URLhaus Database

You are currently viewing the URLhaus database entry for http://nuwagi.com/old/qzbCEKop/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427249
URL: http://nuwagi.com/old/qzbCEKop/
URL Status:Offline
Host: nuwagi.com
Date added:2020-08-07 14:56:16 UTC
Last online:2021-03-30 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 14:58:08 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:7 months, 24 days, 16 hours, 29 minutes Bad (down since 2021-03-30 07:27:18 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-1627adsh07bw98506884.exeexe 7ce2a2200111dc2a30ce3d3939ad98b0571880b8f58fb77c81095cfa95b818dcn/a Heodo
2021-01-1027adsh07bw98506884.exeexe 7af8e7fc875ad83e178aae9429fb39cddb0c5eb19a7b3749f70a848face19ecfn/a Heodo
2020-12-1827adsh07bw98506884.exeexe 2b84e50f47d38446cf7b3596aa57f8158f9eff2e1838cb2eda3498a317bd7014n/a Heodo
2020-09-0627adsh07bw98506884.exeexe 794190148d7affbddbc43dfe891baf02cbe9e9189e0e061a3480251773f9ecf0n/a 
2020-08-0927adsh07bw98506884.exeexe 74a5f628a05bd89af618679fbd34f52584c35dd4d932f5dbf201d92f16569fb8n/aHeodo
2020-08-09ly0hsek869782.exeexe 310b13656d7993a8111adfb881611721f347bdb94b7b1d924ed5ba9b89775d6bn/a Heodo
2020-08-090x4jmm4909730166.exeexe a3b4338cca3feeebe4a475266a866cd90486fc476a8e8c80abdbfbea4cfe4c24Virustotal results 31.43% Heodo
2020-08-094jb9496.exeexe 7d3d958c775fd08ee16642a9a190acd7e143a2f23234657b09b274b570ac5a3an/a Heodo
2020-08-08f59.exeexe 19cf14c2e1ad912dbd678980726c0ae7052025a2a51c6ce6585f11c9c50b55b8Virustotal results 9.72% Heodo
2020-08-08n6oa645545.exeexe b1c58d0eca695e8d01176fa167c6a9ec47679e8372f45ebfc5cc5a9cbefd3068n/a Heodo
2020-08-08g4jg489236.exeexe d9a18f05f610dd127783bded5982e0466ee59071eae8887bd7aee04a517086f5Virustotal results 15.28% Heodo
2020-08-0859k2awv3u0478905.exeexe af9689886d4eb4654989e7088aaa0367c2559c868ab488e60aa717b4b7831225n/a Heodo
2020-08-083l9rr771254.exeexe edf9baff95fb1eae8c0638f88f7ff08bc30e17466c1ba78ddc413cd76bbc3b0bn/a 
2020-08-08h4pdg6pz6c37.exeexe 77ee2a65c56afe79bbf49fc015bc73cc2c551847d18c866555571c81a3e859c4n/a Heodo
2020-08-07tqy358b9b2446.exeexe 4b12b25e01cd5b41921343df373a2d99c268877a1a7ab4303de3fcd2687b9fe9n/a Heodo
2020-08-07r9494094.exeexe bb2c540568ff704094fd8d85a251a7803a1f6eee62b9602a143dc2824b7fd953n/a Heodo
2020-08-07mz994539384.exeexe 9d8b70f87975057633184b9dd95078767588076a9f625bc6c553e57b66d6ffa4n/a 
2020-08-0722ijzh7297.exeexe bd39bf11107535f68e62e67a5093f17e031ef416be1d14adbc3ad35ad5ac6b76n/a Heodo
2020-08-07kvff27j4lo89793346.exeexe 0cd60ea46c83e8559d05adca4b903adc80d9c2bf7c6910631adb4437af3ea9c8n/a 
2020-08-076vdit5233528175.exeexe 2fad738308a55927b830a6da18cf823afc198410205502aac76f60b1bea33aa3n/a Heodo
2020-08-079p1307413.exeexe 4200f4e6521a296d2e07698b29f245e3baaf3cc629d7f02c30d771cc6bf7a39en/a 
2020-08-075jgh25658342.exeexe 7b2bd82f8eead4de4b7e581792bed938db5ec4343ec463d770ab21a93c8e7dadVirustotal results 13.70% Heodo
2020-08-07yi7877.exeexe 61a3602a7f1c4c4f8f676520aa1aa799a07feb166e7a2f5530073a2f3f12564an/a Heodo
2020-08-07smjg6.exeexe 3911508070ce39ad04de96095791f175ae58f9f1d14512dd5879768c4f89159en/a Heodo
2020-08-07mi05.exeexe 90c43a9e9dfbc22b8812a49cc280f114001166723e4fdf6d95401fb32e35d9edn/a Heodo
2020-08-07ez0e36u0767930428.exeexe 2d4dc6d03b795717d14731b8ebe609eb79254fa76b99cd79bcc033da5b7e2d9dn/a Heodo
2020-08-07y8460.exeexe 57a0ecfc119871ac21e3f0a5f5f4d86513c27bc2a98540444488ac5a6c57b127n/a Heodo
2020-08-07vj9to3dc34681892.exeexe 1af285d20c66ed4d09675741761f4d78b1a3381c4421f5fcfcfb15735fe7b500n/a Heodo