URLhaus Database

You are currently viewing the URLhaus database entry for http://nuwagi.com/old/EOBPpCJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421766
URL: http://nuwagi.com/old/EOBPpCJ/
URL Status:Offline
Host: nuwagi.com
Date added:2020-07-30 02:23:51 UTC
Last online:2021-03-30 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 02:24:04 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:8 months, 3 days, 4 hours, 57 minutes Bad (down since 2021-03-30 07:21:10 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30invoice-59_73491450.docdoc 1bb56e849596fd788a8c9905d08684f8043a4cc4e72209d9978d78aa4f9f6f22Virustotal results 45.90%Heodo
2020-07-30Inv6_047477.docdoc a99c7d681efd2f154e47e585cda75103f5e9abbffee3f7e86dc9da37260624ddVirustotal results 46.67%Heodo
2020-07-30invoice-8447 747482937.docdoc 7579d4a1d6d4da73019950ba9cd7de417560465889ccbc12fffbebff6b87ca3cVirustotal results 45.16% Heodo
2020-07-30Invoice 99-74129932.docdoc 7368694a3871cfebf9fe3f6475e2ac71a2749e5383a93480b5fb708aae70d572Virustotal results 45.90% Heodo
2020-07-30Inv-J39_5708696.docdoc b56e407fa18991949dc9cc5347f42a17737b284c9e00b08050cc721bae5a8e7fVirustotal results 46.67% Heodo
2020-07-30Invoice29{:REGEX:.docdoc 907516b73bbcea22b548ab281f487773521e2af661bbe7615b82466ceb99e403Virustotal results 47.46% Heodo
2020-07-30INVOICE QQ064 289213257.docdoc 6aaf1d2548a2d3e3af5573be71f022d7b0f795816398a54e9bd79a341453530cVirustotal results 45.90% Heodo
2020-07-30Invoice-EHPN9283-626713871.docdoc 9a8f438d67fc21b41ed272e536678baf70653b5c7c55986ca9d59569ee046e49Virustotal results 47.46%Heodo
2020-07-30INVOICE-JK303-759474460.docdoc f109e6ae9c85ddfe69a3f7312184afd244ca7deea6b5f977cd6b9869dbbbe860Virustotal results 46.67%Heodo
2020-07-30invoiceFW5511-511219888.docdoc d39ce67865da7efb2895401ef8d8f54bdd3a7d09784d012b1068d4b5ceaf44cfVirustotal results 45.16% Heodo