URLhaus Database

You are currently viewing the URLhaus database entry for http://nuwagi.com/old/GC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:433755
URL: http://nuwagi.com/old/GC/
URL Status:Offline
Host: nuwagi.com
Date added:2020-08-15 02:19:07 UTC
Last online:2021-03-30 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-15 02:20:04 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:7 months, 17 days, 5 hours, 6 minutes Bad (down since 2021-03-30 07:26:20 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15INVOICE XQT8945 14445510.docdoc b9d2bc9624f1e81b007fd1d89170294eb6eb29c779f83f4e75576a0fa3fa421aVirustotal results 41.38%Heodo
2020-08-15invoice 251 0054531.docdoc 62832607fcefbef56ee871dd3ef7d35bb36d9b2837e62a50dc05ccac097c6b72Virustotal results 41.38%Heodo
2020-08-15invoice-MY0751-145747038.docdoc e661e88652754e32269956878b435a3d8e7884d7af66fd23ec88f5ff1a59e235n/aHeodo
2020-08-15InvFSC8714565461.docdoc 715b876221f1b5e1bcb052a019ee033638ba9829c8ee712edc2ef66cc27c0e7dVirustotal results 40.68%Heodo
2020-08-15Inv AJRK0967 99137071.docdoc 39e1005ce7b833af7d15208f045080aff3d0cea6b1695169d52a4eebece6ed61Virustotal results 40.68%Heodo
2020-08-15Invoice-QKK972-917420464.docdoc dae18dd9a3dbbfc06b5e5c10fc7dc93c670a0c191d7cb7065e9d478503274567n/aHeodo
2020-08-15Invoice_I95_444206.docdoc fa32b3496f672c072efeef0acc1a6083d4a8512e1497629916d25cb5959b217dVirustotal results 41.67%Heodo
2020-08-15invoiceX5096921694.docdoc 5028de3ce60c62f1e99fcc961491a81d8a3315f89afef5015243cf80d77872fdVirustotal results 40.68%Heodo
2020-08-15invoice-J6-038488.docdoc 40f8be090c2e10a4175b11315d5adbd548b1a079fb450c6ff18b82b5ad0d75ccVirustotal results 40.68%Heodo
2020-08-15Invoice_PQT5612_7243673.docdoc f77afce2b8d4472fbcf09e30d3fddb8903ce48eebae03a294d7ca7819c07fdf5n/aHeodo
2020-08-15invoice-NDV5289-779643.docdoc b50b82d54433037c2321938527d4485ff439d6f6d5871ca14b88b0c887a51116Virustotal results 40.68%Heodo
2020-08-15Inv_FINQ3_510791.docdoc 4ac2ea7a4562ab7ea7c23ad733c0e4d0767936120e16b62e0248ce2af1beec1fVirustotal results 41.38%Heodo
2020-08-15Inv-BZ484-793988150.docdoc 94b9821024615e536b2196b18ad6a0c092e4030cc19a99f35d6cf7637a4a3eafVirustotal results 40.68%Heodo
2020-08-15invoice-CQU953-498440135.docdoc 0626485a74e0892c83b55a0cf767cdf3603df9603dfe205ff02ab869d24ec13dVirustotal results 43.10%Heodo
2020-08-15Invoice HCG7251 46403291.docdoc 3d3319da15a4774593968e93c815aabd17f3ccdd973793e8f372028cf510fbeaVirustotal results 39.66%Heodo
2020-08-15Invoice-BHQX9-0657967.docdoc b3b1d9de78d806f5d6869abbcf8eca4d70fc0167946479c7a173ac9729ef799eVirustotal results 40.68%Heodo
2020-08-15INVOICE-AB2668-17543488.docdoc 7685045c26c2b57ea45d561d8f6b9d4746939825e90633a6e3d72480686c1858Virustotal results 42.37%Heodo
2020-08-15InvoiceHU161997265.docdoc 8b3eedcae7d03df0cb4bd2ad3c213467e2eab49f9dcf7e10c91a71873e847c4cVirustotal results 42.11%Heodo