Heodo
2020-01-17INVOICE OYC4406_978486.docdoc 562abea095cfa78a34b3896d0d1c23bb11525f5c7691852026b0aaa3d97151c8Virustotal results 19.67% Heodo
2020-01-17Invoice-VMBE6_949398.docdoc 3f227c11e8835a6cb877438bf4628c9b105553fa1fc681389fcf5bd5574dcfa0Virustotal results 19.35% 
2020-01-17invoice-KSRZ23_154308.docdoc ba41ad73fcdce6b4e813741379ada938bdc3b9f751255d0f38bf9e39833dd000Virustotal results 23.33% 
2020-01-17Inv EIJM818_450279.docdoc 210a6a37775d925d838f75b9b8c15635f4b9a2fecade8e4b1f6fedacdc428c72Virustotal results 22.58% Heodo
2020-01-17Invoice_FCH3_499584757.docdoc 127fbb144e09a37a3fb74478730d2c431fc0876897035497e7dce1c49d3d539fVirustotal results 20.00% 
2020-01-17INVOICE-DCN92_8906123.docdoc 298a10ce8a9fe8dcc5947d02585a549d1c9d0609c7d11473ff4c8dfbb3a9f801Virustotal results 21.31% 
2020-01-17Invoice_SM8_81523429.docdoc dd16805945f08b66a472325c92bdb3d2a2568f1741453e6d5249a2532c721232Virustotal results 18.03% Heodo
2020-01-17invoice_2_85246895.docdoc 6a30e995f8d4b431a06066f77625efb700c679b72dd760d573016bfb6c391a87Virustotal results 18.03% Heodo
2020-01-17Invoice CYKH93_78725012.docdoc a841b264457a4ff7ff83a9b12a0f80c9902edff2f134497e5906e16a3b5b77adVirustotal results 19.67% Heodo
2020-01-17INVOICE-YOU1318_51142973.docdoc c682de9b99812ab7c470a026d17e1060364b9bf4e1890d733b05ef312452f8d8Virustotal results 19.67% Heodo
2020-01-17INVOICE-YD0211_86773686.docdoc 72e668b37382f89e2ca769002432f8795a29663a6d98d1e2ad158c6cc13f3794Virustotal results 19.35% Heodo
2020-01-17Inv-NT957_5754852.docdoc 81e67b1fefc9adfcf367364590a04c14a8b109dafe04e935412b4f8c82ed5f64Virustotal results 19.67% Heodo
2020-01-17invoice-BO9_057131641.docdoc 30c567c6efb9fbfe69f1689efbf61d25a4e8eb9c44018602a7bbbb699505ddb1Virustotal results 19.35% 
2020-01-17INVOICE-QF3_264349870.docdoc e54979318c06a7cc3d8fb5f00d32d0fa2a169f8447a224ec8822749071c550f6Virustotal results 37.10% Heodo
2020-01-17Inv-RKTF3101_3130616.docdoc 197af116115110512c62798ebf269522be366efda960b47d38c99064a6d9f373Virustotal results 37.10% 
2020-01-16invoice-BJ3_0093107.docdoc bb4020e88ad04a6388b6b9e8ff83bb890bfe825f0927d15e8efe19b3c506f59cVirustotal results 36.07% Heodo
2020-01-16INVOICE-7_7699253.docdoc 443e433f060461b09207bb30cb7b5cdea7f4b53176d4554a94524b25f0e984b3Virustotal results 34.43% Heodo
2020-01-16invoice_WQG90_1285460.docdoc 6181d694653add4a58a2dc8535371c420cf35014cb78f8ed1447986900fd103bVirustotal results 35.48% Heodo
2020-01-16Inv_RICD0099_025008215.docdoc d138359ab7543bbfedd4895fb0e815b5a41453c87e601a5a4ab2d04363a3aec0Virustotal results 31.15% 
2020-01-16Inv_7_161711.docdoc bb26c71a0583d024ba82776f408a57eba39ca86dd7c403c127aeb747e83fde9bVirustotal results 31.15% Heodo
2020-01-16INVOICE_D112_03544703.docdoc 3733fb5c12eb91bf990e79b83409042accf206318cc69a2ba170c69a7fa2da30Virustotal results 30.65% Heodo
2020-01-16invoice_BQ956_36995115.docdoc 10a9ecd17e41685a7887e61d9f954dda1fb10b88f63108e0fa658862eb6350ebn/a Heodo
2020-01-16Inv D1880_362617.docdoc 8d08c64109af9505b6c11a3290ec23b392dbbb001faf7a0e568b4b31ab1eb138n/a Heodo
2020-01-16invoice-DAZ7_299853.docdoc b44638c59970903aff549cbdb9555ba334f7471ff807475bb8e1713cfa35b0afVirustotal results 29.51% Heodo
2020-01-16INVOICE_MAVH7727_748198.docdoc 8fa8afbec1406fdb512b5830336edd4933a2900bb41a779acbc6193898392b55n/a 
2020-01-16INVOICE-8263_308601.docdoc dd749bb3c949f637fa1cfd7c91e112d1216bfb350a0c795270491d04fff7d9e0Virustotal results 28.81% Heodo