URLhaus Database

You are currently viewing the URLhaus database entry for http://sherwoodsilverbags.com/dc-electronic/lm/6exvmy8tr2741/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:725818
URL: http://sherwoodsilverbags.com/dc-electronic/lm/6exvmy8tr2741/
URL Status:Offline
Host: sherwoodsilverbags.com
Date added:2020-10-20 22:19:04 UTC
Last online:2020-10-21 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003024715 created on 2020-10-20 22:20:06 UTC)
Takedown time:1 day, 0 hours, 51 minutes Poor (down since 2020-10-21 23:11:09 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21D_84122702176345.docdoc 890535144da2084ee8e9431e6521be9719100cc5bec7679a4d7bdce3763a692cVirustotal results 41.51%Heodo
2020-10-21LJ8140997260RA.docdoc 0d4957ad656edeaef3f49b20de1845bcafd5e78981c607cff352212e84ae913eVirustotal results 41.67%Heodo
2020-10-2126413645.docdoc 3edf85ed613cb1c778b32fa1ff5aea9553de2e9e8224d5cd868eca8863b67ff8Virustotal results 39.62%Heodo
2020-10-21FILE_3426116627516114082.docdoc a607fcbdbc7033dabce78e1e902b9822bfe98a9a901c350b44c8f053fb3851c3n/aHeodo
2020-10-213828313716.docdoc 633b2b1963bd2dd467845e87a2d06ace1c22e9402d4dd3aee12618af8f0846a8Virustotal results 39.62%Heodo
2020-10-21REP_LUG_100120_GTR_102120.docdoc c986e90bb2d441b1ef1a8a5669f5f0ce41463363649532b34e712a86bf62b844Virustotal results 29.03%Heodo
2020-10-2106420209.docdoc 202d0af84b5b68cf2a54ce8f9afa3befc8f994b934e380cbc1dab9dfdbd11bccVirustotal results 30.65%Heodo
2020-10-214Y5NAJT.docdoc 8a2b904ad14790b5a69146c0f573dc2da8adc472159bba2aed0afdfe0a550d5fVirustotal results 27.42%Heodo
2020-10-21FILE_8757NZDZ8W.docdoc f32c2612be11b6cce6029b0f7b2b9396e61d7313b26fb513f79b5d416349f937n/aHeodo
2020-10-21X_50775948831803965310.docdoc 25c71c161f7a916496cd76d407fc6a0863e2f36fa50e8b2cb886b5ca7b853dfan/aHeodo
2020-10-212472374918927.docdoc afaa3e615a4cdb709e0914026d5c1d07892391f9e7a2540e8f35da1b810515daVirustotal results 20.97%Heodo
2020-10-21PO_10212020EX.docdoc fddd48d21efdc1d86734b611c1183bfe17b584b835bdb85655c3f9b17cf3e8afn/aHeodo
2020-10-21FILE_Y01WA2CWG.docdoc 52caf1a070aa97f41dee32688e691efd22f50efe87a8f77d4a36a28281c19136Virustotal results 30.00%Heodo
2020-10-21Q_PO_10212020EX.docdoc ad28c5637cf46e7d7e2c3c841334cfac3be445ea84fadcfa2b42829a5718fbe1n/aHeodo
2020-10-21BAL_WZQ_100120_CYX_102120.docdoc 0ee34b08635cebc909a2b1768d921c645fb1cf94ddf18ada0c4a5bf5f9481bf2Virustotal results 32.08%Heodo
2020-10-21UFN_100120_MTI_102120.docdoc 146e75921fa5eb2ef11001446c1120af2407e159711d06d62fc6a8b2e0da6386Virustotal results 32.08%Heodo
2020-10-21Q_LN6507618793GC.docdoc 446984c6e82fb80bf931ba816a5d3da71a7cc64172c4904f80b59f4fbb80346fVirustotal results 27.42%Heodo
2020-10-213976697767286865.docdoc b27ba8b639475544466c43ebd426609308dcc0c1f4842f45627c564e96678335Virustotal results 27.42%Heodo
2020-10-21REP_ETJ_100120_XVW_102120.docdoc 88c45b613e6367cbb58e012779f1cd95ff6a44efc175b2163185aa309e18573fn/aHeodo
2020-10-21FILE_28238244655466236.docdoc 07dbb0f511ef2ce6007a7b576be51073b953253a7e7182b361b06036e6a82f84Virustotal results 29.63%Heodo
2020-10-21R_SK2273565544JB.docdoc d09a3b2020a8fe4602378a86d4e37891b134569113ac01d5fb358f9538b5449aVirustotal results 26.32%Heodo
2020-10-21F277CTIR8U5P.docdoc 3c7b26a013548adeebf30936453b373c34b920df67fb1b135775f0ea8ba32341n/aHeodo
2020-10-2181250201.docdoc af36ad567085faaef5425d233641e227fdf842e426001e855103b942dde705efVirustotal results 46.55%Heodo
2020-10-21INV_14538896608810514133.docdoc 44ba6008506a7673feb84fe893ea958153dae8b82def146db7f497d3537bfbceVirustotal results 48.33%Heodo
2020-10-21INV_UOO_100120_TNS_102120.docdoc aef69b034379dfae45642c5c2271b27f04298dab56a9de3b608ab2d3cb00fa72Virustotal results 45.90%Heodo
2020-10-21JVB_PO_10212020EX.docdoc 850a811a1e29aafadeaca369778609e35c77edcb8588f69f153e44195d40d6b5n/aHeodo
2020-10-21RDI_XS9925330159UB.docdoc 70a369ce3943f743ffc7740c3c003a5f00705abf0505641d7d193d5cf79b8dc5Virustotal results 50.00%Heodo
2020-10-21FO0486157834TF.docdoc f6ca28aa0ec1ee28ce246d787de062e5b78554ec2cfc62fbf00db085c177b074Virustotal results 40.74%Heodo
2020-10-21REP_KYT_100120_YJM_102120.docdoc 39a7385578321db9d477ff19e7087b03d3c57076ceca16fc2af049c087f72343Virustotal results 38.98%Heodo
2020-10-21INV_8A7B0LOGF2GH0K.docdoc cda1bf170e4f678baeac39af84d506bde1d33ed9ccbc753273718f5bd2a503e0Virustotal results 48.33%Heodo
2020-10-21FILE_70747089.docdoc bde4c84d280a8a946e6bc75242c05f9d2b7feb93f84625d34174f8b92b772a15Virustotal results 48.08%Heodo
2020-10-21INV_375998894684854.docdoc 192d1f4fdc36c10af1e2e207ca659c5b7549c01b189257a12f226c42a6c6b4cfn/aHeodo
2020-10-21919928437089208.docdoc 84163a483557d206843913f622d2da3f15392e74ee55e35d61961d07a1dd68afn/aHeodo
2020-10-21DOC_QXZ14LSO.docdoc d755c5281821fb9a1af024b9c6bd977a7da4c3aabe8999703525ece1767fdd13Virustotal results 48.39%Heodo
2020-10-21I_542257327510322.docdoc 927877d8e5e4459c44bb91a386050f2aee647421c37048212690b5caa0fba080Virustotal results 48.39%Heodo
2020-10-214HPXGNU73NEI.docdoc a22d83a786eb7f5a04facaabb04117ecb5f8cdf09fcbb8405c0a70c97a51f225n/aHeodo
2020-10-21WER_100120_QZJ_102120.docdoc d6053ab1f8a8801a71b22ecf5257f4cdfee7138eb99345ad33ff208e175aac0fVirustotal results 42.59%Heodo
2020-10-21A_WD2464011033ZV.docdoc 614bbd10017422522d46a734ed08de066834e449d5802b036b0231a39b0c043cVirustotal results 34.78%Heodo
2020-10-21DOC_38538659559824.docdoc afcfe7ff49c2df7f47347c4c49d64ac3f027b1c79f5d090a0daf526fd65d859dVirustotal results 43.55%Heodo
2020-10-21FILE_PO_10212020EX.docdoc b5f8485da1270855c2866456988ce8010f5c32c69fb19f324859d685e719fa3eVirustotal results 40.38%Heodo
2020-10-21PO_10212020EX.docdoc 92e4476fe9673fe19a33b4c306402a172f3b2124ad380f0782517a9e15fec347n/aHeodo
2020-10-21REP_4ZRWOOXXBF.docdoc 1393994f35a8a5910cbc519d9a9d9baa91d4dbc85080bea49d95c152892a2aabn/aHeodo
2020-10-21DOC_06430206.docdoc 7bf2ce4dd307b31f8b2eeff8a5ca658f7a680a9bb132d54d6182c711504b0ac3n/aHeodo
2020-10-20HLG_PO_10212020EX.docdoc 681fa75f785a2b6eede8e0045ce0ba666fc0be736b8bba8d23f474b0bc400a7fn/aHeodo
2020-10-20BAL_32743449.docdoc 8cadf5fc31643a1acc9b991d110e039e7e0520e94783c61d9caf5ccb2481915eVirustotal results 44.64%Heodo