URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ugl.ch/administrator/cache/payment/45344621454/VNngG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:445527
URL: http://www.ugl.ch/administrator/cache/payment/45344621454/VNngG/
URL Status:Offline
Host: www.ugl.ch
Date added:2020-08-27 22:12:05 UTC
Last online:2020-08-28 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-27 22:14:03 UTC to abuse{at}infomaniak[dot]ch)
Takedown time:9 hours, 34 minutes Good (down since 2020-08-28 07:48:11 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-28Inv. 0296930.docdoc 717e95cf51d45cf596aabdf52e31383a32dea1d2e41d90601b9d8176d44f588cVirustotal results 30.51%Heodo
2020-08-28Form - Aug 28, 2020.docdoc 2012064cfc4ba5e01f3677d2f52053612232c932876a8266ac2bd8bd8a35af6bVirustotal results 31.58%Heodo
2020-08-28INV #04986192 FOR PO #008185857967.docdoc 1d2b270375ae00907412647180a7dffae422dac066c42966c9cca4bd1dd8dfe2n/aHeodo
2020-08-28OKA-080120 CURM-082820.docdoc 7e0d6fc8bc7a69d5e27e2130c83b434512af52a5337145098c2426f62abf97eeVirustotal results 33.33%Heodo
2020-08-27invoice.docdoc b1f8d82d19d6020ac3606afc8e0699ddde66a03ce07d5d7f6b6bc45a238084f2n/aHeodo
2020-08-27August Invoice.docdoc 474fe5a4009da897047f91b9d9b8f40aaa5d674955f0815934507029c7038976Virustotal results 33.90%Heodo
2020-08-27FNK-080120 FWJU-082820.docdoc 7314c132ed2bd783a95997d7bb4306ebfb97de0cd23e31c78dbf77ebb4dd61efn/a Heodo
2020-08-27Invoice #081.docdoc 97dfe06b3f4e9ebb2beb149355b82886fe468ce91c30adb82a16097ec15cbdfdVirustotal results 33.33%Heodo
2020-08-27Inv. 04335102469.docdoc 55729022c3684fd899ee712d0d0d3dbfeb5161fa842b101cd28dfcf85ead1a74n/aHeodo
2020-08-27Electronic form.docdoc 49bba49f3424d943a1dcdbacda92160af1c9df3b59ef884accef905c247edc11n/aHeodo