URLhaus Database

You are currently viewing the URLhaus database entry for https://shagua.name/xjj/si71lzgq3foh_xd5gk3jbfh4_sector/security_46368467_TxCfHmU20ReM8/704771606906_OMTJJd7rs6XGGI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290418
URL: https://shagua.name/xjj/si71lzgq3foh_xd5gk3jbfh4_sector/security_46368467_TxCfHmU20ReM8/704771606906_OMTJJd7rs6XGGI/
URL Status:Offline
Host: shagua.name
Date added:2020-01-16 22:58:10 UTC
Last online:2020-04-18 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-16 23:00:03 UTC to ipas{at}cnnic[dot]cn)
Takedown time:3 months, 2 days, 6 hours, 28 minutes Bad (down since 2020-04-18 05:28:23 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18578201.docdoc fb680f476f064419b4c691854253bfbed052197faafca93d027f487c8de86785Virustotal results 43.33% Heodo
2020-01-18UNTITLED 9336374117.docdoc 5bb8b7197cc1e9717f275644d2d24e4c332776ec9da58322e3d1520bf2d18e55Virustotal results 43.55% Heodo
2020-01-18Untitled 060.docdoc 7e6a4bbd6980416fdfb0a0a4f640f34c9b85b3d591e02d2e6c25fe0b1952b493Virustotal results 40.00% 
2020-01-18UNTITLED 7559837_13942.docdoc a199f7115c7a50f782bdd9c055313c4b7488b0220779f0bf60d8bc57a05588e5Virustotal results 38.33% Heodo
2020-01-18Attachments 52711448_9989.docdoc 723e18efedff5086e5ee078490176f0c7e408ebec167c0ee458c9976c3745a48Virustotal results 36.07% Heodo
2020-01-1855427.docdoc 8ec7b546faca87b18192561fdbe4f11954c88dcc3fe617bf340f27821d6d4989Virustotal results 33.87% Heodo
2020-01-18Untitled 0701.docdoc 0725c7fdaa743d5e01fa2f8ac36988c0210db3d037aff2b46b649d1d8c359ec6Virustotal results 26.23% Heodo
2020-01-18Untitled 7424603284.docdoc 05ed49924f9a734be2613850bc14127dd985d33127bb4974abe4141032765d35Virustotal results 29.03% 
2020-01-182175130830_075.docdoc e727d11b8218fe3115606fc4fc0cd4affe8bc9530fa7e629a19380988ba2d761Virustotal results 23.33% Heodo
2020-01-18UNTITLED 1741591.docdoc 382d4b003341ac1a0515f9034bbc23810f761be5352f3d7879cc42a688d7faa7Virustotal results 27.87% Heodo
2020-01-17Untitled 041-70321460.docdoc 64d2bf29b115ca3491e65a4f38b7cfde374784f32974d328d40552abaddb8eceVirustotal results 19.35% Heodo
2020-01-178927841_9852.docdoc 662c45aa9a011fd5404b6d5ea8d2bb53a0b723d8fcdca58a66dc66aa6561b0eaVirustotal results 20.00% Heodo
2020-01-1702141.docdoc d293b2b91bd68c8b8ae7dae6cdbbcac02a533dd9256195096f026bd42d896b7dVirustotal results 19.67% Heodo
2020-01-172878.docdoc e7c83acc1f74cebdaccbfd1af1697b358dcc86a93cc49a977602623a237a7b6bVirustotal results 19.67% Heodo
2020-01-17073979_085.docdoc 7c00f98b5ef5a762e53d392dfe229f00db813cf40ee114c3406c084f1474454fVirustotal results 21.67% Heodo
2020-01-17Attachment 418886-1364071117.docdoc 5a0bb9b15555a25dc31379feede50b11df32b3fdcb7fa379d4e0a04fab25a7dfVirustotal results 20.97% Heodo
2020-01-17Attachment 5392469293_198652.docdoc 14bb34f9809c158815060a077bfd7fd2c0f71ba0feb346eb5b9c65604354f35cVirustotal results 21.31% Heodo
2020-01-1770083473_718183.docdoc 3757bd463ec512f0a037483f880bfb599a9ce216a0c71f00197e8cef071855b3Virustotal results 19.67% Heodo
2020-01-171242-668472608.docdoc 4926c006521338ee85d1c82e53db2c39908c6e427d7570cfda91eebfd40b04ebVirustotal results 22.95% Heodo
2020-01-17Attachments 2082.docdoc ed3f5dfbda732c80c2f439ff47c8c6d45ce5215d5cca1ad8765c955395cc6881Virustotal results 23.33% 
2020-01-17Untitled 85788.docdoc 66fd8c3206bd81f95b0a4b9937a3c6c4558b30bc4bacd85f9265f94f2cb0213fn/a Heodo
2020-01-17Attachment 2918161016.docdoc f6a634c9998a0d1b36562b23d5956f5f3da1369c9827c9cb198856ef2197ea35Virustotal results 18.03% Heodo
2020-01-17Untitled 363985-7982130375.docdoc 0910756013c93bd04bb0df0b501ac958c61e561bf65b445b4b0a56e597a1310cVirustotal results 18.33% Heodo
2020-01-17Attachment 06776402.docdoc 70bc9fa11de427443cc32fe5c68e424ce770562ef9fb622d232b78b67c6e6d99n/a Heodo
2020-01-1742554134.docdoc 17e6fbbc141f6b7e27df7ddeb423b4aee5adfecd80db00b9990b85ca7d75fa88Virustotal results 18.64% Heodo
2020-01-17959349811_97503.docdoc 5cfcfd2674e95e2d29ba8fed8516b1eae2601ebba05a93287d6b29d041d4dc5bVirustotal results 44.26% Heodo
2020-01-17Attachments 471560-164446797.docdoc 142c2efda50596eb5d5e050338142a7c86a5030a0c4bd1095bb30cbe0f722e1eVirustotal results 40.98% 
2020-01-172404-885162757.docdoc baff02e524a1dc5e3aa3c7d79cd378bc8c858c899d1e25e75b0c13bfcbeb48feVirustotal results 40.98% Heodo
2020-01-17UNTITLED 872.docdoc de8f84ced2a3a6a85aeb9ff016c38d519a51898a16fb059a6555f9df453c4595Virustotal results 36.21% Heodo
2020-01-174595227.docdoc 49a2ab600f53f77b09bf90962731f7559940c6dba4c5151d67ff9bd581082d9en/a Heodo
2020-01-16430.docdoc f942462b771aaec7fb9e1bb8fc3eeeed0fa6c2b229eb6950b8135afa16403305Virustotal results 37.10% Heodo