URLhaus Database

You are currently viewing the URLhaus database entry for http://propertywatch.ng/alfacgiapi/https://Zinu7D92Vmlk9vgkvXPO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452617
URL: http://propertywatch.ng/alfacgiapi/https://Zinu7D92Vmlk9vgkvXPO/
URL Status:Offline
Host: propertywatch.ng
Date added:2020-09-03 18:01:27 UTC
Last online:2020-09-03 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 18:02:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 15 minutes Good (down since 2020-09-03 20:17:56 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03list_20200903_YKM779.docdoc b16cdb69a8c0fb85792f37b8a979b0e3e9fe8abb6ee2dd5a0d21c50b8400720eVirustotal results 28.81%Heodo
2020-09-03Rep_20200903_53974.docdoc bbb8481db8d91e443182bfc4898ed75ed829f7120eec1117572bc21d3c7f611bn/aHeodo
2020-09-03inf O9082.docdoc f70cea3bda98140e023f339d8c5ebd63935b269da5f1dc201819cc9d2a8dc78fVirustotal results 26.67%Heodo
2020-09-03Attachment 6639304.docdoc 509ecb6a2610738956ebdf8a885bdb413fe84bd8143e1012a1fb4a4e14333d19Virustotal results 23.73%Heodo
2020-09-03Mes-20200903-VI689787.docdoc 88c16f598ab3e2ae31833ecde0a55057c723a25101a16540d55fe86ea861fe2dn/aHeodo
2020-09-0300243YKO 20200903 855.docdoc bc4ee7e49e05ab462e199c1a2635de8de23b9ca32d8c7634cc4902f425967e22Virustotal results 23.33%Heodo
2020-09-03Inf_7355.docdoc 63930b14af729c7269381e50fe9d2aa5c1e270c629023c4a39564d39ef0d42f0Virustotal results 23.33%Heodo
2020-09-03Mes 94587.docdoc e6c4accc4dc0b7466fe7c7fb8bde85ef87a0604f53bdf089c2def419214f14faVirustotal results 22.03%Heodo
2020-09-03File XFV9914.docdoc 7542089a9b48b8812b9b4746ac6fff006e18134f861730e1c85c4cfadcebd7d5n/aHeodo
2020-09-03inf_2020_09_03_KH566.docdoc 86bcb8fe918dc1b3fdc5a6ff0902527872723b002108c86f14be504b2a9c295en/aHeodo