URLhaus Database

You are currently viewing the URLhaus database entry for https://paymentsconsole.giving.agency/sys-cache/attachments/nj1kk6rrtrpdrh5o5faz9of854z/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:693877
URL: https://paymentsconsole.giving.agency/sys-cache/attachments/nj1kk6rrtrpdrh5o5faz9of854z/
URL Status:Offline
Host: paymentsconsole.giving.agency
Date added:2020-10-14 18:51:05 UTC
Last online:2021-02-04 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2020-10-14 18:52:34 UTC to abuse{at}amazonaws[dot]com)
Takedown time:3 months, 22 days, 22 hours, 7 minutes Bad (down since 2021-02-04 17:00:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-14VOM_100120_UKC_101520.docdoc 89805057d1a481cf26a6efd0f74ed731cefd3ee7547ac6f529a6cce3223f6d07Virustotal results 33.87%Heodo
2020-10-14DOC_WF8058598598OT.docdoc 9140235214871fd0aa4167f88aafd261126784ecf7c266b1f5678c46dc9be18dVirustotal results 31.15%Heodo
2020-10-14FILE_M9E2EN8.docdoc acac416cece30666385ae079cb90ec34a542354582617767f179f71cfc03384bn/aHeodo
2020-10-14W_70100713.docdoc 0d4936ae5e3283118f9e06740ac00c8fb354fd8ae5abe43d0ee6b3bdd1cc56e9Virustotal results 32.26%Heodo
2020-10-14DOC_91464684.docdoc b4cf90104e1c633a207abdb3339c42f5439bf889fc1c9129d7fbdf41ef337999Virustotal results 27.42%Heodo
2020-10-14BAL_PO_10142020EX.docdoc dff04a292f708be6dc651f4164c2f711a836eeab00529793693a3f25518a0341Virustotal results 27.42%Heodo
2020-10-14FU_IU1SV74NW2PN.docdoc f8682dff194df2aeec3387ee4554f0374cac8d776c24a84061dd127d67a86aefVirustotal results 27.42%Heodo
2020-10-14GMWT24J2WIQONV9.docdoc 11b6433cc50996eaa60f48be87ac8627f7ef22e82111415e743daee3d32b613an/aHeodo
2020-10-143QFAS9M35UUG.docdoc 1df6aef022d1cbf3066209efa10f084a0089988d6d488006d43ef433edf1cac3Virustotal results 29.03%Heodo