URLhaus Database

You are currently viewing the URLhaus database entry for https://shagua.name/xjj/vNcts1QRe0-NJt7cc3-modulo//zIPilvMeg-D8Q2k2pUttt-zIPilvMeg-D8Q2k2pUttt/NJZv1p-2ze0zyzIr3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308893
URL: https://shagua.name/xjj/vNcts1QRe0-NJt7cc3-modulo//zIPilvMeg-D8Q2k2pUttt-zIPilvMeg-D8Q2k2pUttt/NJZv1p-2ze0zyzIr3/
URL Status:Offline
Host: shagua.name
Date added:2020-02-05 10:28:38 UTC
Last online:2020-04-18 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-05 10:30:03 UTC to ipas{at}cnnic[dot]cn)
Takedown time:2 months, 12 days, 18 hours, 57 minutes Bad (down since 2020-04-18 05:28:02 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-07oferta-F462308.docmdoc c59dc2c1dfeeb1396f7d5c6dd909f830da34247b35cb8610414414385eee6fb2Virustotal results 24.19% 
2020-02-07OFRT-p982mq5305.rtfdoc b78604080c721c59f488c01bc4ca9e86ac375242397666a738689216dccf54c7n/a 
2020-02-07oferta-02072020.docmdoc 8f3a0e19e00397efb39708dacfd129d2722146fa6d169e6a7c601c0cc02a1359Virustotal results 24.19% Heodo
2020-02-07Oferta 1716379235556.docdoc 5480139ad1a7d156879a92736b3feda1f6e9bb49c6b7bd8b92471e76e92fa60fVirustotal results 43.55% Heodo
2020-02-07OFRT-02_07_2020 73306861442877.docmdoc 88d2e0f1e728a7142e0fa0f277f4020c91bb5e4222ccfd8162d9e0b6beb60e5aVirustotal results 43.55% 
2020-02-07OFRT 02_07_2020_45316998.docdoc fdeb04909ae31e34780d50be105ea57867dbba4d1306ce1b536dcbf132d96772Virustotal results 43.55% 
2020-02-07Oferta MAA724218_8258266792.rtfdoc ed52942baf8ed14a9b9da31174f471dd978344583c83f0851abbbfa219f15167Virustotal results 41.94% Heodo
2020-02-07Oferta 2XH984924086954.docdoc 8e6abe5bf56e9dbda4b891c693256da6a372b0bff0aa7047df4be981134d8e07Virustotal results 36.07% 
2020-02-07Contrato-145946460673.docmdoc 9707abd47ef72798f3d0aa3c5f58c076f401350bb34bef7d5c7660108eab8e42Virustotal results 32.79% 
2020-02-07Contrato-8n09m0.docdoc 24cc00288998f8deb1ec06f90b3dc247584cff225033e281607b281525f98c91Virustotal results 30.65% 
2020-02-06OFERTA_02072020.rtfdoc 0b878e218014a87bc4674a3f8c7113b207cf3e3203ba565c9e3fcf62cb5f18d6Virustotal results 29.51% 
2020-02-06Oferta p133p6q94366503.docmdoc ac7760c7ac85f9e8058a9af1862e8b503ba18efe9bf1ebfc820845a33714ea8an/a Heodo
2020-02-06contrato_L7168.rtfdoc 0f9546ef0fe98af36e43a06ae58080335e7051c19f85fa72157d75d7e85f12c1Virustotal results 26.23% Heodo
2020-02-06Oferta 941539.docdoc 69caf04e8e1e56614bea23015c10066190147415d1c1699accdc79c49531cedbVirustotal results 29.03% Heodo
2020-02-06OFERTA 02062020.docdoc c1fa4e5776d22f5cdc7e606caee8781318ad35e5c43009b705d630d62f2fa3aeVirustotal results 29.03% Heodo
2020-02-06OFRT_02062020.docdoc 548c32e1f7c11d658a1b45cc341ea2480b28c86e352baf366289aaa70a9e9292Virustotal results 29.03% 
2020-02-06CONTRAT_3EB529634.docdoc 00810a12662ed1714ce797c700855a606ab35c246a1c1a2ada47b503d612a82dn/a 
2020-02-06OFRT 31p6p9m5.docdoc 6518e632fa6ae2b5961ba05d77e16bbec58ffabe10c6f79557a2d1b48b2807a6Virustotal results 26.23% 
2020-02-06CONTRATO_501316.rtfdoc 9d589a2e6c2556df3dabf97bfb5d53fbf92b2303d2b44b92b864eea6df244f80Virustotal results 26.23% 
2020-02-06CONTRAT 712p8m4172.rtfdoc 80f98a0cc63cfcab0ab3cd556448bab9023036aefdebd2eeaf9239f3df354bc4Virustotal results 23.33% Heodo
2020-02-06CONTRATO J008718364162.rtfdoc 6b1d90ff1212f95e6fb72180e90a64d316ee24b22f2803c46dedaca64ca09914Virustotal results 22.95% 
2020-02-06Contrato-02_06_2020 5A572561.docmdoc 6fb9d59fbb6b095e0d539b47649b868ec32360b9e6d115630fba8d061f93b6abVirustotal results 23.33% 
2020-02-06contrato-5Q053029774303.docmdoc 6359275fa65b551a691c324e03fa5c3c73ace835ca4f3d90087dc3332f76ececVirustotal results 22.58% 
2020-02-06CONTRATO-m569m0.docmdoc d0ba1020328bfa59129c6d94b6bfd8979bd652574b24407bcfdadc75fcf28fb4n/a 
2020-02-06contrato 7Y547025649.docmdoc c163d2a385feadd582c11612d2692072b57c78c665520df24672437a2bd549e1Virustotal results 21.67% 
2020-02-06CONTRAT_I5719557-8344.rtfdoc fa37e0cba4786db4ba847c2e4f9b4ee78aedbf0eea4491228705fc00980af4e8Virustotal results 32.79% 
2020-02-06CONTRAT_02062020.docdoc 346d01cf657414934f8c87af6f0ae07d23875f613db84e483f2174b6353ab405Virustotal results 33.33% 
2020-02-06OFERTA-3q899n403q8n0.docmdoc 84e6bb18fc4d5994987feb9edc02eaaec7cc0988b27845fb8735d3c45591e5cdVirustotal results 31.67% 
2020-02-06OFERTA_688307586519.rtfdoc 00788bb2b24d0e0cb6eb61a72e29440b474f722cd5c10a79b29d02bae8319929Virustotal results 32.79% 
2020-02-06contrato-02062020.rtfdoc 9005832cf404bc1202dcad8865b5250a9826f2fa18a6e23ee0a7e705c1d63ab0Virustotal results 33.33% 
2020-02-06oferta_6SP53159266791.rtfdoc 408e410322052b154cc71d747cb64f2525be9909cc3046e32fd1aee7043266c0Virustotal results 33.33% 
2020-02-06Oferta VS25337520.docdoc 58f94895848e841464a8b36d26e332a50e9b082bd7df37c1c054168929b7b34eVirustotal results 31.15% 
2020-02-05OFERTA-915276453.docdoc 061b77c1354bff1d5cafa4e10d903ee5feb16bb91c295298444e056ffefd1370Virustotal results 26.23% Heodo
2020-02-05contrato-014308928053.docdoc 1ff329d123574f88d28f8fa9b93d185f2e70000a4bc1a630ee58c293b6d365f5Virustotal results 26.67% Heodo
2020-02-05contrato-q9695763.docmdoc 23f4a774007e2fc64a2824e5973bb695a64667d8d832fbc29806976dad67d7f7Virustotal results 26.67% Heodo
2020-02-05oferta_140n431m4.rtfdoc 47ca3de0e80a4e9571311ab0b2470ecc29d18c990b063b57aef1818e5a3c260aVirustotal results 26.23% 
2020-02-05OFRT-4q33067.docmdoc fe70cef82c0a8acabe3289f5863a62b3bdf8bbd476ff9c0536600c40fcbbfb9aVirustotal results 26.23% Heodo
2020-02-05oferta_OB431904089-3723763541.docdoc 04b54fab60360e9bcdba842251298ff22e0d220be09421e7c525d51964bc4d4fVirustotal results 26.67% 
2020-02-05contrato_DKS20260.docmdoc ae52ef255f8281c9ef70187ea362faa4de1a8848cbce35b6be5e599d7138a0abVirustotal results 26.67% Heodo
2020-02-05contrato-2321151921.docmdoc f4dbeab20387f793a3dd0b39d717b27c6787e02951aa4ef7cfeb0d156b75697cVirustotal results 25.00% 
2020-02-05Oferta_1749.docdoc ab556aef3f7baf74127e682541cd5bb674af38a62c4c1f89ff43f09388894af2Virustotal results 25.00% Heodo
2020-02-05Contrato-2A585773056990.docmdoc d333ae7c8f1905346c6e502ca34118387ed567e78dc3b8208e7b2a61f25b1b14Virustotal results 24.59% Heodo
2020-02-05CONTRATO-02052020.docdoc 4a45120dce1cd34a211f66e94d6a16a0e567d8aa85527c6fa830f99691cd1816Virustotal results 24.59% Heodo
2020-02-05CONTRATO-983100.rtfdoc f52225c6d469ad7bdca5ba79071cbe42b83e3e3baf17052934f5654549ff26bfn/a Heodo