URLhaus Database

You are currently viewing the URLhaus database entry for http://targeted.thatsswift.com/how-to/2glwdxwlyeshk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:728007
URL: http://targeted.thatsswift.com/how-to/2glwdxwlyeshk/
URL Status:Offline
Host: targeted.thatsswift.com
Date added:2020-10-21 07:52:04 UTC
Last online:2020-10-21 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 07:52:17 UTC to abuse{at}godaddy[dot]com)
Takedown time:15 hours, 15 minutes Good (down since 2020-10-21 23:07:54 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21INV_VC8635707330JJ.docdoc 890535144da2084ee8e9431e6521be9719100cc5bec7679a4d7bdce3763a692cVirustotal results 39.34%Heodo
2020-10-21J_MG1676622930NW.docdoc 3edf85ed613cb1c778b32fa1ff5aea9553de2e9e8224d5cd868eca8863b67ff8n/aHeodo
2020-10-21Q_PO_10212020EX.docdoc 707a2acd195f4e2ac6ab0bdd8c10bb19a6d95938a957ff75aab954aba3526fbfn/aHeodo
2020-10-21INV_545IRMSA.docdoc c3caf9f914df7b8d90ac3dd35fd1ad24ec34a4d1af94293e9002a9f8f943703en/aHeodo
2020-10-21REP_AD5419366037QX.docdoc 0f850282e2508eb5472f9cbae697cfca8675a66d6581f269509f5db6a9f30e53n/aHeodo
2020-10-21RP9689533274HJ.docdoc 99d7234dc759302b6b38de85547762ca5a46358e93508509b534755c9af8c309Virustotal results 30.19%Heodo
2020-10-21WUV_100120_FXJ_102120.docdoc 02a8230dfddee28c717cc288e1573b5a44194cebefd65b8a20d0e37e2e086a1aVirustotal results 26.23%Heodo
2020-10-21EJN0XBVGF7VVJM.docdoc 638d2c28c891f1eb997a450dbdc2f6f1a83b000d7b617d3000cf2b937275de99Virustotal results 20.00%Heodo
2020-10-21REP_PO_10212020EX.docdoc d2a68a5159ea637fa9428d39a0d9469c6c2db0b16b2de2593070c17a0ad49520n/aHeodo
2020-10-21FJ6242195810EE.docdoc fe647619aa21d737e9f948fb92a9286a5f03bac06ab881535069fe060bfd622cVirustotal results 33.87%Heodo
2020-10-21BAL_JDI_100120_HJS_102120.docdoc df23f7673bff775b6e684f5ba9d205d51e926537e185534fb4726ce87e541f04n/aHeodo
2020-10-21BAL_WD0468033176BW.docdoc cdf08877df82aef07518f10414f3dc1ec0bca6a662ee6191b7c76105bb51a0b1n/aHeodo
2020-10-21WU_PO_10212020EX.docdoc cd8851bd896a7e87cc70c70d34d548cf3618138a015fc11eec546d47780a586dn/aHeodo
2020-10-21INV_PO_10212020EX.docdoc aad3348c28dbb9e0a038508e8fde9f2771e550228320b8ebc0f6cf1d11c39945n/aHeodo
2020-10-21DOC_UE4FSVIT9.docdoc f93730c27fbb9a6c6cc64e5f4d9127854a0c11d165e699569dd0828ebee3ec4bVirustotal results 27.42%Heodo
2020-10-21F_U52PB3ZOZBU.docdoc 4a8ef7b61c8dea7745464f96999dcc37abec856e23e55bc6eaa7ef374a6c1878Virustotal results 32.08%Heodo
2020-10-21QF4292838080PE.docdoc d6edabb30c96ad35f08d16e274d639b6a5a5208e7b35167d56392a44b3842599Virustotal results 27.42%Heodo
2020-10-21QFV_100120_PDD_102120.docdoc 552e98ed18af24b89d6cd937f335ee85312e919ad186a6e0d1bb5839fdc96167n/aHeodo
2020-10-21DOC_11I78T0MD1T5B2.docdoc 2e56fde4acc7cac043046e86b999a37aeb702d863f9024c4ce83e95d7c787d70Virustotal results 24.59%Heodo
2020-10-21895072750.docdoc a9d1a8ff09fa0967ed2bbcd45b156698c20fec11fb07d5397bcfd5b8ffba1737n/aHeodo
2020-10-2123759934493.docdoc ecf5ecbbe5e2904306de22bb28532af5b7e0cbadc8446cbb2fa456255683e972n/aHeodo
2020-10-21W99F497K6H.docdoc 0e7f06cdfc74e74e5e00123ac97222a4735cc7b8cb29ca8d7892df978f647a32n/aHeodo
2020-10-21FILE_WX6706135708PX.docdoc 3f28d23c6650e22fa69d824efc5153fd46fecbbdbd236ae7b4ee15bae4ef556dn/aHeodo
2020-10-21DOC_55310158.docdoc 389ad5d9d72b446e4ea03160b107fdc48402bcc7c9f664d73851ebe4d4c7b660n/aHeodo