URLhaus Database

You are currently viewing the URLhaus database entry for http://pgwebhost.com/accounts/common_27542968008_E4bkaWco/verifiable_782922448_l8ajIRnl2/rqBbOawSXA_8tngcd9mryz1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428896
URL: http://pgwebhost.com/accounts/common_27542968008_E4bkaWco/verifiable_782922448_l8ajIRnl2/rqBbOawSXA_8tngcd9mryz1/
URL Status:Offline
Host: pgwebhost.com
Date added:2020-08-10 22:35:10 UTC
Last online:2020-08-11 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-10 22:36:04 UTC to abuse{at}hivelocity[dot]net)
Takedown time:5 hours, 57 minutes Good (down since 2020-08-11 04:33:07 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-11REP-WTZ472.docdoc cae649fa4834fbe773a6759d1c55036ab5a152fa90aa2f64b7751e50b3e7deebVirustotal results 43.33% Heodo
2020-08-11REP 2020_08_11.docdoc 353b24cd1dbb7be15133b64495afbbd1846a83e775870f07cef1efc21c411ddfVirustotal results 44.26% Heodo
2020-08-11rep_2020_08_11_908.docdoc bd21c54cff53a13d78966917cf55e87135e7020967d2416f6a0b259beba63dbaVirustotal results 43.55% Heodo
2020-08-11File_Y218298.docdoc 980c5eb49f054079a587ddcfe2c193c45a1a6be41100c5f1179df24c87986712Virustotal results 42.62% Heodo
2020-08-11Doc-2020_08_11-M11533.docdoc 92f8226b4916acee5abadfd888bd396b2979be223db46252b4decde8b4b3667cVirustotal results 45.00% Heodo
2020-08-11List_20200811_4688299.docdoc e4790d41e27c6978baf5ccf9461b74b1e9606fdc7edcb4d2022edafc3d8a6fd6Virustotal results 44.26% Heodo
2020-08-11rep_97079.docdoc 13c77da9bbdaea66303dfe4cfcb8b5a9f8eae8d46f1e710ab6574c73b2c1d91eVirustotal results 44.83%Heodo
2020-08-11Rep 2020_08_11 2680456.docdoc ce70fba1cd6c71bfbc91162f8e5d6f99e03ffba2db898e1088139f06cef9c304Virustotal results 44.26% Heodo
2020-08-11Dat HHJ4542.docdoc bda55acb649535e7d61133cf076b1604f3da829aa4d7b45a7bf3ba27466d9c3aVirustotal results 45.76% Heodo
2020-08-10REP 2020_08_11 868701.docdoc 1ff50f088800028624af3ad83890529e6cd409d4c797d27b35f77e33fe36793eVirustotal results 40.00% Heodo
2020-08-10List-VO0437.docdoc a685d179f34dc5fcb9fdb968d93826a1931f9e729bd7fa6491dc6cacf4ca0c68Virustotal results 40.00% Heodo
2020-08-10INF_2020_08_11.docdoc 1ceffcd16d5774ac5d4cbf896be5a34a1255b59ecb1ab8c609cfef7e151c739fn/a Heodo
2020-08-10LIST-LZM682732.docdoc cc915da7e58c724b0602504598bbad14ca38c5ab5323a50095fd1fae2fb9d62bVirustotal results 40.32% Heodo
2020-08-10inf-792794.docdoc e7cba81f4938d9f07a764862aa2eea5e681353f6e0324bf7d23971e6919de539Virustotal results 41.67% Heodo