URLhaus Database

You are currently viewing the URLhaus database entry for http://www.willingwater.com/wp-admin/y068zaq-c0h-635977/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415712
URL: http://www.willingwater.com/wp-admin/y068zaq-c0h-635977/
URL Status:Offline
Host: www.willingwater.com
Date added:2020-07-21 04:52:17 UTC
Last online:2020-07-26 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: TrappmanRhett
Abuse complaint sent (?): Yes (2020-07-21 04:54:03 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:5 days, 12 hours, 10 minutes Bad (down since 2020-07-26 17:04:19 UTC)
Tags:doc emotet link epoch3 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22INVOICE_IZS2930_91759307.docdoc 393ac27aa81e021260be2c3de9507d953b3d57f2dfd0ebee96d4a18af210b982Virustotal results 28.33%Heodo
2020-07-22Invoice_MWPC74_99497396.docdoc bc1674694af57a7a421c131be6eb3403a2d2392a862aaff679ac7d2087690953Virustotal results 28.33% Heodo
2020-07-22Invoice_UQ7_411644.docdoc 02c7fd8ed2ff395eb8c7eb3caca1e0cec299f4db7480e6d19829069ce541bc7dVirustotal results 27.42%ZLoader
2020-07-22Inv 3158_629370255.docdoc 0f2039a528f454dc85d45347c05e3deeed35f371d829ed160143b2cda326accbVirustotal results 26.67% ZLoader
2020-07-22Invoice KH550_843010630.docdoc 4832f93778c37574a58c2119d6f0df1c00221503b83f91db3a165d2195eeb1acVirustotal results 25.81% ZLoader
2020-07-22invoice-4_961425.docdoc eb7c02a2f5a7f9b6c76befb58faed0e6cba4cfc494eca22bd8e87b36fa241b66Virustotal results 27.12% 
2020-07-22Invoice_DFK76_935201794.docdoc 134fcf928417712824838f1dbfb546e7735361bf131324ddffe62aedbcd5f679Virustotal results 26.23% 
2020-07-22invoice-XU4_767129.docdoc e7af4a6f667a4edbd224f0b3c1358fcc307b4f67688529201e0c1c9a91560f64Virustotal results 26.67% ZLoader
2020-07-22Invoice LZVM1207_00994603.docdoc ebec7284e20fdc5a633b8f505fd018ebfdb512a595eaf179e5d77b60d33970b8n/a 
2020-07-22Inv_FM202_3835828.docdoc 6475e70afc346103957694beb826b2eefdb2850c9939c91d6b514ce9e1cd32a4Virustotal results 26.23% Heodo
2020-07-22INVOICE-SRSH1_05707147.docdoc 2a1b48f3aaada9451e14e735699dc6910a2df66a18b4f4497c7f4f6f159c8296Virustotal results 26.67% ZLoader
2020-07-22INVOICE-492_676489.docdoc 14c000f66600b5ca3d6bac699b2d5c04ddcb6d8718fee703a5cc2c57fc7a1ce5Virustotal results 25.00% 
2020-07-22Invoice_IV052_205407275.docdoc 7476dba24b28d2a074d7e75aea79591f98fbb95b065c91870b5a8198ab615f19Virustotal results 26.23% 
2020-07-22INVOICE-PD28_71333059.docdoc 8cafecab78eb955d85ec99123092085c12c6f94ab003097360fd6bb694cec236Virustotal results 27.12% Heodo
2020-07-21invoice-VCC4_9064533.docdoc d1fe2bcc5439caf2963c2bcf85af9c8b8d4451abbc4675be82a33bf97ca81f18n/aHeodo
2020-07-21Invoice-66_730949326.docdoc 43025670822df6a6ae1ba1f56baae65c0d563c0c12410244aeb8fb166be9f737Virustotal results 26.23% ZLoader
2020-07-21Inv-NXXQ649_567903742.docdoc b697a31e24a1872813f044cfe369887a6850b80c7d79509587d7e4e6955ba322Virustotal results 26.67% ZLoader
2020-07-21Invoice EPCU580_592879771.docdoc 3d8d9972ea35adeb0f1d1014490dd3f3595a14b01aa429e48fe21cdfca7daa31Virustotal results 26.67% 
2020-07-21Inv-PV1981_1192417.docdoc 74a3c90f0a3c99e8816a94689a4cac44f886be61e0dc3f6d324a661c16c663f9Virustotal results 26.23% ZLoader
2020-07-21Invoice-DAPA23_74408273.docdoc 29fd633ba82c884e342db1c88a40a28984b2cb2fc5cbb4fdd901a3c6e5850817Virustotal results 26.23% ZLoader
2020-07-21Invoice DQ2447_45327306.docdoc 9e2fa2ec0c3818292f9a10539ef4bdcda848df84a8e0223cae2f28f82360a11fVirustotal results 25.81% ZLoader
2020-07-21Invoice-Y807_55808061.docdoc 747095882ee4fedcb2d7306fbda6bcc5b792e877d427b855d80a0fdf5db073a2Virustotal results 26.67% ZLoader
2020-07-21Inv-WSOQ5802_2613545.docdoc 2bf992bac6895328fca415aeeee4f89aff347608e709524ad9a2f549b007dae3Virustotal results 26.23% ZLoader
2020-07-21Inv YTRW0772_058143.docdoc 72a76d3c5a30ccf7584528d7bd29ac47062d468d56a417063c19573496089d56n/a ZLoader
2020-07-21INVOICE-AS5515_9557453.docdoc 97af910f93ee8e736e135660fd84b888bdcc82c809ef30af7cac06da62907994Virustotal results 26.23% ZLoader
2020-07-21Inv_RQK61_9993808.docdoc ff78753a5dfc898ae4ad1957d3d5ebbfce28458b5ed38a163e38e35532e62c58Virustotal results 26.23% ZLoader
2020-07-21Inv_8311_75048513.docdoc d00a595a3e71c743fc04ec4a2ba0eaab9fe1d76d7b018423fc5cece4e4a62a29Virustotal results 31.15% Heodo
2020-07-21Inv_8311_75048513.docdoc d00a595a3e71c743fc04ec4a2ba0eaab9fe1d76d7b018423fc5cece4e4a62a29Virustotal results 31.15% Heodo
2020-07-21INVOICE-7627_3315236.docdoc 3a5dd00ce1b9f75836d4575816fd4e49d546dfa29d24a4b5dff87b94d9b34b13Virustotal results 30.65% Heodo
2020-07-21Invoice K1154_97570880.docdoc efa78601a195a5d90844411d1e045d9589a8249a71bf35b0132e17b31a412c5dVirustotal results 29.51% 
2020-07-21INVOICE-UR6126_691366.docdoc 5dd07737bc4bcd586aa9a89cdc86f5222873447eaaf558d404f31e3fb459f437Virustotal results 30.65% Heodo
2020-07-21invoice_S988_58810570.docdoc 4de9b5d8be922ee6f95a85aa378d4b78596a0df19e25a0388096ba0831feebb4Virustotal results 29.03% Heodo
2020-07-21invoice_2_998256435.docdoc bdf6b8a3ab43c2e8091f591a913040c789e38a80e2f57d9dde2c5f0cdd9d7fe6n/a Heodo
2020-07-21Invoice-J28_658976.docdoc a61871e76461292b6923cf001c886dc23104ef7295f6fd608c7b444e577398e6Virustotal results 27.87% 
2020-07-21Invoice-G8366_80057983.docdoc 5ddb6b1bf21e4b873293346c3383ce3ff112b9271388b039ed95d38bbed45c5en/a 
2020-07-21INVOICE_SMSC8136_249379707.docdoc 05b1f0822783aa9419a3b13424fb6d31e224e8dad2c84ace8cafa7c1b42a1f3eVirustotal results 28.33% Heodo
2020-07-21INVOICE-ZV086_965945306.docdoc 37b40dfa5b0802e246f8fc7b2454db8cb46ad31ed36c4f7fb154a71aa200279eVirustotal results 28.81% Heodo
2020-07-21INVOICE-MPE58_570848576.docdoc 75c9115e924a7b2ea6b2565e7d48407cbcdf06ffd452bcb6834bb821185b2272Virustotal results 26.23% Heodo
2020-07-21Invoice-B5_843049.docdoc 692c3606f5b32a2200f1ec78d8764604def5e99ca282474046d78500e09fb91aVirustotal results 26.23% 
2020-07-21Inv SY6_608501.docdoc bcc004820abd0f210285b3aa58c625f0a00187f4f545313a553b4a40ec68b6baVirustotal results 26.67% 
2020-07-21Invoice-RGLQ79_050112.docdoc 8f32874205c29ff499e75943e0f6c9b298417cca9166bee485e13f791d6cc4c3Virustotal results 26.67%Heodo
2020-07-21INVOICE_94_5774644.docdoc f46d92d4440678792e72b414df3ccbe066766a4b486ea3c25c767d8c297335b0Virustotal results 26.67% Heodo
2020-07-21invoice-VD47_495388888.docdoc c809bea4eab861ed271e8d1688b261c33747782ac6756d644edf6889ba745c88Virustotal results 28.33% 
2020-07-21invoice_AE00_948603.docdoc aa31041b4dcd03e3ad1818d6ca5ac597b999aa6725212a9dfecec97c68100a27Virustotal results 26.67% 
2020-07-21Invoice_KCK44_081768.docdoc 969b9fcc13e520a48a60d7e65714c495c99ac1a90075aef31a7486070b8bb171Virustotal results 26.23% Heodo
2020-07-21Inv-LA4397_76186033.docdoc 6a474d19ec3d28962de1668764ca03da5b762d1d6a949bdf78910db1a1bd1bc9Virustotal results 25.00% Heodo
2020-07-21Invoice-KW7_682755537.docdoc ec15490f0fe558b1c2db47afeb9bd903a82cc44b48ba66e6c66a5570e0be87b8Virustotal results 22.95% Heodo
2020-07-21invoice-TA3_87658073.docdoc f37d602c2d14ef7dade7cd13740d744939c846704065c8d20367a677ce0ad095Virustotal results 22.95% 
2020-07-21Invoice DNX1_336952939.docdoc b7c0c24f3f9f552c499937cca5dcb7a8fbb7bbf600dc1ad43256647401ca3d04Virustotal results 22.95% Heodo
2020-07-21INVOICE HLCM371_7513335.docdoc 7f53ea4c64012caad27163ff00c2aefd9e2dff6a4c5fe488955be018c8af4362Virustotal results 22.58%Heodo
2020-07-21INVOICE_ZX504_010988288.docdoc 3f7a1b33f7dcc1b83d5f92638f49684c3669a37cb4aadc5ca4aca17036fbe4b1Virustotal results 22.95% Heodo
2020-07-21Invoice-PT0_360960.docdoc eb0997857baec37d1cddca0ae3c7b6c59fb78566eb5faf16035fef12063a3a2aVirustotal results 23.33% 
2020-07-21INVOICE-44_822102.docdoc e0b1f74edfc82851cded4dcd2efe9482c8272105eb6853b36947bc7ef8510145Virustotal results 22.58% Heodo
2020-07-21INVOICE-AATD22_3075482.docdoc 9880e4daf09068bccb16b2baae14ff902fa9d6f841f48ebb26bdd1944e41045bn/a 
2020-07-21Invoice-UYY3_087355.docdoc 91eeda612b556a293a55a78b95987a664e002e871a53ff177794b04908f39fccn/a Heodo
2020-07-21invoice-FJ235_18667267.docdoc 2b44339164b5e8b860c12c8e8b4ad6dc2e1bc587463ec797b04401d948978140n/a Heodo
2020-07-21invoice-DKPV1899_929993.docdoc 4903f451f19bc16aaefc695c70d0fb223e73d48958a54a4381cf8f776bc4e8f2Virustotal results 22.03% Heodo
2020-07-21Invoice-826_08849438.docdoc 7b89c117307ff77f93913774b637ef762d4bd0656e1b17b9462821cf15e87f0dn/a Heodo
2020-07-21Inv X2696_568006.docdoc 59fdc24661735c738aea0c5ce35581112339c50c9a16a48bdc26694fcc2aec0en/a Heodo
2020-07-21INVOICE-B20_753571763.docdoc d279829ce22ee6a6b6a7c259b4c7be73b7cad4a3ba3771caf3255dc6c4024f3eVirustotal results 32.79% 
2020-07-21Invoice-DJO57_51711739.docdoc ebbd45d43283a8cb0568c350a669315564a1e8707aee4ac4556c0a843483d482n/a Heodo
2020-07-21Invoice-J86_77774332.docdoc 4c0125f72c43063a474cd06d510baf4675597b0dc15dbc75808ba19e47c3b508n/a 
2020-07-21Inv XMI7_048179322.docdoc c8b378b56c943ef48599ab9f3eac4de26ced0acd9c5db6d952aac355b1ba581fn/a 
2020-07-21INVOICE-Z720_59388427.docdoc 38f0850e9bbc46f419acd8e723015f8a5c90bc3643e680ffac42cb2b88179c77Virustotal results 33.90% Heodo
2020-07-21Inv-3_1383351.docdoc 295dab6cbdbbcb48ed5d8b1623aeec9031d7a1c617436d3805f32e3da8267efdVirustotal results 32.79% Heodo
2020-07-21invoice ZRY220_674290610.docdoc 33a93dab74ebd140d4d77872dc8c32cc0a9f876e750bfe15994bc2884d42a458Virustotal results 31.67% Heodo
2020-07-21Invoice-MZV19_139643.docdoc 543ce71bd2deaa4b6c6994a72f3641b50eff2be1f90beca627322bae86b4f7e1Virustotal results 33.90% Heodo
2020-07-21INVOICE-L4_193161.docdoc 19d54ecf09138dbd9153771a0928e858bb5afc3ca208c3a58c9bd8aa5934b110Virustotal results 30.65% 
2020-07-21INVOICE-IL1_3067116.docdoc bcbd3e8aab56417bcded9dbddfa8631d609998e5cdbe1e9dad903c4b5c96c156n/a Heodo
2020-07-21Invoice-KJ6_6033803.docdoc e37800a8be08a41f6959068617236eaaa5f0bcfbf166b68d0aac0292ff664780Virustotal results 30.65% 
2020-07-21Invoice-MOF7_47035858.docdoc 2aafa91f9bf7bb0ba237bd6180ec6279528f3936609ddbb3138e151094fbb45en/a