URLhaus Database

You are currently viewing the URLhaus database entry for http://elook.com.tw/ABOUT/swift/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421140
URL: http://elook.com.tw/ABOUT/swift/
URL Status:Offline
Host: elook.com.tw
Date added:2020-07-28 22:26:37 UTC
Last online:2020-07-29 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-28 22:28:02 UTC to nobody{at}example[dot]com)
Takedown time:14 hours, 41 minutes Good (down since 2020-07-29 13:09:08 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-2966741331678.docdoc 9e99d58a2fad321a27cf4e207a2b954736f93a831834d422f75ac4efb7490683Virustotal results 28.33% Heodo
2020-07-29DOC_JY0794839012BC.docdoc 88f400fbb72c120c9fa8173bc5f047a5e904164c21372b4164f9149f554d4891n/a Heodo
2020-07-29BAL_RYW_070120_TNU_072920.docdoc 1257945161cce1eb5a26d2ae6cd6d914e96eb7e505d3f37a281f2d091e2a7a32n/a Heodo
2020-07-29DOC_PO_07292020EX.docdoc db9b63cdcaff706197aea2e1a576f55006b3513170c106f6e2ee66586482b6f6n/aHeodo
2020-07-29BZ4439978648LH.docdoc b051dcc8a4c8215cd5456b9ff9d3de2ca7d04f269134ce6ebe467f79185046adn/a Heodo
2020-07-29PO_07292020EX.docdoc c973cb08af272436c10c7665181ab3cb5ca566f5ddb70644ca92882b87d2b29bn/a Heodo
2020-07-29J_JZ8N2RPXBN.docdoc 10361963fee9e09d6ecba109538947570bb5bc47275c46101f018ad1913138bdVirustotal results 26.23% Heodo
2020-07-29UKLZ_61299516.docdoc 10bff4abcb10a44b3d14435988ead41d1468bf4dc8fa4fc184e0babdac5ae73dVirustotal results 26.23% Heodo
2020-07-29REP_03793304.docdoc faed57431e1e52e4507d6942ea715086f78a6a07fe7fa534da07f2ffa3710df9n/a Heodo
2020-07-29DOC_40720840.docdoc fccf70d8d89e60e1121cdc6b1ea78acec628a2f192e60810ec0948a20808fcafn/a Heodo
2020-07-29DPV_070120_NMX_072920.docdoc a1774a6485655119ea70b0979992d361b648420fb0b003439e52adff57c241baVirustotal results 48.33% Heodo
2020-07-29S_INA_070120_XUK_072920.docdoc 5d022a451650f6f56f406617294a4445538b97a8f88aa1b89e72480f34ba8bc0Virustotal results 42.37% Heodo
2020-07-29K_GM3415047392CM.docdoc 9e3690a0a71dc239833dddc5b2aa94983eec61d88a636aa96f12bcfac9898592Virustotal results 41.94% Heodo
2020-07-29PD62QZPM.docdoc b3ffca228d4d444172e54cbafb591ce0d37193492c7775c7dbf7e8c8e6bc00dcVirustotal results 42.62% Heodo
2020-07-29FILE_6YUUCR696RDINP.docdoc 5ed1399f2abe4abc20390f317598ea019e62a7f410ae2ca299df6b438bee4995Virustotal results 40.32% Heodo
2020-07-2968422486.docdoc 85433bf01e39441b1cc6245f6096bbb9410c45c3a53efaa948c9b2b48a2292b7Virustotal results 41.67% Heodo
2020-07-29REP_HAO_070120_HPG_072920.docdoc e7efbf8e260c6820d94ea6e8f46ab6bad5ba9bc28a33bf73ea420854de41caf8n/a Heodo
2020-07-29REP_05140265.docdoc 6370801cfa9c5207d9891ac6bce41478e5f4d52c83922ec87b94af39195aaf65n/a Heodo
2020-07-2911169455.docdoc 1f19f1cc91f28959e4f1a099b4f6d11a2dfd3b5d5ecf73f596b764dfdc356b57Virustotal results 42.37% Heodo
2020-07-2853729397999.docdoc 9e2785a9cb319ef1e1ae50d46ca804ae72583b7910a6c8fcd6bdafc8fd8ce956Virustotal results 40.32% Heodo
2020-07-28TOKA_768395017161764358210.docdoc 26c4e8ead2701556bd3d09795db4bb4cd554b40cf9f30b9e76b7434c0e6e96fbVirustotal results 40.32% Heodo
2020-07-28FILE_PO_07292020EX.docdoc 63c74b892d39492d60408cece9e71cc78d5bb63eb8f598ad5d4f1f375c2745fdn/a Heodo
2020-07-28DOC_VRK_070120_QXM_072920.docdoc 50563ca2e8c59a4a909655f6fc73f1b3700042972dba5cf08ccd036321098da5n/a Heodo
2020-07-28DOC_992499858476627594.docdoc f11b8a55079b29b5a63d984d3c29da9b7fcc2d7a0208fd59321de596595d240dVirustotal results 44.83% Heodo
2020-07-2883776793.docdoc 369f77422abb84e08c73fe88c002e4e05538594642ba46045f2f0e0539823379Virustotal results 43.33% Heodo