URLhaus Database

You are currently viewing the URLhaus database entry for https://fudiai.com/apps/swift/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:723561
URL: https://fudiai.com/apps/swift/
URL Status:Offline
Host: fudiai.com
Date added:2020-10-20 12:56:12 UTC
Last online:2020-10-20 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 13:00:18 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:6 hours, 38 minutes Good (down since 2020-10-20 19:39:06 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20PF22QATRWE4PV.docdoc 257a7a26795e79f908c2add722126270035ccc4c5a71ae074cb2afc303d00ad7n/aHeodo
2020-10-20BAL_RK5101961156RV.docdoc ab0f780d3717e6b5be76ac64376d1d82b1b0e1b5da173cf7e602e60d0a9d1f9bVirustotal results 37.93%Heodo
2020-10-2006736900.docdoc b3367c32b211d1a338b9739a2a47b98efaaa7b8eecee17b0483558f7c1eccd61Virustotal results 38.18%Heodo
2020-10-20REP_83513615.docdoc 024ec5f4dd60b0098283bf9293494360cb6abb8479b56ed3cc7e5f3bc2a73fbfVirustotal results 38.89%Heodo
2020-10-20REP_PO_10202020EX.docdoc 9d1544d6ef4200e70c0018b901d6c0457725561405f6f093e42b29b4f294916dVirustotal results 38.98%Heodo
2020-10-20REP_TNY_100120_ISE_102020.docdoc 621f20067cbf141bfbaa9f852e46d9dd4345b045435364b925741d9f180a2918Virustotal results 38.33%Heodo
2020-10-2009019509402312897.docdoc 53d96a7a8d56f1e2d064c677509dbaa14fdbbb01054bb25349290a7a959fd920n/aHeodo
2020-10-20FILE_PO_10202020EX.docdoc e0b1bc7ae2ab93ab68ecc603b67bf124c72d2aab047c0a5280afc1c7b50c0600Virustotal results 40.32%Heodo
2020-10-20DOC_15753841200911470.docdoc 9cf5b02816bd565827cdce9d51379ce60e8de2b2a83156c0ac9f6f2bb688fd38Virustotal results 38.33%Heodo
2020-10-20J_IPI_100120_LVV_102020.docdoc 521d891d4ae509c8262b875df2e3d2dd21b8b638721d2aa59e5106ae666ce2e7Virustotal results 37.74%Heodo
2020-10-2088OUCL3J2XXM4CHO.docdoc 08057a9df9d17da8a860ee860efc60fef7c46b9cc8bf15ffceeb7ed05480b01aVirustotal results 33.87%Heodo
2020-10-20S_8652340220599148331498307.docdoc 717d8cbfd8b6e490d31d7e4650d8ab128397cd69b31470fd4d873a903337c58eVirustotal results 44.23%Heodo
2020-10-20PO_10202020EX.docdoc 40acf5c1261d6d9139f62df39cfae30d1514dc9b507ce21ac857069a62b2ad95n/aHeodo
2020-10-20BAL_UF1477719968PC.docdoc 8d265b2a1f4f7b4f035d094bb3c7e31a22449709662db50101e76b3088f309bdVirustotal results 26.19%Heodo
2020-10-20X_PO_10202020EX.docdoc ddfed25e7057b0ce36b9d4e9543d67b6533c84e1dd80a99777a26a0841ecc6c2Virustotal results 32.79%Heodo