URLhaus Database

You are currently viewing the URLhaus database entry for https://saifood.in/wp-content/2170860580/qsw9mn0j/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:518050
URL: https://saifood.in/wp-content/2170860580/qsw9mn0j/
URL Status:Offline
Host: saifood.in
Date added:2020-09-15 17:50:35 UTC
Last online:2020-09-15 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-15 17:52:29 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 hours, 11 minutes Good (down since 2020-09-15 20:04:01 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-15DOC_PO_09152020EX.docdoc 82c25613755c7a3a9737fe08cbc7fae6d75faa2807218b65d6b5a6dfb1bbff67Virustotal results 32.20%Heodo
2020-09-15M_84448687969006365727.docdoc c6cc0bc5f638343530d50e465ee7b0a2cf952d971f2d50d1b26c5ff8d2068280Virustotal results 31.03%Heodo
2020-09-15INV_KV4306384209DU.docdoc 1c6ce51748a1b4bdc97378a6091b03df69c39d6ec6185382608edd0355ae0bf5Virustotal results 32.20%Heodo
2020-09-15REP_ZOQ_090120_QTU_091520.docdoc b98c6bb5f406dd831d675d835a86587322ffbbcf4e47b5a01c471fad167f8cfan/aHeodo
2020-09-15FILE_VDI3VU7UQ5JB.docdoc 234abcda5234527fd9e5441e8bcb123edbc786548ab844a1b481642bfa9a4e29Virustotal results 30.51%Heodo
2020-09-1535042967748380.docdoc df8e3bb8218a241d663a81c536d1ce5f64b91ade8fb09dbdc183006ab9e901a0n/aHeodo
2020-09-1589151237.docdoc 29e6800b32fe83e4c3eea894351d851e0ba7013aa256aa96ca27b0423fe084d8Virustotal results 30.00%Heodo