URLhaus Database

You are currently viewing the URLhaus database entry for https://www.topcounterfeit.com/dwgtb/sr938583528iyggl3l1reqow/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431937
URL: https://www.topcounterfeit.com/dwgtb/sr938583528iyggl3l1reqow/
URL Status:Offline
Host: www.topcounterfeit.com
Date added:2020-08-13 13:19:05 UTC
Last online:2020-08-17 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-13 13:20:03 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:4 days, 1 hours, 52 minutes Bad (down since 2020-08-17 15:12:46 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15INV_WF6654081009QW.docdoc 55f8854dbcaa2832aa10f768c129ab27544b5b153c7e4ea008f7ae9444681eecVirustotal results 44.83%Heodo
2020-08-15AFC_080120_VLV_081520.docdoc 458c321276db8b07aa2b87bfb9720a649e7f31002a3fa0caee33ae8e1c8302acVirustotal results 44.07%Heodo
2020-08-15DOC_PO_08152020EX.docdoc e3dc10847c610fb756b701eb6c9eff581d98adda60bbd1df9ca1c41f43e6710fVirustotal results 45.00%Heodo
2020-08-15FILE_PO_08152020EX.docdoc 72af635d51194d2ab428924c2c7f51aa4a9d040e93566ed7302ed43f5fa16eedVirustotal results 38.98%Heodo
2020-08-15BAL_SFG_080120_IBW_081520.docdoc b165a72e79277f849a4ef95a5f985c8d4c92c6685bdeedd4326c941c9931c1c8Virustotal results 41.07%Heodo
2020-08-13DOC_XOF_080120_YSH_081320.docdoc 9ad97679cbee7aac235985d49340c9b7f81becacdc6718cadc94648869514682Virustotal results 32.79%Heodo
2020-08-135054704801.docdoc 8c8c709e2b7cfd3dce74062f2564bef84cafcc329cbfcafbc2c056c35cc38c50n/aHeodo
2020-08-13REP_YJL_080120_NGG_081320.docdoc 5dfe99bdd766418f029d534146438a97818581f989d4b2ebf5f92179344000c0Virustotal results 30.00%Heodo
2020-08-13SBV_5A1J64L2I2Z.docdoc 0532eadbdda96ceadb7250d379491c1bb64d6d40b96bc71d551268896fd4bdd6Virustotal results 28.33%Heodo
2020-08-13BAL_JJ1079179709VT.docdoc 8a0a74b31fb30ce1a4adbaa3945c4186c7d467268e76b9ca802905b7cf5fa54eVirustotal results 29.51%Heodo
2020-08-13DOC_PO_08132020EX.docdoc 8acced4ab7dda88cd9bc9ce01d2f5cc3a725971c8bcf1fd1b9a6bf4653fa0000n/aHeodo
2020-08-13NHT_080120_YZK_081320.docdoc 4b99e8df8f724bfea2f32a9274cf4aa0f41b3e57a2b1ec753b17514149c670b2n/aHeodo
2020-08-13FILE_C79PIVEGWI9O.docdoc bd7871f1fceddc02727f3be310e4507aa75ac650a9319a03989d0a1c18bc74cdn/aHeodo
2020-08-13REP_12442733.docdoc 9544785ab882041f58e5879a9cbadb6d7058982180ead9e1eef44adf3b92fca1n/aHeodo
2020-08-13I_31260352.docdoc 44a4e9297c1d0191631e49532aa755b5a7928836c63b7a9f37deb77293cf2ec7Virustotal results 30.00%Heodo