URLhaus Database

You are currently viewing the URLhaus database entry for https://fides.uy/cgi-bin/Pages/XSQtfifp5XKWQ0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:718188
URL: https://fides.uy/cgi-bin/Pages/XSQtfifp5XKWQ0/
URL Status:Offline
Host: fides.uy
Date added:2020-10-19 14:22:07 UTC
Last online:2020-10-19 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 14:24:34 UTC to abuse{at}liquidweb[dot]com)
Takedown time:6 hours, 11 minutes Good (down since 2020-10-19 20:36:25 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-194422WNF-OC0338.docdoc d0132055304b041268020fd30816c556f84bdacf1d2a557efac9b7e9340ab421Virustotal results 37.70% Heodo
2020-10-19File_20201019.docdoc eafa3440b1b3cc0b658086ee26210d96b6da49caa2d6ed3ba7b1ff285c60350bn/a Heodo
2020-10-19DAT-20201019-0562568.docdoc 0741cfd29e5f65b1aa4109ef4a59d28a73671f4ccd35cf80c3df2928ecf39a03Virustotal results 38.33%Heodo
2020-10-19Untitled-904029.docdoc a5562dc1d98da4ea0f833e5d1ad078fe3e243e0afacd05b216c4890c328d9505n/aHeodo
2020-10-19INF-1073111.docdoc f579a6044d9f764bd59abd53771cb8846744e24997e2d83e41a17a445578826dVirustotal results 37.29%Heodo
2020-10-19arc_20201019_FO0295.docdoc 06dcbd114edf8160eb598be2701ba77ce7fa290adae7d7627b2ad68e7511664dn/aHeodo
2020-10-19INF A722.docdoc 4846b137d8cc5dae6ed7e1b3477444bca0adc09c3c8c235c17116f513c44bf63Virustotal results 35.48%Heodo
2020-10-19rep_2020_10_19_5344.docdoc d5ed2d2ddca9dda025de70fd868c356ab540e1f1bd596566fa73f1bed19168bbn/aHeodo
2020-10-19doc-20201019-LZI32308.docdoc a3724d04e16526450d49ad8cf77b30accaf8c02c67de379f80cbc06003905de9n/aHeodo
2020-10-19212R 2020_10_19 892806.docdoc 41d9101a9835faaf362375ab98bd7fe90f00dff615874def1d8d228c12d71348Virustotal results 30.65%Heodo
2020-10-19Arc_2020_10_19_XG824887.docdoc c4b5bd4c4e073e1697860dc4d98fc7a389099cf59279e8784ee387340b488fcaVirustotal results 33.33%Heodo
2020-10-19Dat 20201019 3373692.docdoc fbc0425c72eb13dde61a7d687221084f9cc667dd76975a20b60bce0d524490bcn/aHeodo
2020-10-19rep-20201019-RNA33133.docdoc b37d1eec9c9f39bf111d8d5f46a0426063d5aec3c75e4737894dc0b7860b5965n/aHeodo