URLhaus Database

You are currently viewing the URLhaus database entry for http://hguk.net/cgi-bin/parts_service/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421424
URL: http://hguk.net/cgi-bin/parts_service/
URL Status:Offline
Host: hguk.net
Date added:2020-07-29 12:44:15 UTC
Last online:2020-08-09 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-29 12:46:02 UTC to abuse{at}ihnetworks[dot]com)
Takedown time:10 days, 16 hours, 45 minutes Bad (down since 2020-08-09 05:31:16 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30H_PO_07302020EX.docdoc 18190f715f0c05ac6e28e0fa78c58fe7a1f6a0733be72ea6494e4340611c2194Virustotal results 40.00%Heodo
2020-07-30BAL_QJE_070120_GTO_073020.docdoc 07e19f3c256981e488d086f48552ee93a5b7d9148744edc670f477090ecfd5fcn/aHeodo
2020-07-30INV_CPKRE12FB8R2KC.docdoc a79b0c25cac58457612034a8ca6f0f8582c8107bf7b64ba145d23dec09a34b39Virustotal results 40.98%Heodo
2020-07-30PQHP_PO_07302020EX.docdoc ede4d3f3f62948285291afc16d31abd1c17c5f9db3ceb0e376151913977749cen/aHeodo
2020-07-30D_59659370.docdoc f6a7b1d24aba7dfadc3430a9b49eeb6652dbb88493bfc229986d644624f05f82Virustotal results 39.34% Heodo
2020-07-30INV_AB8727262141UT.docdoc 83df298646a7ee7eb341e606b340fd4daf3c0bc2e3d1f7003509e9cf2a155616n/a Heodo
2020-07-30BAL_94114566.docdoc fd052d7b77fd112247dd93e3ff96b40e88c95d0cdc0adb5b81a49e91d5fd754dVirustotal results 46.67% Heodo
2020-07-30BAL_HID_070120_HYK_073020.docdoc bc06aea71e46ed5e64ca7cf24f3b794f46b9371d1df13696a3dfe4096a3bb6acn/a Heodo
2020-07-30FE_LPB_070120_ZNW_073020.docdoc 7d44f831d3f2a872bb859afa8572c6b61b11da75e5db08dc662221a6ae37008fn/a Heodo
2020-07-30BAL_6111862941833069.docdoc d3925d4dce34de594b7873b36880de7be2b8cf95a583665c91ab3c660f18d292n/a Heodo
2020-07-29Q_5529792246579482256223045.docdoc df0fd9aeb27800d1d055526f68c68130262c8c15596eaa5077cf3a067e810d76n/a Heodo
2020-07-29DOC_CY5010748617TQ.docdoc ef354afa479fb3c2a19622cee6c8b67e9b54ff16871ace2f97bf8cf992883da6Virustotal results 44.26% Heodo
2020-07-29BA3218084770TF.docdoc 0bb41da3d7f6f972f06276bd500f8c8c520928871f48a3751835a23497658939Virustotal results 44.26% Heodo
2020-07-29Y_VGM_070120_BRY_073020.docdoc 247650d657b93cdc868b938cf09c549175ede9f04050b49bf731bf4187040030Virustotal results 44.26% Heodo
2020-07-29FILE_00336756.docdoc ea1d07ae55467195b610358c91f9d4cb4f280d055e9a86158339ca3bdba8ca15Virustotal results 38.71%Heodo
2020-07-29FILE_OMP_070120_CRM_072920.docdoc 85586aed0ec99352b1a7641827523f66047222df673d56eaef2318e8cfe5d325Virustotal results 36.07%Heodo
2020-07-29FBMT_4QM2ECHOCT9HOMYS.docdoc 9699d65df4c2fe82af8b8dbfe2a0b1165432346f1be0417429b127a7d7346558Virustotal results 36.67% Heodo
2020-07-29REP_PO_07292020EX.docdoc 21ba8eb2d82ec96bf7a1b9842c3b05b964b09dbd3533c017faf9e6a30f59b1caVirustotal results 35.48% Heodo
2020-07-29FILE_EY3864483296JJ.docdoc 018beffb57923eb38dac054bea5fce0c4e9aca87f1971e226c7a7bacad5606b7Virustotal results 36.67% Heodo
2020-07-29L_BM4955613918JP.docdoc 591cc81573603cec788c988d64e2f0cb02c72beadacc745b8d52381729041393Virustotal results 34.43% Heodo
2020-07-29F_14324909.docdoc 3d0f47c47fbc6cfee2fb276f433b21cca723df51f5c2a24b876cef35c936e81eVirustotal results 34.43% Heodo
2020-07-29BAL_J0II3PM1K.docdoc 6fbae9bccf7687065cab8a4f08d6b3698f4d8224cf72ca4eb10032c0178766adn/a Heodo
2020-07-29DOC_YK7883284896KI.docdoc 2b446f962d60ae78cb353c325d1371e6526cb8315092524b2709b9c2eeae6753n/a Heodo
2020-07-29VOXE_24053520.docdoc 4a406747cc4af71f72229df7ddbd5c6858984101d67e93ab864273cdff151823n/a Heodo
2020-07-29REP_FBODTL83G1KD8.docdoc c2ac2bba78f3f27d36a97f527237ad4454b85b03bd0d8a1bd3c47c161c99aa5fn/a Heodo
2020-07-29RB_UZMSQ3HTAMV8YQ.docdoc 63f7966dccfe3ea71a5d5de0ee43699e8e889f67ffc683470b7bb4c222a0a4c3Virustotal results 30.00% Heodo
2020-07-29REP_QY5564210687DF.docdoc 3681daa87fcd7273080d8c9943be0e8f549075f23e2ceef7e89875649ad5a0efVirustotal results 27.87%Heodo
2020-07-29XO1392247984DX.docdoc ea0c4bf37a77d48ec55e6fd331d26c6efd0c643194ff2c6919b8f975f0562e7dn/a Heodo
2020-07-293732476047352760260491819.docdoc 35882c33b875d15f1c62d995a525bdbf80355da1abfef138e5b369c5543b2ac9Virustotal results 27.87% Heodo
2020-07-29MGQ_ZMNNKWJNIZ.docdoc 5a959afcb67ab697d8f53e2e91f7424fb274bee1600360681f6b61c26e377fd7Virustotal results 28.33% Heodo
2020-07-29EH3647275118CQ.docdoc a555bca3e4e59affbe0224378fb9bb050ce81c45bac472e542fdad497759531fVirustotal results 27.87% Heodo
2020-07-29BAL_MX1750885351CA.docdoc f2079fe72b86eddb5c15d9b80c2cc59076a08c0fbbacc4663d5573f5fe40e88dVirustotal results 28.81% Heodo
2020-07-29A_975852117066.docdoc f794639d67379bfe9c95c945acab77981d8f44fc8d75e2566e09aaff420cb280n/aHeodo