URLhaus Database

You are currently viewing the URLhaus database entry for http://chitgarbar.com/01/wja7ho9-qywlv-582008/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:416054
URL: http://chitgarbar.com/01/wja7ho9-qywlv-582008/
URL Status:Offline
Host: chitgarbar.com
Date added:2020-07-21 14:36:31 UTC
Last online:2020-07-22 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-21 14:38:05 UTC to abuse{at}hetzner[dot]de)
Takedown time:1 day, 0 hours, 58 minutes Poor (down since 2020-07-22 15:36:27 UTC)
Tags:doc emotet link epoch3 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22Invoice-PZCF445_058324065.docdoc 4866f8481b362767c8c58bb2ba099270e314d22c1d09df4e3afcf0d6038961d7Virustotal results 44.83% Heodo
2020-07-22Invoice NK89_08500950.docdoc c89b170fea78126847d599a493f18d47d967ca36d121d9e9ed71fb87e37172e2Virustotal results 44.26% Heodo
2020-07-22Inv JGZF6_9047263.docdoc 0a359651e943b30173415d91a0886f3c0bcbb1acded5dd7ab4333651f3c99687Virustotal results 37.70% Heodo
2020-07-22invoice_F6_438191.docdoc 22e7ebd85759dfeb93f2368769a68205d61b272401227655676fcf4bb46f0been/a Heodo
2020-07-22Invoice-5260_412081.docdoc 393ac27aa81e021260be2c3de9507d953b3d57f2dfd0ebee96d4a18af210b982Virustotal results 28.33%Heodo
2020-07-22INVOICE-Z891_826243406.docdoc c2e63ea82a2d878192098e0d4a0b6509bb986254ad2f252bb49475e86982ebf7Virustotal results 37.70% 
2020-07-22Invoice KKXB8_809594561.docdoc 4362e6ba330f2fd89b96c0a2bd7407ca83f5c6678f765731244788aa490160cdVirustotal results 32.79% 
2020-07-22Invoice GOP1_434042721.docdoc ac88ce74a14a0b5a78e6bdf86ffa9bd0f2770cd7255210ffed47affc2f220dc7Virustotal results 30.00% 
2020-07-22invoice-FL5259_99621735.docdoc 9c36f76e927ccde32781becbf6a3a8ee5d2b843d19172105b9b9610680e3d82dVirustotal results 30.51% 
2020-07-22INVOICE-SVVZ93_9993253.docdoc 957cebb6f6751d4233f9c5ee7a4f3c1bd643257070d4bd13eae482daf82dece6Virustotal results 29.51% Heodo
2020-07-22Inv-XCUR983_903623.docdoc 6734a3ae13c38e8fd44de930f8cf0da0bda0a3afec46ea9a8899e61b8762ecaaVirustotal results 27.87% Heodo
2020-07-22Inv-51_0293768.docdoc 36cd81d1e9f3def8eb7ab3012b360a09e3bc2c62bbe8ce0b138faacb34c4600eVirustotal results 30.00% 
2020-07-22Invoice AGGF4307_08894947.docdoc 4ecc69d66a27fcded380c3d3d2efc6dad4189f789c784faeefa7bb8d4fea8c1bn/a Heodo
2020-07-22INVOICE-WQW66_817281.docdoc 02c7fd8ed2ff395eb8c7eb3caca1e0cec299f4db7480e6d19829069ce541bc7dVirustotal results 27.42%ZLoader
2020-07-22invoice_TO5_843029272.docdoc 17848a980123cfbb8869e7859b37b1f0e06e992a2ad751fde0a355d4eb377920Virustotal results 29.51% ZLoader
2020-07-22INVOICE-RZ8_67904302.docdoc 639bdf650ed2329ccbe33f471cc8e6e8e24bc3a1147d446ff0ce5ea0e28ae9ebVirustotal results 28.33% 
2020-07-22invoice_EJ0_190747.docdoc eb7c02a2f5a7f9b6c76befb58faed0e6cba4cfc494eca22bd8e87b36fa241b66Virustotal results 27.12% 
2020-07-22INVOICE GY139_313844.docdoc e7edf63be003d87056435fd147d04f6930e07f08dc6534bdfdb3913f4cbbd59cn/a ZLoader
2020-07-22Inv-FMEJ2_810795.docdoc 915ef2dcbb13060e972f99c4e495f50d5fb9144271000603ebb86db379223840Virustotal results 26.67% 
2020-07-22Invoice_KTMH63_62218805.docdoc e7af4a6f667a4edbd224f0b3c1358fcc307b4f67688529201e0c1c9a91560f64n/a ZLoader
2020-07-22Invoice-YNS3_4388916.docdoc 59ea049ff3ab24d93029a5395073975931ffb768537ca09e45fa6bf34af34accVirustotal results 26.67% 
2020-07-22Invoice-AMZO10_426645811.docdoc 40b8fbc9e4135de9d65f33366f01bddb05cfca61799ce403b30c092fcb421725Virustotal results 26.67% 
2020-07-22Invoice-5154_35393000.docdoc 6475e70afc346103957694beb826b2eefdb2850c9939c91d6b514ce9e1cd32a4n/a Heodo
2020-07-22INVOICE 9_916242.docdoc 85f96e5cf282786ef803c7c7886284d3225a9daeecc04ce3b8e5bbd143a3e0abVirustotal results 25.81% 
2020-07-22Inv_DPZQ9887_340856.docdoc 6ae3ae7189628dd42bd3802615aadeb1038ba73d53ab4f1ee1d18cc170ad7ef6n/a ZLoader
2020-07-22Invoice 265_227332478.docdoc ee7974d011582b83c0464f15d86e55b3306961023b16ed3c195c6c1953ea5835Virustotal results 26.23%ZLoader
2020-07-21INVOICE_QTM215_879692.docdoc 062c45cd22faf032486fa920e68f639cfd2a7b640c0d36d297e6490118729c69n/a 
2020-07-21Inv-27_637249.docdoc 599ef65639238b841a852f756d71b9d44c5e02b6d151b6941b95c94b5e8eaf64n/a ZLoader
2020-07-21Inv NDV135_584743.docdoc 112aa4be04d85780875343365b40f2fe9351e69dd4756d26a01f923251e17a49Virustotal results 25.81% 
2020-07-21Inv-AL2_99934376.docdoc 3e48fa00d3dfee3093ad2affb99324ae8e7261f2c92fd9bc71ffc5923a7dc4a3n/a ZLoader
2020-07-21Inv_KB3_3086116.docdoc d9238e5af649fe7ea0572f9699144985895a4c4576ebb77e0e198ea5120f4c20n/a 
2020-07-21Inv-Q3950_2542230.docdoc 88b555290b53e0369600411c472821ad9907eb147dc87e60164918aa85adc3c3Virustotal results 27.12% 
2020-07-21invoice-DHJ2_28132765.docdoc 3bebcaf546b7a6b80b7d94610fb02a2577fdd1331ef3ed8f118677d029e2132dVirustotal results 26.23% 
2020-07-21Invoice_9636_64516009.docdoc fa107254b6f843bb079661702c64654bcdffb1fe41fdcdd125d5d99437e15106n/a ZLoader
2020-07-21INVOICE Q4_046378.docdoc 9f9d6e57c9e3398ca955952e4fcf58321a7f235e18eaafe6aab3b3ddd4e88c7cn/a ZLoader
2020-07-21invoice 30_388337576.docdoc 2bf992bac6895328fca415aeeee4f89aff347608e709524ad9a2f549b007dae3Virustotal results 26.67% ZLoader
2020-07-21Inv-6030_835179.docdoc 6c9f7eb3f83892e735f0beedd952428a90922073dcb4f87543facad68fade4dbVirustotal results 26.67% ZLoader
2020-07-21INVOICE 318_64262839.docdoc 6c2a7d29fcae5f7e2540918ec55d99182b613e01dc109a439f1d5710ce5de0c7Virustotal results 26.23% ZLoader
2020-07-21invoice SWL11_08728269.docdoc 56508ca86a568105ecfe6df473dd0a40bbb40f66270edb514d83e99e1e6ef0d3Virustotal results 26.23% ZLoader
2020-07-21invoice NJ8923_736566318.docdoc 837bbc0f0c83b6a6837640d6ecda9c348ffd06a81fa4b87c7ebfc7df59b1a690Virustotal results 26.23% ZLoader
2020-07-21Invoice-35_66436238.docdoc fcb7d57d53fe5854649e2b62386272c124701478061110c83cb947a4fc0dd3c4Virustotal results 30.65% Heodo
2020-07-21Invoice-35_66436238.docdoc fcb7d57d53fe5854649e2b62386272c124701478061110c83cb947a4fc0dd3c4Virustotal results 30.65% Heodo
2020-07-21Inv_21_85341023.docdoc 9bd09fd88355a1b20c3268d29be2308057a659c4b96c85a618409ec4b57bd45fVirustotal results 31.67% 
2020-07-21Inv-GJAL03_094444768.docdoc 3a5dd00ce1b9f75836d4575816fd4e49d546dfa29d24a4b5dff87b94d9b34b13n/a Heodo
2020-07-21invoice-AFSG0_9866936.docdoc 33c53ca7807a817b61ed5b3a0a7e0ffe44059f5aac7475b14df784384aba5308Virustotal results 29.03% Heodo
2020-07-21invoice-DRQ3588_788145.docdoc 5aa42a51f985e6af1419f2043fb37f51a7a1189fda28293d47fed2abb130c86bVirustotal results 30.00% 
2020-07-21Invoice-WUPN441_926504617.docdoc 07954a3e04bf45308251fa489e56c8b119621131ec4617553fc17ae1e98e051bn/a Heodo
2020-07-21INVOICE-33_494837962.docdoc bdf6b8a3ab43c2e8091f591a913040c789e38a80e2f57d9dde2c5f0cdd9d7fe6n/a Heodo
2020-07-21INVOICE-OFVW2210_281520261.docdoc a15083f68d55c92228c997e26d8596bb25b5cf8129f45e98d3c78ded130081f9Virustotal results 27.87% Heodo
2020-07-21Invoice-OZEE233_968699.docdoc 4680c8fcd0003b6b846f67056399a94649f63ed5bb9bc109fc88d566b3286d94n/a Heodo
2020-07-21invoice-499_71744452.docdoc 1e574fc4ba69742cc714c4f704166cb427d2bb27aa53005da2f65b9bdc73769an/aHeodo
2020-07-21INVOICE 97_1328670.docdoc 43b378fd5752ed3af0656ba0189641526f78a1e2cd4481aa60e9ccef683ddb2cn/a Heodo
2020-07-21Invoice_KL63_678615318.docdoc 37b40dfa5b0802e246f8fc7b2454db8cb46ad31ed36c4f7fb154a71aa200279eVirustotal results 28.81% Heodo
2020-07-21INVOICE DN731_98316744.docdoc 75c9115e924a7b2ea6b2565e7d48407cbcdf06ffd452bcb6834bb821185b2272n/a Heodo
2020-07-21Inv_R2121_8459183.docdoc ee50b9e1ff6d4b77d99dded74e7e4383725809ffbc7f72c7071ef29911e69e0eVirustotal results 27.12%Heodo
2020-07-21Inv-LU8108_67165628.docdoc 8f32874205c29ff499e75943e0f6c9b298417cca9166bee485e13f791d6cc4c3Virustotal results 26.67%Heodo
2020-07-21invoice FQOT1_446687.docdoc 6cb24de3cb231233f9a3fd81c726f49ff835992f50c34efc9419c8f2c7fa1d82Virustotal results 27.87% 
2020-07-21INVOICE-I332_4124193.docdoc e600f8c39f3426d69629493028b94fb484f5b8d45bf8f0fc740b8b158438d1a0n/a Heodo