URLhaus Database

You are currently viewing the URLhaus database entry for http://weapontoys.com/wp-content/esp/183254154065/YQGZUYZB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761091
URL: http://weapontoys.com/wp-content/esp/183254154065/YQGZUYZB/
URL Status:Offline
Host: weapontoys.com
Date added:2020-10-28 13:37:09 UTC
Last online:2020-10-30 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 13:38:22 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 17 hours, 4 minutes Poor (down since 2020-10-30 06:42:37 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29form.docdoc 2efeab91d822ab76173df70e491b2cd6881d1435186ad6659da73c4e5c5214bfVirustotal results 34.38% Heodo
2020-10-29Invoice 00312955.docdoc ee34d9fc3f07a4d4e46927587419c036126144d692c38ded4a9e3ee8dc2d9a57Virustotal results 34.92% Heodo
2020-10-29form.docdoc 2176a02ebbadceedea35c2a83fcce17fd40120ff2cc4390a9f210fc26b40a310Virustotal results 34.38% Heodo
2020-10-29invoices 952 & 5935.docdoc b35e8c1cf63de1025db2d2f786b3252b88272d9bad9576c7e2a223a9b4187663Virustotal results 34.92% Heodo
2020-10-29invoices 283 & 12729.docdoc a0fa698426cf3decea21c3e89fe324393fd7a7743da94068ba8be39c4ebf86b1Virustotal results 35.48% Heodo
2020-10-29H637 invoicing.docdoc 4058286796ed1036d0c66b67dd83752f09a253f4b597095ffd3f2412645e3e3aVirustotal results 34.55% Heodo
2020-10-29Payment.docdoc 7035a94379b991e446531c0965b4935f1d3be9a10b20dd97e7dd1e34e6571707Virustotal results 34.43% Heodo
2020-10-29Copy invoice #974291.docdoc 0d30a2f25c077dbaa89fd166e0c2e24a2d75900432ab850d5c00dbd826ff759fVirustotal results 34.38% Heodo
2020-10-29Invoice #93262.docdoc 092adc3e63864e36764ee209d07e652c3b37b55e0f433d9ae5c69a1619a482a5Virustotal results 34.92% Heodo
2020-10-29YC07 invoicing.docdoc 6510c1088251e05cfe18fc22279a7312308f08614ba3dee7852e6b1342e21dd6Virustotal results 32.81% Heodo
2020-10-29Form.docdoc 015aaecbeea372d2cde18c72ef93ce742b3e8c3ddf7247918403295dfa7357b5Virustotal results 33.33% Heodo
2020-10-29Inv_84848.docdoc e48485a5f02afb4fa932b38c41f278e6a4571911311828ff8fc0cae186be9be2n/a Heodo
2020-10-299713506260JP.docdoc 8d290f947fefa21f9f913406a08c14c04905e3d9989479adbc6e4a46bc8640bdVirustotal results 31.75% Heodo
2020-10-29invoices 72797 & 9129.docdoc 07b12baabc51749df13d78cc093496d641f03a1aed14ee0ecb867e2a4a2d70d5Virustotal results 30.16% Heodo
2020-10-29Inv. 003689421412.docdoc e8eaf6545e2cb1bb8d2294dd179c60990c18eb6fd9f4fa804effa77b6a28ae50Virustotal results 26.98% Heodo
2020-10-29Invoice.docdoc d61c50ab4c3e9a6bf5d5ad2ea05c538fbcadca7f6acc893a7dbbbc7ff9a05b9cVirustotal results 28.12% Heodo
2020-10-29form.docdoc 493d0b6b7fe96f6e344c94ed7931ec69f8344a424f6083374387322b6ce037c7Virustotal results 29.03% Heodo
2020-10-2900208001.docdoc b73a5289bfd407c490d24c3637ff6377dbc5058fcae8ffeab85ce4a879e2d0a5Virustotal results 28.12% Heodo
2020-10-29Inv. 09191794.docdoc 34f4b941f7159e6c2f95f5e599b65b7cffea4b7e46a47c6bb16ea6c38027deb8Virustotal results 27.12% Heodo
2020-10-29invoice.docdoc 9bedff10d91854bee6daf53c351b6ab3254895e11c0b77a9ea5c6433021a04ddVirustotal results 26.56% Heodo
2020-10-29October invoice.docdoc 7fafbcc83ea713a0c58c02025b505e177c9014edc2dc1229d9d7487cd3075faeVirustotal results 26.56% Heodo
2020-10-29INV #03121280 FOR PO #7171946609.docdoc 0ff96480062e84aa44e93eb008a5937b1f317e5a0e222198658fb2a71dc4b952n/a Heodo
2020-10-29invoice.docdoc 477abef826205efd3cf971b2c425dff760789b1c15cfcbc182634ba92187e59bVirustotal results 26.98% Heodo
2020-10-29INV_60865.docdoc b08c46dc3723073450b41bd5ec1e98efeb44b2cd04b91ea57e9fe2f06a607616Virustotal results 25.00% Heodo
2020-10-29INV #51253 FOR PO #00145670490852.docdoc 0128b674249cf22f59bed1a918f9c828770abd2dcd93505856fb7596440a2a5fVirustotal results 23.81% Heodo
2020-10-29I-100120 ROEZ-102920.docdoc 7d41847fb131218d629e6bb8132dc6b2b1ce714b4090c01c3f531fa66ad7274aVirustotal results 21.88% Heodo
2020-10-29October Invoice.docdoc 872d3855e7d15b10167896aa79941f2defa7cd42778c55fef0c4770a6b146560Virustotal results 21.88% Heodo
2020-10-29Invoice #80493812.docdoc 26e0dedfbc389de133350f134455565f185e864b79466539b658dacc21fb1bb6Virustotal results 22.58% Heodo
2020-10-29Copy invoice #656152.docdoc 95b4f0a791e9ffefe35972f8c4e1a90c115fe1c8976f779e44b5190d859b3eb0Virustotal results 22.58% Heodo
2020-10-29INV #0742 FOR PO #7233768113.docdoc 176d883eced9c465d7391f935cbdb75d425c31d1d0d51771b6c730dee296a8d6Virustotal results 22.22% Heodo
2020-10-2994577295.docdoc 3e84e096f2f889c271504b8dcfb1e9fb78a347087b984a219d7749a8a0839c31n/a Heodo
2020-10-29INV_76881.docdoc df634084d9cb08a06d2e82f00cc3fef1f64efc21da9ebd08ba86b684ee237863Virustotal results 19.05% Heodo
2020-10-29PO# 10292020.docdoc 4d064ffae939066e710a994df38ada3de500bfca3fa58d21f40312450b69b3dfn/a Heodo
2020-10-29INV #0098481 FOR PO #0653156768559.docdoc d35618fba11f6c84539c7888912e7eb42799ab92025b7d9b15eb542b4b380d33Virustotal results 17.46% Heodo
2020-10-29ON02 invoicing.docdoc d7d1adcc407dd35eff7098c6e3de2d56ec9b639378bab5eb90380b898c5c826en/a Heodo
2020-10-29invoice.docdoc bf01de28c8cf6dc5958da2bedc45b045e3978c687cc80c399c8fb63407e8562fVirustotal results 19.05% Heodo
2020-10-29074941.docdoc c8e574a25c67cc59d9e1eab78d4591aa32efdd56dc3a64d5e02928d42fe1e732Virustotal results 19.67% Heodo
2020-10-29Inv. 0321351.docdoc 5dcf042f48bafd382c7317aca15826f28d614449f1ef56d3ee67aa26f8ff51c5n/a Heodo
2020-10-28form.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 29.03% Heodo
2020-10-2853456.docdoc f839b00e54aa7b0d68e3f3d7e7c12965d9d64153cd37d0600c4297542385eec4Virustotal results 26.98% Heodo
2020-10-28Payment.docdoc 09ccc81a0d3dd19981c937faf388f0fe7117243b355255e387dce0dfb43f7769Virustotal results 26.98% Heodo
2020-10-28Form - Oct 29, 2020.docdoc 6c3c1280087fe50fd411676b26ffd9bf41044300aeef5d27ed6322cf365fcd99Virustotal results 26.23% Heodo
2020-10-280767200.docdoc ab327e3be9ef1ce4781f725c995feb6a13f6eaf1d1c31e894048e5be6b4e24aaVirustotal results 23.81% Heodo
2020-10-28A6993368708QR.docdoc 96357920882bf90a3ffe1e87ea63ef9f2dac43a1f01c5ac5d3c390103e9a8bb5Virustotal results 22.95% Heodo
2020-10-28Inv_5381.docdoc fccf7156f22fc7676f860e9ac3dfe8f573c89f58106e5946da37e36fcef2a205Virustotal results 22.22% Heodo
2020-10-28October invoice.docdoc 329f623c62c598576abebccee07ddfe04ba97b4c7ae3307e6a9601185941755bVirustotal results 21.67% Heodo
2020-10-287088279992WD.docdoc e69175f1d0fc57715610220f59992ae3a56ac12d27917162e4626cd0ef2bfc30Virustotal results 19.05% Heodo
2020-10-28M-100120 YCSV-102820.docdoc a489db63b3d5de10623868c1348ded5fa888b398c6c9ecd199dc5c1fe55ac9d9Virustotal results 17.46% Heodo
2020-10-28Invoice 9315591.docdoc 22ccc563e61d8e3c9936d06fb1d86632f7544d213ae91216e74ad8bef00b45c3n/a Heodo
2020-10-28Payment.docdoc fadcbe7aa3d7b823b03d2627cf8a05b229e0f6c7518a71b9c4a106155b04df3cVirustotal results 17.46% Heodo
2020-10-28Copy invoice #23064.docdoc cdcc9f999263c672f77e84b1b08028da0a298140b3e9e300baaa8a6b69c84e99Virustotal results 17.46% Heodo
2020-10-28INV_9185.docdoc 08d832a1ff20d74ba37553d0ac28f94bc54d7463e392873c34faf6bb44d47afdn/a Heodo
2020-10-28Inv. 005503916.docdoc 10bc06dc05769972ecb24dd4e1bac275a4cb33e846d292361500fe1ed7ac0930n/a Heodo
2020-10-28invoices 835 & 9337.docdoc 35ea56863ec97fca389fd1138ca3a7aef03c68c4988c72ad389d4c4cbd211a63n/a Heodo
2020-10-28Electronic form.docdoc f6835e95393920b5b465037c620c254f15629e9fc86a98b421876da191ff1904n/a Heodo
2020-10-2800797724.docdoc 5a9c040e67efe0446aaaeff9b0dacd2f668516484cf5487449360cd489ce268aVirustotal results 17.46% Heodo
2020-10-28Inv_6368.docdoc 00be80b011b00e2de85e342852402bd4fb7b9bd28a03d3631202c6ab79baf9cfVirustotal results 17.46% Heodo
2020-10-28F8267305684WE.docdoc 91fd99663914efc537bbc0f6a9c7f56b4211918e3b5cd280e590c58c23a002e7n/a Heodo
2020-10-28Invoice 418618.docdoc 8d628c60fb8a3dcaf40f3ad332715bef982f7bb08b77223501bd663299bb719dVirustotal results 23.81% Heodo
2020-10-28RU00465 invoicing.docdoc e2e6b46ee6eafc1f980ec767666e1758535992fcb4757f374c0f01d555fada31Virustotal results 19.05% Heodo
2020-10-28invoice #64044.docdoc cf5066738d5862bead47940e22a0cab26d7236c22d450506b045f226bfbf624cVirustotal results 17.46% Heodo
2020-10-28Inv_889024.docdoc 7b55e5dcf03999a440acbe690dddf943d03bd37fbfc7892d196708992044efdfVirustotal results 18.03% Heodo
2020-10-28Invoice #3401.docdoc f973018352488fe6ba623919161c5b4387f67d9aca131af19480684ae2740544Virustotal results 17.46% Heodo
2020-10-28Invoice #435.docdoc 1f78558f3017d180e7ec6d453d46b87192b207476536447d4502b9f6ebb0a173Virustotal results 17.74% Heodo