URLhaus Database

You are currently viewing the URLhaus database entry for http://onestepshops.com/cgi-bin/jiayecg421q92b_jz25a1lh2m_22863835_0lGFUoOO3iL588/guarded_space/r1iuo59zvl_4zzyx7ust286z9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435665
URL: http://onestepshops.com/cgi-bin/jiayecg421q92b_jz25a1lh2m_22863835_0lGFUoOO3iL588/guarded_space/r1iuo59zvl_4zzyx7ust286z9/
URL Status:Offline
Host: onestepshops.com
Date added:2020-08-18 13:43:05 UTC
Last online:2020-08-21 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002873769 created on 2020-08-18 13:44:04 UTC)
Takedown time:3 days, 4 hours, 6 minutes Bad (down since 2020-08-21 17:50:45 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-20Arc 2020_08_20.docdoc 48c065c3c6c626c7fca855686845bf480a74dd0902ae005eeea171dcb5237947Virustotal results 23.33%Heodo
2020-08-20doc 20200820 6590847.docdoc ce3ff108a607fa2314a8bcbced388fe05dd7231df86db8dbd4beb6271388f1cfVirustotal results 23.33%Heodo
2020-08-20DAT-4598.docdoc 9c9367c53706fa2ba5f1d7fb94dc1e4f88c020964733d83eb07c6b6df1e54c3cVirustotal results 23.33%Heodo
2020-08-20inf-2020_08_20-ASJ04593.docdoc 0cfb318d3d085c288f88aec1cfef6e9e6671ca0e72ca39b712957286a6c42747Virustotal results 22.03%Heodo
2020-08-20Arc-536.docdoc 2a69cd4b1c4563c571abd485da746b2f91dc64d32b0e037496dcf024c2356910Virustotal results 21.67%Heodo
2020-08-20INF-80520.docdoc 4ac73bdfeff908fb80f6ec1d6ced2c7fc24d9cb440e5a5334565fd31532b78faVirustotal results 22.03%Heodo
2020-08-20Doc_20200820_266.docdoc c11d62723af7a6fe384f8bba4caebff15e9e0888fc230a14099888cbe4e058adVirustotal results 22.03%Heodo
2020-08-20Mes-OZW941.docdoc bb5c7cc50314e29b5bec47c7124033a531be632d03166dfce846d84e393148daVirustotal results 21.67%Heodo
2020-08-20REP.docdoc 17c8b3b54c7d7a0b30e549b7ad0f567dead7d06419ad75bc8426607ffef84e41Virustotal results 21.67%Heodo
2020-08-20List_20200820_V157.docdoc bd0d2e2b677ac399c561156e9044105cc1b264a82b831046eb87c508d58359ebVirustotal results 21.67%Heodo
2020-08-20LIST_20200820_EF6003.docdoc 953b662d9aef02326fea06afebcb2c0f499bf6075210cee6bc361cbf62c74c8bVirustotal results 22.03%Heodo
2020-08-20DAT.docdoc c0f5f0a1aa4c69b6453e9e1156ce1e886eb92d0b1114a63c47ae2ab0f4923841Virustotal results 21.67%Heodo
2020-08-20FILE 2020_08_20 268875.docdoc a6495ce0634ebce9b181f45914574e07b54400238c8a8eeeacd6516ccce7752dVirustotal results 43.10%Heodo
2020-08-20Inf 20200820 JHX972.docdoc 8f6788d862d18d0671375430af4c756bc9cdc6b99663b5df0842840a77af44d3Virustotal results 38.33%Heodo
2020-08-20MES_995405.docdoc 89b6ed4e8a0cf8a07e457b0f616f06fc4770fd168802ee6180994858453dc3f3Virustotal results 40.00%Heodo
2020-08-20FILE-2020_08_20-GUE8444.docdoc f6393c7e4e0b8603bbf2de4f4a138e6002e14b472d8d79514ed04a38bb6abd79Virustotal results 40.68%Heodo
2020-08-20Arc_XU080938.docdoc 67a3761b4abfe902aeefe85f6d92576b90564d706f24a08b54b1e90e5cec0105Virustotal results 40.00%Heodo
2020-08-20Rep_DL311600.docdoc 62ec1bd0426af880a8212346e5dd56fa705a031c9b838cba9dc012e37a661ceaVirustotal results 43.10%Heodo
2020-08-20File_2020_08_20_469345.docdoc 139d96003a5964f811cfd1d2a1c28130de97b7b0a548b04e7eb8dbf7331d94e3Virustotal results 40.68%Heodo
2020-08-20FILE_20200820_4146.docdoc b520ba622b83b81208d66821aeb38a6d30a8f9a5a4043f69bcd2cec19db40e19Virustotal results 36.67%Heodo
2020-08-20Arc VD0399.docdoc 55c3d321b60e04d0d240475060336ab053b3707e5493082cd69d464b0dda2beaVirustotal results 38.33%Heodo
2020-08-20dat 2020_08_20 75300.docdoc 38910d48a5b54e7d0b4f33b6ae9ff7668cb5a8ea4b8895d894b73115cf8d3596Virustotal results 38.33%Heodo
2020-08-20ARC-CEU69586.docdoc 744029fece917740a88f43a6f35c563dce6abb340e34652085620785547883e6Virustotal results 36.67%Heodo
2020-08-20Rep.docdoc b9dd0c46c40a59f5ee13585b936980a4e93d12bace98f342421fbb63fc15a460Virustotal results 38.98%Heodo
2020-08-20list_2020_08_20_GPP035061.docdoc fa5fd14228252426c8224b795502a3ba3af894cc4117e8247d8bc9901d4a2588Virustotal results 38.33%Heodo
2020-08-20LIST-W095.docdoc 34df63aaf08820ef807a0992d54df52142bea2fc2135e5f4012ab9f1f89aaac9Virustotal results 38.33%Heodo
2020-08-20dat_2020_08_20_039323.docdoc 4a3130ce997517653b96c59865fc6c7a60a0c6444c2a7c8a5a8d93fd1dbbc6b2Virustotal results 38.33%Heodo
2020-08-20doc_2020_08_20_D676340.docdoc 9ea89a24c2efb06595aa09d8d9dc8ac79ad4a9df0d0d99a7fd5fe63fe9e1f7f8Virustotal results 38.33%Heodo
2020-08-20File_20200820_37763.docdoc b9c36d0ae81127e9a86b1e0fa168ac30bc961720617f9aba50858f99186786d0Virustotal results 38.33%Heodo
2020-08-20Doc_20200820_K9551.docdoc d328fbbc3e82b9e2db08fbfcc9d4554921637299f82f0cd330253529ba130219Virustotal results 32.76%Heodo
2020-08-19Inf-854.docdoc 763cc0ddbf92ab735d7975d8e7137950d402f8475ab7f08f1e332940e4dbdd05n/aHeodo
2020-08-19list_2020_08_20_G392.docdoc 3209a90ec70f3c389ad600fad212afe06d4d60c9ebf4535af52b590f95c642d5Virustotal results 27.12%Heodo
2020-08-19File_20200820.docdoc 18f2491dcef8d7f0113049e146994fc5a8fc1615ff0fbbd659fa0a5d580ea72dVirustotal results 28.07%Heodo
2020-08-19MES 20200819 CI005000.docdoc c940432dc1875cdb1adfbda4eb2c3a23b3a10fd0a53cf12cc32e79389120b5d8Virustotal results 26.67%Heodo
2020-08-19ARC 2020_08_19 9530.docdoc 49332870601ca0a8710ad69eb2e09ff1952cd8c9d843fad20ce04ad0b8de8546Virustotal results 26.67%Heodo
2020-08-19arc_EM671963.docdoc 7b1214f3fa1a87909df1dc2aaf3d66f4ef5ebe9cc2a8040bffa44e44e28ae36bVirustotal results 26.67%Heodo
2020-08-19File 20200819 RR763645.docdoc 949d5111399eaea6135927548fb0154fd3b99217f2e5556ee5b7efb4eeb8d813Virustotal results 27.12%Heodo
2020-08-19list-126015.docdoc b6bc398b50e53b9134174954be2711af3ba4a2715a4407db570f3f0ab63c81bdVirustotal results 26.32%Heodo
2020-08-19DAT_20200819_263985.docdoc 7c9a4d56c192bd2e71e2098965b8affdfaf10cc6e3e5ced40ede0fd1c947d50eVirustotal results 27.12%Heodo
2020-08-19arc-20200819-667.docdoc 1974d9df785e9c234899f09030fb1e99b007709c6ed249e4e8b2fc080df7ff16Virustotal results 26.67%Heodo
2020-08-19ARC 2020_08_19 7410.docdoc 621f57169211edd6bfa1215035b4b15f300b7356aa6f3c40a716b29b9c2f0db6Virustotal results 27.12%Heodo
2020-08-19Rep 2020_08_19 FOS2726.docdoc 183d1e6553bd3b1cee00fca671146b0924641e30b98303d75d1d944d084bccf6Virustotal results 26.67%Heodo
2020-08-19Rep 2020_08_19 WFC5624.docdoc 60583244e23ce73f1033463f27a56403be325eef59cb3050e85c5265d2cbcb3bVirustotal results 25.00%Heodo
2020-08-19dat-UY15892.docdoc 4f49566c22cd95508f39368f73be4e9b6c9c8e504c519f2383cc00fb67d28c55Virustotal results 23.73%Heodo
2020-08-19Mes-70210.docdoc 66915150d26a0500bee5a47eef810f6d5ef9c9a9282973f17b3e434bac5600bfn/aHeodo
2020-08-19ARC_20200819_08207.docdoc 0ce5e53c8098dbfc4fd1e58da405b66f8289522b964544eaa585a1094562edd9Virustotal results 22.03%Heodo
2020-08-19Arc_GNN6032.docdoc c39bb34670a35b5275e2087959a8cd74dc36504378b84cf5040950caaea3ebedVirustotal results 19.67%Heodo
2020-08-19FILE 2020_08_19 LP428590.docdoc ce2cccaa128b1df5c8ca3da6be23ca4d16075f145df2a84a9ad382bcd78dbd73Virustotal results 20.00%Heodo
2020-08-19Inf_20200819_FCV159.docdoc fc2f45f39f8109fea4895e2ba18c63719f2189980ad4ba3adda2cbe7a852dac3Virustotal results 20.00%Heodo
2020-08-19ARC-2020_08_19-307.docdoc ff3dae4dba7055a170bde6b5cd1c62c47c680d32b65e19ea32fc4af41f8c3f06Virustotal results 20.00%Heodo
2020-08-19Dat_2020_08_19_859656.docdoc 1e1bd9b8516ba6602eafeeb65a0fd430014d63b18bb637cc352f7f55ccd80332Virustotal results 20.00%Heodo
2020-08-19Dat_20200819_533.docdoc 124ae2447478f4b71404f5f07ea89abe4b985e402955ebcd02fb67b27939de31Virustotal results 19.30%Heodo
2020-08-19file 20200819 342427.docdoc 0438242a3ca04ab173d67a0fcf3cad13a9cfaffc01aac04ffe0050024bc471f3Virustotal results 20.00%Heodo
2020-08-19File-2020_08_19.docdoc 681b60c42182e1e44908749abbbdcf6b53a3cdb654acb4630f41348068d297ceVirustotal results 18.64%Heodo
2020-08-19Arc-2020_08_19-3332622.docdoc 8c8c9a461837ed77d0dcfda29092e08452817660cf5a56a7e9547741960e43dcn/aHeodo
2020-08-19INF W76993.docdoc 003331c267448f379ec242d8b35b9d556baeba21e8b8a542eeb3886871df8d0cn/aHeodo
2020-08-19doc_42592.docdoc e9da8132017bc36f1448def9ba8b2ea44184e68bf955c08ba75f2560ade79372Virustotal results 18.33%Heodo
2020-08-19Arc_20200819_SAO893016.docdoc 355ae9ce7f18c1cd0e3f82cba9251b9b368cb11edb902fe09e6d8d4a471d5091Virustotal results 18.33%Heodo
2020-08-19inf_20200819_71816.docdoc 4798faf76258c8ed12cd2d43a683e3c56b6fadbcbc5b6e7a797ca73e76ed49dfVirustotal results 18.18%Heodo
2020-08-19inf-20200819-QOZ1128.docdoc 4d67ba7b02437c5005b0ea3c12d97bbc3b42df9a30b2f85c525446f1cee37b2fn/aHeodo
2020-08-19Mes-20200819-GJX265376.docdoc 55243fe4d8aaffb5742798883e5ebb342f4cbf5eb2b4ea32c0f3603c658ddc93Virustotal results 18.64%Heodo
2020-08-19file_2020_08_19_PD1262.docdoc 36ba95c1057a9ae52d37138e2d2e3d6a062e0c0aec687ece18259b238fd439b4Virustotal results 18.87%Heodo
2020-08-19Inf-2020_08_19-B17694.docdoc 06a4431e2a5467fd8f9c297a6a25e670ee44231c92dd38d8f998a3a93115f0c9Virustotal results 18.33%Heodo
2020-08-19Dat 2020_08_19 UY16613.docdoc e539186195154e173115f68e790dac9a32909a8c4344a387ce25fba6fbf55d27Virustotal results 18.33%Heodo
2020-08-19file 20200819 H731055.docdoc ec04bee2423d5f00191bc124105d869b664321f61b553a0d1b7335989bfce7bbVirustotal results 17.54%Heodo
2020-08-19rep 8431.docdoc 92d96fb1b1020da8494603f46e6a2fa6264b69688537b879fbd01f229d3ca1a9Virustotal results 18.18%Heodo
2020-08-19rep_2859948.docdoc 1dd9e898cf2ef400f93bb6759c7453980dc396b70c7c8748055db01b62685f2aVirustotal results 18.64%Heodo
2020-08-19Inf-20200819-H61210.docdoc c94255c1e218f6578be80a7dd64f4d75acb2c91812aa436908f37c81d531df90Virustotal results 19.67%Heodo
2020-08-19inf_2020_08_19.docdoc 2dea73b6391db01c0900ef660c75b0841dcb9fd8fd91c892a5faee2e9701606eVirustotal results 48.28%Heodo
2020-08-19REP_2020_08_19_063.docdoc a09fb497ce5738081489fafa343ed354128eba16cc5f8f6bfbb26ff79e19ceebVirustotal results 47.46%Heodo
2020-08-19MES YXZ3808.docdoc 1c98753feb43790bf0b2979ae0d73c4760638ab1d9c5d6b6336ce2241ba31aa4Virustotal results 45.76%Heodo
2020-08-19MES 2020_08_19 781.docdoc 305d205cdb3c030f05543db463c783753137d91a3d8c2721189a94fb36e4f7c6Virustotal results 47.46%Heodo
2020-08-19MES_JO20099.docdoc 7065577cfc7f1d2a71a9044c23838d7703f1a1e02b2c222ab507407a778aae24Virustotal results 47.46%Heodo
2020-08-19REP 2020_08_19 5526.docdoc e5b01db94661c2b883ef2842c74fb6f95c34c13ba556efde6c2877c168a5204bVirustotal results 46.43%Heodo
2020-08-19Rep-20200819-XPU95113.docdoc af3f70492545cd6391ad67cedb9347c9e78980d2462b1b1a6b656113d246e010Virustotal results 46.67%Heodo
2020-08-19List 20200819.docdoc 8ecfd0e0dbd4257b0b0f97f99517f9d1d825e32d7862b1ceb1b6bfdc67b205a0Virustotal results 45.76%Heodo
2020-08-19FILE-20200819-0966116.docdoc 9f95680d93e52258b33600da99d066d953f0aa373f991d850e83ae0e050fdb4eVirustotal results 45.76%Heodo
2020-08-19ARC 2020_08_19 1327.docdoc 7916fa0619bd4a976c48a8b068040591dd8f78f9eb5b2bd3abafc019ec1f0dadn/aHeodo
2020-08-19INF-20200819-WOL06009.docdoc bed0745c35c33e15125967c2bd9523522638c0a7e10d38d2d100097a5767941bVirustotal results 45.00%Heodo
2020-08-19ARC 2020_08_19 185.docdoc 682cb4ff880f1a6a000f5a227f8dba42abd73d836308162dc519644d9dae94efVirustotal results 45.76%Heodo
2020-08-19Mes_SOS5987.docdoc 45a1dbdb6b372ed28b9806469cbe031baa76035067cb69b5e936960e53988a80Virustotal results 44.83%Heodo
2020-08-19inf 2020_08_19.docdoc 7833c0d39d11142241550af1fa9cb743026dc00c841f79a52d695fd8e9bfdd43Virustotal results 46.67%Heodo
2020-08-19File 20200819 O1961.docdoc eb36ddd9edb9f64c1d10743135f87875826990fee2cde8abfcc653b1045c9061Virustotal results 46.67%Heodo
2020-08-19mes-2020_08_19.docdoc 5df568ab274842e91a3f5717af61fdbe6827249fc71e135fdc493f5177ccac7aVirustotal results 46.67%Heodo
2020-08-18ARC_48780.docdoc 5644494f53e0f58e39e8c623b06d33e093d920e7728632366beaa74ce3ce75a2Virustotal results 43.33%Heodo
2020-08-18rep 76815.docdoc 276103362e47f26f80bc04fff0f98df32d19fb0693919ac618f3c6f3c8350aabVirustotal results 45.00%Heodo
2020-08-18Arc_20200819.docdoc f7f2b55cdbf9f24f6e1850b32aa87b859717f840d46caff776674a973d28d51cVirustotal results 43.33%Heodo
2020-08-18doc_2020_08_19_49653.docdoc 5fe3b8e6945f1fd2e0c85c1b8cf1c0969965447dcb9d72deb04c28e05c9116b4Virustotal results 44.07%Heodo
2020-08-18Dat 20200819 1750.docdoc 1a586ed406130c0ed7d070f24ccb79ee1b6f0b4a3f47373cfa6285ed1ee322b9Virustotal results 43.33%Heodo
2020-08-18INF_20200818_YA565.docdoc 17300227be521550f2f2047dc5be4dcad326b59b87378c8a1372dbc867fb29c8n/aHeodo
2020-08-18Dat BS643371.docdoc 2df5b20d8f749d1edb14c16c6c1c1ce78165354f3d038a23ac8d4d99188391bfVirustotal results 44.26%Heodo
2020-08-18REP 2020_08_18 W470811.docdoc 8eff0446f444542435bf1ea66d34ac5b2339a87d7702ba744f403dc5ec5d4795Virustotal results 44.07%Heodo
2020-08-18Doc_20200818_UY55553.docdoc 2665e27cc12b9a111b35b73a7afd85da8a5d1877d6270f6d8ea48edd2acc0718Virustotal results 42.62%Heodo
2020-08-18File-20200818-05020.docdoc 52386a3f4ed721abc491a22e4d08ba4497e8392249b04e5fbcdcff39502cb314n/aHeodo
2020-08-18Dat-20200818-65597.docdoc 0b363d06eef3483aa25d2de2db90bbc7f005cdff8f14bcbd6f44f29676696a5bVirustotal results 38.33%Heodo
2020-08-18Mes_20200818.docdoc 1ce1aeae00cd890c114b881b3bf395f26890fec2d8373ae3fc4d0717274dd21fVirustotal results 40.68%Heodo
2020-08-18File_20200818_SW535372.docdoc cae4e9249f1219782d6c234dc44eab63930830f75ab90f4d533f0ddd3bacb745n/aHeodo
2020-08-18File 2020_08_18 93953.docdoc 4447568080893f02a97ee86ec9e776b6d5b4f7ea644870e130a19f3df9b16667Virustotal results 36.67%Heodo
2020-08-18list 20200818 1373374.docdoc b8ceb76e216625929c1a81fd2260e8b3ed97b6dda3a18f3054ef2fd575f7b15fn/aHeodo
2020-08-18Dat 2020_08_18 QOT7304.docdoc 8f959970d7700626885598cb613f8e0466e0d1f6def0930bc12f4e742f2617cbn/aHeodo
2020-08-18ARC_2020_08_18_PG291644.docdoc b9e74d54e9138fa7ef402b14aa1df4b1b59295bf0664eff87426820863baa337Virustotal results 30.00%Heodo
2020-08-18FILE_55057.docdoc 1ebc6066895cd6a2d840b1d65e7d6bf4d0b8de6ae8b9fafc74f6a63986818dadn/aHeodo