URLhaus Database

You are currently viewing the URLhaus database entry for http://aljoaib.com.sa/cgi-bin/eTrac/3VccqV512iUyFmR66aV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:757382
URL: http://aljoaib.com.sa/cgi-bin/eTrac/3VccqV512iUyFmR66aV/
URL Status:Offline
Host: aljoaib.com.sa
Date added:2020-10-27 17:37:17 UTC
Last online:2020-10-29 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 17:38:14 UTC to abuse{at}sahara[dot]com[dot]sa)
Takedown time:1 day, 20 hours, 7 minutes Poor (down since 2020-10-29 13:46:05 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-2717172QQN-MZ200570.docdoc 5c883b5095d6cfcf09860df73cd8d8df18b1387fe489b9041602167fefac2c71n/aHeodo
2020-10-27Inf_2020_10_28_VQY615682.docdoc 3f2fcb39ab59404b406f3cf830473811a4686337ed3e3bee2701a96ce07e4e14n/aHeodo
2020-10-27C40060 2020_10_28 2880745.docdoc 414730c09b8914aad74e763d7ccacbfe96361572d2f1c53fd6210f913dc96549Virustotal results 19.35%Heodo
2020-10-27REP 2020_10_28 9316527.docdoc bb9eea8a1f46b7f1705bf48d3570b9bc5082375303cbd793c2e9d2e8e27efa02Virustotal results 18.97%Heodo
2020-10-27UNTITLED-20201027-PPN765726.docdoc a851a17be48fb9f40d25b14949caffd6ad3f90a89f3ade23e49634e2649edc0bn/aHeodo
2020-10-27Doc-TK616958.docdoc 8cdd9b2aaac8151e3f992d56df49f1fb61045ab4d38e673b52a82c2fb011cd8aVirustotal results 19.23%Heodo
2020-10-27Arc-20201027-24551.docdoc c4478df05ea4d77b2886f04b1a0b8ab67fd66e0f90064c0fce17fdf1171aec22Virustotal results 18.33%Heodo
2020-10-27inf_20201027_9810332.docdoc 62bcc19331151319c7f92f51fc561380900d5c6f4b128b0df63db3ac0c442afcn/aHeodo
2020-10-27ARC L46854.docdoc 59abc8db0f0cf37b6af7e7d73b3cb31e690fe75114023a548fbab6b5755281b8Virustotal results 19.35%Heodo
2020-10-27INF_2020_10_27.docdoc 486838cbf31e36e048d22c4684c571196e1410811269ebbd7f7f33c640bd1838n/a Heodo
2020-10-27List.docdoc 9a665625762701ef94a2ebac83e7afc5fe24eeb05095df8655a980ba20f75343Virustotal results 19.35%Heodo
2020-10-27Dat_2020_10_27.docdoc 4404fac35c28f7aff909e081a460c93972a6b1a174906fd4e9cd7fe20cbf5dfan/aHeodo
2020-10-27Attachments_20201027_DSD6166.docdoc 672df5031e725bfac0c97e002d436bd64cd9be2565a07608954b264221464464n/aHeodo
2020-10-27arc_ZB68442.docdoc a0befbd5126d4660e42ef357002601c14c94c5e2b1f9c83097159362a590075dVirustotal results 34.43%Heodo
2020-10-27File_3391.docdoc a8f90351c28fc268cec63f45f68a993cf9ef9c459b5d9fa23e939791d57bcb45Virustotal results 35.19%Heodo