URLhaus Database

You are currently viewing the URLhaus database entry for http://shatabbytek.com/wp-includes/multifunctional_zone/guarded_area/kcd70_9y8z0u35/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299398
URL: http://shatabbytek.com/wp-includes/multifunctional_zone/guarded_area/kcd70_9y8z0u35/
URL Status:Offline
Host: shatabbytek.com
Date added:2020-01-28 02:33:06 UTC
Last online:2020-01-28 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002281055 created on 2020-01-28 02:34:08 UTC)
Takedown time:12 hours, 41 minutes Good (down since 2020-01-28 15:15:51 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-28Doc 20200128 MP48415.docdoc 45f4837dd3c4164db2df0fc600696eb225eff9a66e0dadffa9ff07c9f797a8e6Virustotal results 22.58% Heodo
2020-01-28LIST.docdoc 267aa23c9031b06e6dc7fac45daca30a65d4f08843fe0976c2ad7201d9646dafVirustotal results 28.57% Heodo
2020-01-28list_20200128_C213939.docdoc e3ba2559956e5915407cc1fb85cbb6d4a50bfb9d028a5ba9dd33505953aa5ddbVirustotal results 29.03% Heodo
2020-01-28file 20200128 527949.docdoc fccf3876128e78c8d3a6385aa312b1333c822a2b9efafb26daf1d2ffea296d59Virustotal results 25.40% Heodo
2020-01-28file_328442.docdoc 68938178a947046088472c9c687caf7843271233fbba2b888ada13c2bb5a5e5cVirustotal results 22.58% Heodo
2020-01-28file_NQ470385.docdoc c5666d80df3d2361122568d511e336c58a58b27576a1cd78b434c425d8b2e809Virustotal results 22.58% Heodo
2020-01-28Arc_475.docdoc 256954bf735b73749d5fd67afbf6e789abb356f02cec192954e129996801d642Virustotal results 22.22% Heodo
2020-01-28REP 20200128 94206.docdoc 9cb664f1e4189925744979c21e305e2af11f98b2fedd6d32c4e3d5745b51ce07Virustotal results 22.95% 
2020-01-28LIST A25276.docdoc ae1c2a1ebc838f4092123a0fed626a10f1325e7796629f6d370111fd50d8154dVirustotal results 22.22% Heodo
2020-01-28FILE-20200128-709.docdoc 0827a2ab4aa1c0caddd493489b6197943bc03b6da0d9f52c54071449dee6538cn/a Heodo
2020-01-28dat.docdoc 20cdcb97c92b8c58397ab1170823f96ce0db2c3e93d4859bd06fb23302687d30Virustotal results 41.27% Heodo
2020-01-28arc_2020_01_28_831.docdoc f79992105131cff7dd4570db1648129b246323085d2843087e402a966d52503aVirustotal results 41.27% 
2020-01-28INF.docdoc c37742802393d60152b9ff4dc3ce0da8428959d7a589768b43e58478ddf4fbfen/a Heodo