URLhaus Database

You are currently viewing the URLhaus database entry for https://passoapasso.giving.agency/sys-cache/browse/6jgwwg7kmhw/8acjsx5sd7rdjp/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:693483
URL: https://passoapasso.giving.agency/sys-cache/browse/6jgwwg7kmhw/8acjsx5sd7rdjp/
URL Status:Offline
Host: passoapasso.giving.agency
Date added:2020-10-14 17:15:04 UTC
Last online:2020-10-14 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 17:16:02 UTC to abuse{at}amazonaws[dot]com)
Takedown time:4 hours, 8 minutes Good (down since 2020-10-14 21:24:18 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-14INV_PO_10142020EX.docdoc 3f22f924db8066982fcf6f6b72ce5e37a76a15db8a9fd7e10e0123529da3c28fVirustotal results 26.23%Heodo
2020-10-14T_KFD_100120_ERS_101420.docdoc 0d4936ae5e3283118f9e06740ac00c8fb354fd8ae5abe43d0ee6b3bdd1cc56e9Virustotal results 32.26%Heodo
2020-10-14401634665044203326.docdoc b4cf90104e1c633a207abdb3339c42f5439bf889fc1c9129d7fbdf41ef337999Virustotal results 27.42%Heodo
2020-10-14BAL_2956374247254.docdoc aa08af368a5160b9286b65057e96e42aba63933c677ed3bc930d3357d7b40176Virustotal results 29.03%Heodo
2020-10-14980526045920307.docdoc f1c1bd706f5e8baa7c955366898faf470b2b4f44037c26a07320c45900d7e6eaVirustotal results 30.65%Heodo
2020-10-14REP_PHR_100120_LCY_101420.docdoc d35a361ae4f33701ef64ed5127d5ebfb837ddb2f32f33ec1fd399c422074f947n/aHeodo
2020-10-14OVC_100120_RFF_101420.docdoc 11b6433cc50996eaa60f48be87ac8627f7ef22e82111415e743daee3d32b613aVirustotal results 29.03%Heodo
2020-10-14CI1972733773EK.docdoc 7f12ac5050b001bf7409ea74f6b6dad0f8bd7d4fc74773887b8ed8e571d12ceaVirustotal results 27.87%Heodo
2020-10-14KTV_100120_PNS_101420.docdoc dc3a4798ba0993eadfbe6ccff855c67eb355ba48d62fbc5363b8297d9715ae40n/aHeodo
2020-10-14G_26002826.docdoc 266b94aef7020a8f128002d83bca80c054900d06c066a2e4223fddbcdbc9e7feVirustotal results 26.98%Heodo
2020-10-1474757018.docdoc cb95c0f075aa9b05d19137df3b3142fdc742e4bbe395125a71aa281a6083ed40n/aHeodo