URLhaus Database

You are currently viewing the URLhaus database entry for http://surewin.com.my/wp-admin/Document/ZHruU2atdhXg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:717749
URL: http://surewin.com.my/wp-admin/Document/ZHruU2atdhXg/
URL Status:Offline
Host: surewin.com.my
Date added:2020-10-19 12:41:05 UTC
Last online:2020-10-19 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 12:42:03 UTC to abuse{at}shinjiru[dot]com[dot]my)
Takedown time:5 hours, 29 minutes Good (down since 2020-10-19 18:11:10 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-19ARC-20201019-F037571.docdoc f579a6044d9f764bd59abd53771cb8846744e24997e2d83e41a17a445578826dn/aHeodo
2020-10-19INF XNE33922.docdoc 82340ab044c23fbe6b78871b252c6d1db5fcc60f091df0da9452e8f946f8be03n/aHeodo
2020-10-19DAT-2020_10_19-103766.docdoc 4846b137d8cc5dae6ed7e1b3477444bca0adc09c3c8c235c17116f513c44bf63n/aHeodo
2020-10-1971914LOP_9622016.docdoc 92353815ff999cb487b2007b517962fdb9b8c87ac78f64c95f68f6985ef1039an/aHeodo
2020-10-193558819 IZ8555.docdoc a3724d04e16526450d49ad8cf77b30accaf8c02c67de379f80cbc06003905de9n/aHeodo
2020-10-19arc.docdoc 03be372e3764255ae72c077c81eae48bcb91d9085abf8b7a48d00d84c13a1af4Virustotal results 30.65%Heodo
2020-10-19file-20201019-EI722365.docdoc 41d9101a9835faaf362375ab98bd7fe90f00dff615874def1d8d228c12d71348Virustotal results 30.65%Heodo
2020-10-19KI31120-20201019-577477.docdoc ff7c8badd74bc17f454520ceaa28cc0470f8976b60048136920674098e7070bdn/aHeodo
2020-10-19ARC-20201019-SP628.docdoc b37d1eec9c9f39bf111d8d5f46a0426063d5aec3c75e4737894dc0b7860b5965n/aHeodo
2020-10-19inf ZKV90493.docdoc 8991dca6329376736b2d04b1c423029a534bcb89189abece2928682ce5c2ff6an/aHeodo
2020-10-19REP_2020_10_19_2582.docdoc 41874dc716c6a5709b4a6b92486ae1068bbac5068dc4ad73126acc68062db72an/aHeodo
2020-10-19list 20201019 6274.docdoc 0ff52caeb6c47e929cd9ed98195f7568848e6e5639e84066b3c9cd90f3d7eaf0n/aHeodo
2020-10-19List-2020_10_19-ZLV329.docdoc 5a07cdb878ed3a11ea48c225aa964318309c965b7038baf1d2d099f4b23f6909n/aHeodo
2020-10-19file-7536.docdoc e76c9eb013e40ad5ca973b6c617ac40485d2cea01b53812e16bd134b736c7b21Virustotal results 29.03%Heodo
2020-10-19inf 20201019.docdoc 55b62bae0795590aaccf7a37bed2dd6bed886319838e88d1f8b0cad359db2104n/aHeodo