URLhaus Database

You are currently viewing the URLhaus database entry for http://debtwatchdogs.com/sys-cache/9pq5jbjx78i/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:698285
URL: http://debtwatchdogs.com/sys-cache/9pq5jbjx78i/
URL Status:Offline
Host: debtwatchdogs.com
Date added:2020-10-15 18:34:04 UTC
Last online:2020-10-17 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 18:36:07 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:1 day, 12 hours, 40 minutes Poor (down since 2020-10-17 07:16:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17PO_10172020EX.docdoc 02730b23749bb5e945d78771425520fe94a15b5647f34a7efeca54a72c9297c9Virustotal results 52.46%Heodo
2020-10-17PO_10172020EX.docdoc db234da6bba5f671c8a6fad07cfc6ad7ce1b078a32f920e2edb4b142167e18dcVirustotal results 51.61%Heodo
2020-10-17X_80802959.docdoc fd0ec2733cb7fc4d8f934cf81b56a9a6fd2dd7290c257cdf4c2a1b3da2bcfc10Virustotal results 51.61%Heodo
2020-10-17WAQR_TU2411326099YB.docdoc 5990f98a0aeffb24181deb144a8519e54f7695794e545b9ba0cb52fe28e3f987Virustotal results 50.00%Heodo
2020-10-17INV_GV1366054132LT.docdoc 8d9046f3f3aef8eaa74dbcc4aa33811b0f06438b3c4fd36bda76c6190da4f669Virustotal results 50.00%Heodo
2020-10-17267587150931410457.docdoc 1f9fcb8ad3585c6cbf7250308fc58ebd7fd913baf350cbd3d7fd8934c9e33e43Virustotal results 50.00%Heodo
2020-10-16DOC_G42GT1I0MAZAI.docdoc 3772d83153c2d54a8a3dd72055370d3db69948bf4eafeb69018ce518c7801d05Virustotal results 50.00%Heodo
2020-10-16015639276643.docdoc 2d4a3ae690cd64017a114de08ffb095c8208ca65f5647809600f6caf8ff7cd97Virustotal results 50.00%Heodo
2020-10-160OQT2DQK.docdoc 6647111dcc98f3a01470eee7de5a3b93b579a08c585cd3553cbfbdf3d54db556Virustotal results 48.39%Heodo
2020-10-16FILE_HWV_100120_NTF_101720.docdoc 1b2a426d5d7d5a0185640c82655ec40245f89ff62644ec1a04de9894a169114cVirustotal results 51.61%Heodo
2020-10-16REP_0VKHD86.docdoc 69bf38e708fcc10caf5824bb4460ed7f950dfb3085f715c81303b992c3bb6857Virustotal results 50.82%Heodo
2020-10-16INV_27652011490981652.docdoc ed7305c8affe8cff65cc112f1d79f66621e2632a8ec647ce7aa6817e738b989fVirustotal results 51.61%Heodo
2020-10-16140276197.docdoc f9e446821e7544fb3343aa3a069112853a802cfa173c8ff3650af2faf9b22caeVirustotal results 53.33%Heodo
2020-10-16DOC_KL6058416342IY.docdoc 30e4cb15ec8c1e838060a3e4fa642919313c6b9c0e9b3eee6cb507eee695f828Virustotal results 46.77%Heodo
2020-10-16KF9349045943CH.docdoc 81142095ca7067d93c133d0df243493b2a602818aa45374296436668bfa14b59Virustotal results 50.85%Heodo
2020-10-16FNE_21790706.docdoc 2069708e26eb58f872b15305b2443d1fd546458a653b01f5f0fabb291e3d4dean/aHeodo
2020-10-16INV_TOQ_100120_DVQ_101620.docdoc 11c67e93ede508aef0bb3d1c43fd0dcc4109fa2c3c93811c94f36094662b2c23Virustotal results 47.54%Heodo
2020-10-16395YC5J.docdoc 5d3294aeac345f3c7f5fc36fafe0997b3a7140045bb1b001649713f9ecf5002bVirustotal results 41.94%Heodo
2020-10-16D_LRR_100120_UCL_101620.docdoc cd0d5e141f44055a552beea578018b7eecae25b9d5cecd2fd128f4d3d7a87a30Virustotal results 40.32%Heodo
2020-10-16ZI_058555263435842.docdoc a9ae456f451a63c2762f0224c66ba47edee2217b42c275e003a2e62382ef69e9Virustotal results 32.26%Heodo
2020-10-16FILE_1MKPL1SXGIROI2R.docdoc 3b29c8e3eb58dc756778fe366c1768a95e278d08ac62156cef908400044ddbc9Virustotal results 30.65%Heodo
2020-10-16INV_N84V89OG.docdoc 74f63318ba7dd16ddae51e0b9e1e8a253d02156b7ccdbc947aa9559b49ed49a4Virustotal results 30.65%Heodo
2020-10-16TIX_100120_RUN_101620.docdoc 8f3f984fbd71cc396aa42dd0f50f3368055a81b68e63712dfe482c04b6ac804eVirustotal results 30.65%Heodo
2020-10-16DOC_24200014.docdoc 6a0b601c431187f4680301122156322706726f05eedf22684295042c3277df8an/aHeodo
2020-10-16W_00586786.docdoc 9e16a1c487318559bca602d0c341d760109650549d600ab32ea6c5b07b9c838dVirustotal results 33.33%Heodo
2020-10-16PO_10162020EX.docdoc a74b230d5a83dd721b98493e0a752cd0f9d6739bc4ff6f0046b798fa98513fbaVirustotal results 32.79%Heodo
2020-10-16FPB_100120_LSC_101620.docdoc 3550b173f084aabdd854dc658b31eeac18f28c421c23052d45d5e8a92f8a3e93Virustotal results 32.26%Heodo
2020-10-16SR3939652363JW.docdoc 63409e6742b521d02cfb6f833ee7484c6db70237e48675a06c28cc7c9920bfe5Virustotal results 50.00%Heodo
2020-10-15T_88519299856583.docdoc c092eeeaefd8e9d4c328cc78e77530cb40fc820d921ce06c271c47781aae2da4Virustotal results 48.39%Heodo
2020-10-15BAL_7116042538068975360125.docdoc 2889aa2818bb6b697ece0258b29a039f5f46f85444792ecad4d3667806bb5610Virustotal results 50.00%Heodo
2020-10-15BAL_94138702.docdoc ab321ed0f56034ac636d328802440c291af5a379fee4ff6b31fbc859ab2d9004Virustotal results 52.46%Heodo
2020-10-15FILE_SU5531117807RR.docdoc 9ff3fa5bcfc5a9b21abf19a4f8f3c406f0874fd93f8508c58e42529f672a6d23Virustotal results 48.39%Heodo
2020-10-159880567463475607.docdoc 2ea42eea9abe81ee4415154eabd2fc00bb951b3a234e1b3ef9e824d77ee97732n/aHeodo
2020-10-15DOC_37317953.docdoc b9bb517022d0b2c98532d6239bd55d7a33911467a4ca1d6c8d69736530a6157aVirustotal results 46.77%Heodo
2020-10-15FILE_43662130.docdoc 52cc4044252ebba622acceb8374c67dac01416c08fc26a5a1e366be2d6a475aeVirustotal results 47.54%Heodo
2020-10-15REP_PO_10152020EX.docdoc f0abef25579afd4a06a70b4a55ce9b492df87c17b66b1949f541f679f6376b84n/aHeodo
2020-10-15DOC_S8R8YAG53PG.docdoc 4175a2dd2295146108a2fb6d370f0d24239715d3709a82c0c6ec420a962efe90n/aHeodo
2020-10-15INV_11314510.docdoc 3a655449935db1d07871d79739c4fe01d8792844b72e4bc0c3f2c936b6d5ee1fVirustotal results 43.55%Heodo
2020-10-15REP_272014580037979.docdoc 39c25de18abaccdff5bdbe5fb490b60e00e8b38d1c30556115d11f468d4b6a76Virustotal results 45.16%Heodo