URLhaus Database

You are currently viewing the URLhaus database entry for http://shqczb.com/404/d0fcoo-2921/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:434785
URL: http://shqczb.com/404/d0fcoo-2921/
URL Status:Offline
Host: shqczb.com
Date added:2020-08-17 17:02:40 UTC
Last online:2020-08-18 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-17 17:04:02 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:9 hours, 40 minutes Good (down since 2020-08-18 02:44:42 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-18INVOICE-TXWW053-4074331.docdoc 1e7287370cc53c7ed5f90f379996dab92032b889d11133d6358713d54401c260Virustotal results 40.00%Heodo
2020-08-18INVOICE-X0074-4299655.docdoc 40f7770f2b4cf7b9278695e6fcea916099ecedae08d4f4b3070f3fb47feb413bVirustotal results 40.98%Heodo
2020-08-18invoice-DP0016-6779823.docdoc a3224bdb1c93e4cde36918c2078ed886cfb4ab92e19bdd94579ca9650643dcd6n/aHeodo
2020-08-18INVOICE-PF2-6558887.docdoc 22a9b83d6ba8df6e5d38c7c93c4c43ed12d0b45cfdba2aa3baa84a2cf2d35531Virustotal results 41.67%Heodo
2020-08-18INVOICESCRL0000584625968.docdoc 78592ac8692e506cbf84de53eb9e18f8758944a5bd60a40fdc7a5b11218af2c5Virustotal results 40.00%Heodo
2020-08-18invoice_Z000458_227546998.docdoc 34f6f3dfbf731cc3d87253cdb7a6cbf7cbbf8a47369e0ff4b5a2c966e8f2335bVirustotal results 42.37%Heodo
2020-08-18Invoice_0006_3880964.docdoc 77b91e171886421bc7a87ccccd572453071795281331490c3984b3601ca941a6Virustotal results 41.67%Heodo
2020-08-18invoiceWABX0042109269651.docdoc 92be4a79167b433e9a255723e3b6e3e3b01bc350cdaa6bc01a1cb46653bdc086Virustotal results 43.10%Heodo
2020-08-17Invoice-KT0003-859580943.docdoc 4cfd1a4d130209a42e6f1463451b36e01d0290a5b62df9a4b6a802eaa6580dc3Virustotal results 41.67%Heodo
2020-08-17invoice_957_973674610.docdoc 78a2cd40d747f3c621c50eadc47b9f15eb11a59b729dda17d525ae52a89cac41Virustotal results 42.37%Heodo
2020-08-17INVOICEZ000123143898.docdoc 8f519c2aaf3e05564df5221f4bf2f52e0ffb055e6f0466185ef43c721ad18757Virustotal results 42.37%Heodo
2020-08-17InvVMLF00000349782376.docdoc 32754532f0eb0205b94c93df24d8c8dfadf0769460b0983c124988bc8c3a267aVirustotal results 41.67%Heodo
2020-08-17Invoice_626_18603926.docdoc c194f0d9702a16ea1f8b9a5ffec32ddca75c5ab3076ad1e9d7e249fe6bab7d65Virustotal results 40.68%Heodo
2020-08-17INVOICEGVZ000067082966881.docdoc 4de2466dd0aa46843aac10caf6fa9ef8a414ee57491d87eff8e1a4d6d3b7a443Virustotal results 40.68% Heodo
2020-08-17INVOICE-KVHB05-2219749.docdoc 61ec87677af079740e9c49f8d26425ce9c1226a994c24e44e236880751d8dc14Virustotal results 39.66%Heodo
2020-08-17INVOICE_MAR0757_86818254.docdoc 69aad8b30bf71211ae9950bb6ba0f258d420597413f988aa094e5e6f15dae70bVirustotal results 36.21%Heodo
2020-08-17InvoiceM015180103.docdoc f5d638d5d64bfb767081e85f1be73d5d6d3bd697b9c44443f168ca765c3b207aVirustotal results 36.21%Heodo
2020-08-17Inv_GQDM0006184_332451.docdoc 4fa07d2b92390ce810b09723ccf48c59d24051c791428e3daed60edd9bbe8248Virustotal results 36.21%Heodo
2020-08-17INVOICE NV0109 389051.docdoc 00e63f775ab6754542ad3fc9901605f2f2deffc3c9b94042334f3dfaa2d57813n/aHeodo
2020-08-17INVOICE-0008856-756999115.docdoc 746d6b431ea0298e8c198ed25d40a2ebac830a9ab45a026e598b9b12da73d755Virustotal results 34.48%Heodo
2020-08-17Invoice_JQ0020_241448.docdoc 002fc17ef46f5a786a26f8463cd5ec94ae73ee28100e60d364eb8ac85e70a10an/aHeodo
2020-08-17invoice_MMV000558_4830665.docdoc a63fd6eac2ee50dc75e438aee7a9583cb97067bed45ed1c41a7ff5b6b3f89cf0Virustotal results 30.51%Heodo
2020-08-17invoice S000 7658525.docdoc 0858225435ef18d51362fbdf7228a8db3ed5b107ff8de17591a83a7366b936cfVirustotal results 28.81%Heodo
2020-08-17INVOICE 007 0821619.docdoc 19309ee1d5e957ad48c03b80e1e6df757b9ae11d767e2fc16a7400a126a88fd8n/aHeodo
2020-08-17INVOICERZL1988597992.docdoc 45aab90e927c3a36af0a42f1a9518728836182a36d4dda34d69a80aac9184d68Virustotal results 28.33%Heodo
2020-08-17INVOICE-MAQ2-76820203.docdoc 19f616fa8b36e081543ab44b72e5fae898845029fbc2dae6aa62cc7cfe3cefd0Virustotal results 27.12%Heodo
2020-08-17INVOICE ZJFG000847 512159692.docdoc b9878f3f33f338d3ea58d9e922b333821014a2aaf46a8d3b598c7a27aedac605Virustotal results 22.03%Heodo
2020-08-17invoice-JJ06-62513306.docdoc 8b03dc5fe55fec0064b3e0886526d6645dd239585dbd1aac5ccaa79d68bf51e4Virustotal results 22.03%Heodo
2020-08-17Inv_HM758_670272073.docdoc 49ae1440ca7ad2c718e9d8144098580b50956c65d95b8d31c3e511d7122e7286Virustotal results 22.03%Heodo
2020-08-17INVOICE-NWYF1-014139.docdoc 1fd07ddab4cb9aecb75208f1984ab69ba9f6fbfbed18307adcf8efe0bf7e3204n/aHeodo
2020-08-17Inv-OGA01435-5730399.docdoc 78914d1610f2b33ab56dc9c16f5d6ef36a1094b1e8349cc078a05c37da758c4bVirustotal results 22.03%Heodo
2020-08-17Invoice-C098-29332957.docdoc c44ddcbb54399b54e123f47cf9753dd6376799ce5b101f6a809e957d0b087a3fVirustotal results 22.03%Heodo