URLhaus Database

You are currently viewing the URLhaus database entry for http://mysql.flypig.group/index-hold/fjY/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:301068
URL: http://mysql.flypig.group/index-hold/fjY/
URL Status:Offline
Host: mysql.flypig.group
Date added:2020-01-29 09:41:10 UTC
Last online:2020-02-10 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-29 09:42:05 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:12 days, 0 hours, 45 minutes Bad (down since 2020-02-10 10:27:55 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31invoice-VDN885_736371478.docdoc e01b9d1ec39ab6b746fab54011b045e107974f3d979db52766632eec495d9b59Virustotal results 20.31% Heodo
2020-01-31invoice_UBOJ8_54509461.docdoc fc244aba71a46c59805f50c5e9bfbed39277b6c94199062748330ab074a89a11Virustotal results 20.31% Heodo
2020-01-31Invoice_6115_329619.docdoc 1fdae9fc6aa69ff362c050d3b72b7ea035f4347be47b332d1cf733a6a60ebf62Virustotal results 20.63% Heodo
2020-01-31Invoice HRH77_085876017.docdoc 943444f98f1bb22118cddf2198722733aa216ad0aa313ece459ae6e268a9e2c0Virustotal results 35.48% Heodo
2020-01-31INVOICE_E693_581796488.docdoc 813226187f75c12909c10d00dfafe96c916ad768979a68def760048753fdea9eVirustotal results 34.38% 
2020-01-31INVOICE HGGI7852_9635595.docdoc 8a06475b5843111147926b32b1aecdad3780400157cfae38379d64a78b36139fVirustotal results 33.87% Heodo
2020-01-31invoice-U13_662162.docdoc 5cc9b80f9de781a2bc9717ed8ae9323422aeedca1df3e663869ed6a168f1986dVirustotal results 33.87% Heodo
2020-01-31Inv-EROD550_753471209.docdoc 1c2d2dcc9e0140fd9e9055a697ec4c2c969590ba93a2f5ebf75bde37cc7ba0f1Virustotal results 33.87% 
2020-01-31INVOICE_TG179_245597.docdoc 1092c9cc1b0dbf643c81898c30d3034b4db59f49a86de85ced39a5315ce4549eVirustotal results 35.94% 
2020-01-30Inv BAUQ19_6534750.docdoc 228960ea68978d82cf8f245946c0522095c90c78bd4a188a620e87d306c2619aVirustotal results 34.43% Heodo
2020-01-30INVOICE_RF098_42108335.docdoc 8aa2f0d5d11a3aedd257f45c6768e0c8af5a1473436c6e956d5455494349ab8cVirustotal results 34.38% Heodo
2020-01-30Invoice VW586_70056244.docdoc c2f41be5de64b96803bc308b3839583b6a786b8bb404aa5e2c775b595272e2e2Virustotal results 34.92% Heodo
2020-01-30invoice_12_586733.docdoc ad23200b4b35cf861876a41444203cb74f57e2be7bfddbc92b3fc7a07ecfe056Virustotal results 34.38% Heodo
2020-01-30Invoice_UO857_932633.docdoc 9d23b6da889229ad96e4d4ac90dd6c382fca9006273b8de6254bd3fe1415f403n/a Heodo
2020-01-30Inv_SNQ0975_968340481.docdoc 4b8c920544a36d2b2fe8e35aafddad4a1052e8cced8e159cf4b9753d1c1a82eeVirustotal results 38.71% Heodo
2020-01-30Inv-QOH1_9650211.docdoc 55f4b1324dcf648c873b70518a37777563890c60c108b2a3eb40eaa7f5f2f90cn/a 
2020-01-30Invoice AIB8900_4828228.docdoc 9e09d9765d276107e2b31f2d02ad5e09e72dd259f6dfe01401ec33ee1343f659Virustotal results 35.94% Heodo
2020-01-30Inv-XC28_486285.docdoc 9440498706f2d925d78ed85c677ee615fe3fdf05c7188cf59cadf543e59e0c32Virustotal results 32.81% Heodo
2020-01-30Inv 238_3926673.docdoc d1dcb4fa88a056a19af9634c99847a108027f1a0f5c3fc9d0219fc0f8d676b24Virustotal results 30.16% Heodo
2020-01-30Inv_P31_6317055.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 26.56% Heodo
2020-01-29INVOICE-BFQ7_078178.docdoc e14bd51bea91be160aefdfd75c853ce85ef348e87400f0d1e14b64c7d46eb748Virustotal results 33.87% Heodo
2020-01-29Invoice_GW90_929483747.docdoc 8f114fa9732298d525aa216d90905f24142f129d79e62500f139a3c09db00fd2Virustotal results 29.03% Heodo
2020-01-29invoice_MY3677_48301082.docdoc 4491676350c083084299affa5206946e8a9d6b63632f236d119e24cbd1239a38Virustotal results 31.75% Heodo
2020-01-29invoice-AQZ378_647212696.docdoc 7bfcb28623bb456b78495610797c508f2f0d900d9f5917557ef2e021b03f4349Virustotal results 27.42% Heodo
2020-01-29Invoice PGWG0205_34430755.docdoc 3025dd0f7c5bcce361eb76f350f7313e70bb8d2b908d2edf67b9494b934c8f7fVirustotal results 26.98% Heodo
2020-01-29invoice IVH7_635531564.docdoc abc1e31965fa6cf8716c4256ce70b73a84e8e2620a2bf5609581010eeba6b53eVirustotal results 25.81% Heodo
2020-01-29Inv_QPU312_704168492.docdoc ae350e475f5f34203313d523d6a5b8eec86357ef06ca6c9cc222d2c353506387Virustotal results 26.23% 
2020-01-29invoice-G8_8506768.docdoc 06b21d7aaf258ceb4137f8d4905cd3f83dd3be1789745f6fe45d6043564c95fdVirustotal results 26.23% Heodo
2020-01-29Inv-PP50_2182192.docdoc 992e6e5ceb5ec8864b03020268729a5498549bd9c9067fbed53b8f3ca5474142Virustotal results 25.81% Heodo
2020-01-29INVOICE E17_107828.docdoc e8f8cbc324e2601a0d32232c887aa398adfc45984b6a254666b95a1c00ef496aVirustotal results 30.00% Heodo
2020-01-29Inv 9467_68763702.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo