URLhaus Database

You are currently viewing the URLhaus database entry for https://aswad.shop/wp-admin/swift/thsao2y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417812
URL: https://aswad.shop/wp-admin/swift/thsao2y/
URL Status:Offline
Host: aswad.shop
Date added:2020-07-22 14:32:10 UTC
Last online:2020-07-22 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-22 14:34:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 32 minutes Good (down since 2020-07-22 17:06:07 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-223317764196.docdoc 0c133bcd327858b979c14422ac2623c0efef1dabc588f2e775e58049bacf093eVirustotal results 38.33%Heodo
2020-07-22DOC_9QUY9U0ZZ2K.docdoc 527f1d378d5c6addc8574d362df991207e3530f13a9705b667ea7d28b708112bVirustotal results 44.26% 
2020-07-22INV_QM9GWICL.docdoc 71fc59c792baaf787bf4536e969036e4e2aff0ce6f9f8319ee51515bedbd7488Virustotal results 45.90% Heodo
2020-07-22FILE_33784594675.docdoc 7e7aa30ca5690996f1a10f67cfb4dc964e5abc8b9ebb860ae6c3c770ff551894n/a Heodo
2020-07-22FILE_01799783.docdoc a20bd02f74a347c085b69f0fc0e88439a81ca48bc6609580b02c7b1af1045217n/a Heodo
2020-07-22YW_8H3Z40N7U1N.docdoc 0903878bcc1c642efdacd0a38728427d7694d63ee079ad0c29a6dc86640c7a07Virustotal results 42.62% Heodo
2020-07-22BAL_02700798161456179.docdoc 5cbd34babe0ec377534dd02560a79250776943095dad7b6d53f17cbfebfe738en/a Heodo
2020-07-22HEQ_6940817387732521568166.docdoc 717d843ec0f588601f8e53158a3cf6c88ca8f514c3f32cbaa004b9d6cb8fe6d0n/aHeodo
2020-07-22DOC_103424413601417496887.docdoc 516b990afeea66dde2feaf3c08cc03d53b102010a7563f735bcd2a9298a4978eVirustotal results 44.26% Heodo
2020-07-22UOOX_TQ8188230449FZ.docdoc 4a9d26b321d5a445a605753d2d0572005b9b9b84a415cd4b915644cede606e5cVirustotal results 42.62% 
2020-07-22FILE_VT9967674828RN.docdoc 63d1c06eca8d50a20349ce6b57149e8aaee2a2e012012a9e84dad48aeb38cbb1Virustotal results 43.33% Heodo