URLhaus Database

You are currently viewing the URLhaus database entry for http://mega-shop.paditech.com/l5xifq/gcgpo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:298693
URL: http://mega-shop.paditech.com/l5xifq/gcgpo/
URL Status:Offline
Host: mega-shop.paditech.com
Date added:2020-01-27 09:52:05 UTC
Last online:2020-01-29 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-27 09:54:02 UTC to abuse{at}digitalocean[dot]com)
Takedown time:2 days, 2 hours, 5 minutes Poor (down since 2020-01-29 11:59:27 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29INVOICE_627_03448675.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29INVOICE 990_611038167.docdoc 0d59daa51eb7228797a0ca35d46c6419936ef4df01bdfe603db22aa45a7ad0eeVirustotal results 47.62% Heodo
2020-01-29Inv-OAA9034_40486129.docdoc ce585ca3bbc24cf3e93360b57e2f8f9574cd89823963cd35ae08bb6a252d682fVirustotal results 46.88% Heodo
2020-01-29invoice PNAF447_506009786.docdoc 0a84308348fee6bbfe64a9ef23bb9c32cb319bcdf5cf78ddfda4a83dadea4b8eVirustotal results 45.31% Heodo
2020-01-29Inv_VW8_56691551.docdoc 32753598f94412fe3dc382dc12dcf2edf7881d9f07814c82aeec36481b9362b5Virustotal results 46.03% Heodo
2020-01-29Inv-YPUH8_211732674.docdoc ea3a0a223474592635d1fb7a0731dd28a96381ad2562e3e064f70e2d4830c39dVirustotal results 49.18% Heodo
2020-01-29INVOICE_463_14381469.docdoc 255b6d2d7740a61962ad81bf302187f984dcefe57edd825c67985e7c4425e205Virustotal results 51.61% Heodo
2020-01-29Inv-Y3_02613927.docdoc 1fe8cea2fabc31ad37931e33bdba652c012489533daa90a699e3aee3b8d75b91Virustotal results 49.18% Heodo
2020-01-29INVOICE 498_220493.docdoc 0d1de45954adee600bf2a41e5b1de25ba4ead4b3938d1c987f6bdf8e48fb9a42Virustotal results 43.55% Heodo
2020-01-28Inv BEZM578_6116921.docdoc f9a330484e52de8ab57a920eb93d6308dd150ba0001e7ba7cfb2a50edfec5ca0Virustotal results 43.55% 
2020-01-28invoice DD0784_26926424.docdoc 9e9d8e60ea0a7b028513b69e3f41360a4d6a4be4ec05af3fae645bcbca37f827Virustotal results 42.19% Heodo
2020-01-28Inv M489_565762.docdoc b7109568a2beba7e63236e9fae5d014d43ea3164de3e4149790c89356b10766aVirustotal results 39.68% 
2020-01-28Inv_VMU871_446373.docdoc 85e978955f2d5b46e50d3a259f837643be8e5b3e0c643465881342f1cc7f3d31Virustotal results 35.48% Heodo
2020-01-28Invoice KCMC9_93988846.docdoc e8c780bbb1f9fd071b00776b138b3cf27c3815c7203593068e78774d4dbdb36an/a Heodo
2020-01-28INVOICE-FYD9_1639507.docdoc b351412551b1d480fe50603de72c1d23a0afa22991461d2b812edbf5ad7d6021Virustotal results 25.81% Heodo
2020-01-28INVOICE VEHA175_716162244.docdoc ff71f06910cdebceb665fef3861262fbabd9f92ebd7285926a1b3d4ed3a7c166Virustotal results 26.67% Heodo
2020-01-28invoice LFB9_863662.docdoc a7cd0e0d4371256091f7a81ff6100974822424c0c06e2dd5e07956b1ab62c19eVirustotal results 24.19% Heodo
2020-01-28INVOICE MJVH06_200735151.docdoc 9db28f01c7a26ba6a757542ddb44145a167395b639df0eac4d9f48a926d8f810Virustotal results 22.95% Heodo
2020-01-28Inv_M370_958061521.docdoc a6b9f25b3f632a071e548d1e092d8557eedd074094e5e1a2dd684a724fb07fe6Virustotal results 26.98% Heodo
2020-01-28Inv_353_893093770.docdoc 32a27468a4355d462e5de6e29290189f023ad6b51836d3134dcb19a74f615f51Virustotal results 25.81% Heodo
2020-01-28Invoice-JML4_116579.docdoc fcdf9154d769d5e1f3935355b39b57010d978fd2dc9ad24a1df12131f7d34155Virustotal results 26.56% Heodo
2020-01-28INVOICE NH305_316867.docdoc 5de69dc108e73dca8473f765ae9d54df950da922d58d6950a7ee5a8d0470be85Virustotal results 23.81% Heodo
2020-01-28Invoice PDYC101_933072444.docdoc 69e19219795fcc89a44dc863d7b1c970f92a785afb3c7bfe3923562119c32adeVirustotal results 24.59% Heodo
2020-01-28INVOICE-SFFF104_1861488.docdoc 37f7008209b0cf19267afa8ccdab629b76f4bfa992d7f77ce2c098e5e473c8dbVirustotal results 40.32% Heodo
2020-01-28Inv-HFSH9_858545712.docdoc fbe992a68ce37d101a4005da5062aee9e868e5885fe5b4c69e69c0981c8eeaffVirustotal results 40.98% Heodo
2020-01-28Invoice_X3097_77218259.docdoc 6f7ef2942319a8f55b338d43ac0717e2999baaf867ba160e6cdc15c85b47a4e1Virustotal results 34.43% Heodo
2020-01-28INVOICE EZSL9_04646502.docdoc 4732690cf746cecd8bd49d095d5514cf185703860490402cc2a5cfbb9e3fadf1Virustotal results 32.26% 
2020-01-27Inv_NF57_23368073.docdoc 11c1f2089f30fba10c0d8e7a46d5b5a163acc645ae1ac899f9c1da16fd34d5cdVirustotal results 31.67% Heodo
2020-01-27Inv_73_39031581.docdoc cf6fc0c9b296a21a605c029d19eab5d466b785cdc4efb16d18963b598f82ccden/a Heodo
2020-01-27invoice_1_195968.docdoc b8234c3a29dfe136921812c6011604fac4f3860df104d73b44365fd690d34e17n/a 
2020-01-27Invoice_K10_1094534.docdoc 844e6dce32ab6c95097c5fd947761f9c4c47cd4a18f6f88e94b906eec219b073Virustotal results 21.31% Heodo
2020-01-27invoice-4_436762.docdoc b08e839fcaa91713751d0ce0fa1ed4f8bdd81ab3803347177886cfc3095440a1Virustotal results 25.40% 
2020-01-27INVOICE_LNVR0836_923353699.docdoc ff41ca3c8f2ec42a86f291c2cd1c4b023767b2b41782d20933cc96071bfb168aVirustotal results 25.81% Heodo
2020-01-27Invoice-17_832904.docdoc dfaa827439562eeff34e4ee725e9e1d19ecab21556134361ab102dbb7f41afceVirustotal results 22.58% Heodo
2020-01-27INVOICE-683_355399556.docdoc 2f53ea6777ed917ddceaa0c9f0150b3650efe7639066b4f0ecb1776c09a356abn/a 
2020-01-27INVOICE_S80_723343.docdoc 6cddcfd58c789c8db9ae41d6a91bf3070fa44d597a43db9d3726e6b7bf56a93cVirustotal results 26.98% Heodo
2020-01-27Inv-PBB7876_36122809.docdoc cd985cdc0263c68992ab45b3529e073a837632f1baeb93f3266229c38428ee3fVirustotal results 23.81% Heodo
2020-01-27Inv_LOGJ6_265339154.docdoc d4454c1408702289ee30645ef718fb792dc3c7c3a6473e97b2b608f40b8c6a63n/a Heodo
2020-01-27invoice_2_583584935.docdoc e6b9b81ce547eec06c402e08fd665a7426c66e956a6f2cc5ed510072bdbb4433n/a Heodo
2020-01-27Invoice_DED1_6562915.docdoc e5057bed23134edaa4a3dfcea7be4224621df200d63faddb53e0fb9a080cbaefVirustotal results 25.40% Heodo
2020-01-27Inv-B1_7503778.docdoc 83426e4068af9c457cfbb6b5bca7101f39126d52c3c5ea49f9964115e224592fn/a