URLhaus Database

You are currently viewing the URLhaus database entry for https://watchshare.net/wp-includes/8go-ul4h-490923/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299620
URL: https://watchshare.net/wp-includes/8go-ul4h-490923/
URL Status:Offline
Host: watchshare.net
Date added:2020-01-28 07:35:07 UTC
Last online:2020-02-02 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 07:36:04 UTC to abuse{at}online[dot]net)
Takedown time:5 days, 6 hours, 17 minutes Bad (down since 2020-02-02 13:53:26 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29invoice-3033_6731539.docdoc 0e7d6a780c7dedc2d2625158cde219a2df7eb7b37a509c810644085e1781eb12Virustotal results 29.69% Heodo
2020-01-29INVOICE-D76_563791873.docdoc 3bdbcccc69e55ca69203cb80868675eb9aed4e2e9f880d181e51bb341905b8b7Virustotal results 28.57% Heodo
2020-01-29invoice_V7_021345359.docdoc 8a502f32c4e9b027761b883615a99071262858fe124e0f76a51ee65583ff4c59Virustotal results 27.42% Heodo
2020-01-29Inv LWR69_900491.docdoc 7522a47f398818f54f95582e8d122a7bbd81f69c9807cc61fa12d0fc15a2e39bVirustotal results 27.42% Heodo
2020-01-29Invoice-R946_7988747.docdoc ae350e475f5f34203313d523d6a5b8eec86357ef06ca6c9cc222d2c353506387Virustotal results 27.87% 
2020-01-29invoice CCT5595_480333736.docdoc 603a04c67b941a3ff9345c94e890896e5570dd544e8ca3998f5197f45ab28f00Virustotal results 26.56% 
2020-01-29INVOICE-9_336332.docdoc 19f29957bde797c4505244aec4c78ca3ff7e264967215abd6444d9f7c31da7edVirustotal results 25.40% Heodo
2020-01-29invoice 811_562102272.docdoc e8eb03b874c14f0429931aa7f367e9b480b593c28963c964049ea04f6670caf9Virustotal results 30.16% Heodo
2020-01-29INVOICE-TZK0253_688928.docdoc 7cbcad4d6e9ad8438e5febd3830bff9aef4729b98d23935ad7f9e6d290272732Virustotal results 32.79% Heodo
2020-01-29INVOICE_ZDXM0_70786648.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29invoice-R72_87234328.docdoc f51d2aa766b1b07701a52e866f50132c0fcfaad288c1aaf13c781a66db3168daVirustotal results 47.62% Heodo
2020-01-28INVOICE_22_264387.docdoc ed6f25f194f984aa989e3171a6be8991cf7f533e4e96f4bba8b21d6c2e7b8cb0Virustotal results 25.40% Heodo
2020-01-28Inv_A026_884188.docdoc c17c75821c89a7ad0099092a5b55fcc514e74124e43e60fcf669de6436453b82Virustotal results 23.44% 
2020-01-28Invoice-ZDI2_9399796.docdoc c72d3a18baf0023ac80353b06452c4fd43e003247f97c3aa98cee47b2f4bc27dVirustotal results 25.81% Heodo
2020-01-28Invoice_VT672_97656773.docdoc 160fe2d4287a96770020461a685816eb0d9ba8b3a3275b86f708784b778f380eVirustotal results 22.58% 
2020-01-28Inv-BGFY89_8659926.docdoc a458b04b14f8cb2b9c8c9aa525e5f16e80fefbf4c0f91a18d25af97f328841abVirustotal results 25.40% Heodo
2020-01-28Invoice-5917_890081.docdoc a6b9f25b3f632a071e548d1e092d8557eedd074094e5e1a2dd684a724fb07fe6Virustotal results 26.98% Heodo
2020-01-28invoice-FTOB4_05337544.docdoc 32a27468a4355d462e5de6e29290189f023ad6b51836d3134dcb19a74f615f51Virustotal results 25.81% Heodo
2020-01-28Invoice-87_300619.docdoc fad431f81e098efc657ea4c9787427f6080e70ef1ea7631dbf51f35578e79438Virustotal results 26.98% Heodo
2020-01-28invoice-NB9001_779538.docdoc 10110ba02728cd33f942639ed9af5ef77659f31b95631ef77803c3e8b97d72efn/a 
2020-01-28INVOICE-QI6378_02291470.docdoc 84e58656a3220edb66d39216830f1c47b2c8743c6e3e37e52a23f8d6b180a071n/a