URLhaus Database

You are currently viewing the URLhaus database entry for http://nsheldon.co.uk/sophie/closed_zone/uCdGgz_K1W0jIWlu_space/ymtuk0ui0_u8w9su13w692/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422891
URL: http://nsheldon.co.uk/sophie/closed_zone/uCdGgz_K1W0jIWlu_space/ymtuk0ui0_u8w9su13w692/
URL Status:Offline
Host: nsheldon.co.uk
Date added:2020-07-31 15:37:09 UTC
Last online:2021-04-01 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-31 15:38:03 UTC to abuse{at}heartinternet[dot]co[dot]uk)
Takedown time:8 months, 3 days, 23 hours, 5 minutes Bad (down since 2021-04-01 14:43:32 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-01Rep_20200801_DPG7575.docdoc 92a8c9729a35ef4fbe97b8b931ac2ba3284ff4c1aaaab30eadbe36ad12c75465n/aHeodo
2020-08-01DAT-OO845.docdoc d0af068d0fb59c36a723f73b9a022dd2bfc71dec2a8679de9cfb406aff10561eVirustotal results 46.67% Heodo
2020-08-01inf-WKL10629.docdoc a680dee80d1c2e20335b72e1ab12908d3d79228c4be39a045dbcf6bff5c2f2can/a Heodo
2020-08-01dat-2020_08_01.docdoc 5b869243a1f25181d647b1ab540885e1991a6d935499fe16f8b1866d6c11cceeVirustotal results 49.15% Heodo
2020-08-01REP_2020_08_01_470.docdoc b022041c3866fa72e9822bbd3eb197dfe6d228453a0261f39be63a3d2b47f9cfVirustotal results 50.00% Heodo
2020-08-01INF 20200801.docdoc b516a3797050f6ac640f573248069d74c0a95c2f96e09f7c8f960d02edb53117Virustotal results 49.18% Heodo
2020-08-01List_MOQ16654.docdoc 73b934062bb8c8721173ac73c39f36f73eaf2b1236fd8ae3a0284cb972fbcbc5Virustotal results 47.54% Heodo
2020-08-01File 2020_08_01 SV813.docdoc dd7b7de461d1bb98f753cab9f3d748f28f34c6919770f2c279541724298390a8Virustotal results 49.18% Heodo
2020-08-01Mes-40785.docdoc 8d88b8b69a328ea24a481452ebbd0b239ebcb55d271c85b2bc1e99d4edb8b709Virustotal results 50.00% Heodo
2020-08-01Mes 2020_08_01 OD223.docdoc 8c17593a656e91dd4f497ede251ae65edcf1b44f79bafaf31cb1c270131d7245Virustotal results 48.39% Heodo
2020-08-01mes-20200801-X79272.docdoc badce2483951ae1a102173ec603478bd0d218eac1287212b49aa80c421e80438Virustotal results 48.33% Heodo
2020-08-01file_20200801_03449.docdoc df2dc0151e9893df9a0b5fc037b8857125e0e013db773886f7714baaac50f250Virustotal results 50.82% Heodo
2020-07-31inf-20200801-117.docdoc 3d5959acbd3858cb4d5ceaf822493ee9d0b2250bb989193f8fbbc64db8570dcbVirustotal results 50.82% Heodo
2020-07-31Dat_2020_08_01_4602.docdoc bb7bf7084a18fe63dc1c4ab7b9e6efbbffe5e925099c0dfa664cc648e6d92adfVirustotal results 47.54% Heodo
2020-07-31doc 2020_08_01 VER19424.docdoc 8698a975eeefa70a6e8eac20e57be07dbed23f59301a735a72892edcfdc62d26Virustotal results 49.18% Heodo
2020-07-31DAT_20200801_520.docdoc ecd04f11959248f4efbea63e69ab2359e0031dbefa8aaea74b90de94456bb89fVirustotal results 46.77% Heodo
2020-07-31Doc-2020_08_01-4488924.docdoc be26601d6cda02134a641d0d0888c7c780636ec180084ca0fc3f66281e23677aVirustotal results 47.54% Heodo
2020-07-31DAT_2020_08_01_WS9685.docdoc 3d5427a07cdecdce3e2943473bf2a141a3eeff0e22919c7b1fe3378aed3d1590Virustotal results 48.33%Heodo
2020-07-31Dat_20200801_RG229.docdoc c45bcf9a41075804172523238d905c314dea01aad3babafd32cfe0ef52b86260Virustotal results 45.76% Heodo
2020-07-31mes 20200801 MO044.docdoc 796654f192e741799d2243175e6ea18540b6c48fbed84b010dd806485acbbbceVirustotal results 47.54% Heodo
2020-07-31Dat-6129928.docdoc f4469edd9d414e0d622d3b4445beafe1ef3b0787f29b9225b2157438d9bfa722Virustotal results 46.67% Heodo
2020-07-31REP-20200801-7630.docdoc c392286c985ecf84b1e75a52095b44c2e5f596410d388ea8ebe5f912bad95650Virustotal results 47.54% Heodo
2020-07-31FILE-2020_08_01-9086.docdoc 028ad78c3d669870415ca9cef8fdf704e543382daa866d7ee003993217aaf48cVirustotal results 47.54%Heodo
2020-07-31MES_2020_08_01_DZ531327.docdoc fe41313ae7dcaf87736d8cfd069d8fda8577fcc2c9b406fe90caed2e64ab2d13Virustotal results 50.85% Heodo
2020-07-31Mes-20200731-LL809532.docdoc 94d08b2e28420afa4d42953f61aa1a50786365e8d11f0744f4ff83f9182df0a1Virustotal results 49.15% Heodo
2020-07-31Inf-20200731-SP783.docdoc 195cda14e2dd15fa317cc0bcecfb75d39c2807e27954bbf5d34e643c4709486eVirustotal results 47.54% Heodo
2020-07-31rep_20200731_32154.docdoc 2e50d9050449582cc5e9bf03feb2170c82ff1baf77da1e0421fdbe1b21046af2Virustotal results 47.54% Heodo
2020-07-31rep 20200731.docdoc 07bf2a3130f0c9f7b406b5fb8e8fd88bd219af6bb182f8a8640dcd671df9eaa4Virustotal results 48.33% Heodo
2020-07-31Inf_20200731_627.docdoc fef0d18bba05ab168d989f1ea7d66da777b94b321f8acd7d00614eacef0b7476n/a Heodo
2020-07-31Doc_20200731.docdoc 2b91118705ef2dd0fa616e8221085c4d21af78e807b0ca0b8071520592c6859aVirustotal results 50.00% Heodo
2020-07-31REP_20200731.docdoc 292178338f7f8510eb142c51f9e32b7698b9167a26ee9f4eac6f921f285d9d07n/a Heodo
2020-07-31FILE-20200731-74227.docdoc 242a7cf61d7a50d7a5eb9a2a9ffd61ac47f061eabbf92f8f2d57c70eca976871Virustotal results 49.15% Heodo
2020-07-31doc 20200731 2711.docdoc 32e881072750a545a85cea81d48946596c0396a875f3bc5bb2c23512b2d33110Virustotal results 47.46% Heodo
2020-07-31ARC.docdoc 8aab946a92b0c4ad6c84dcfcdb778ce9d17bde1bf3e62de5bf55071fe1757200n/a Heodo
2020-07-31Doc 7176.docdoc 2aab70d8abfcb974151b102dff75d1e11116cc777b835de41be4b9bbc3e13576n/a Heodo