URLhaus Database

You are currently viewing the URLhaus database entry for http://uhawra.net/wp-content/nNIzunN55x8Oh7UE6XEjrw6D8qsXBHFXPXoHVr6lj61dDXFkMVTPlPNBkHtVhN/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761574
URL: http://uhawra.net/wp-content/nNIzunN55x8Oh7UE6XEjrw6D8qsXBHFXPXoHVr6lj61dDXFkMVTPlPNBkHtVhN/
URL Status:Offline
Host: uhawra.net
Date added:2020-10-28 16:16:14 UTC
Last online:2020-10-29 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 16:18:18 UTC to abuse{at}hetzner[dot]com)
Takedown time:22 hours, 11 minutes Good (down since 2020-10-29 14:30:13 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29ARC_68YR9DISZ7G.docdoc 29808c9db3a80e9ed46d4aecbe478dd8e57089d7e2977c916421cba71b0d6c42Virustotal results 26.56%Heodo
2020-10-29Inf_062095723600805950446459.docdoc fd810765d8200ee0c56b220f79375a5a76d36bde37b25512c664f45c7d130181n/aHeodo
2020-10-29Attachments_FR3NJN69U3.docdoc 4a66929263cee2a8c48e07dbf1fb484199f5d51da94f42703fff35d3213235d9Virustotal results 24.59%Heodo
2020-10-29UL7207650645JW.docdoc 1909a3514994e354da8e5abdfbb3b73173a1a6782a739ebdbfbacf098abf0fb2Virustotal results 20.97%Heodo
2020-10-29UNTITLED_PO_10292020EX.docdoc 3dda8251733c1b96b75d29bcbe3466add36d495368b4b44232fae1dba4a4cec6Virustotal results 20.63%Heodo
2020-10-29DAT_IP6698769995QI.docdoc af8373a05bb4ac069cb45da6f676db803e252cb4c3e378c3fe25375323c74db8Virustotal results 20.31%Heodo
2020-10-29LIST_94108791.docdoc cd49f6f6b2b1cbf28331a1eff67e7179731f34a790a1bb69c89b65ffcfc38e01Virustotal results 20.31%Heodo
2020-10-29list_PO_10292020EX.docdoc e631c078dc0639fe8db3a1c45b1e38da8a369c37f69511f6458de6d8809f9732Virustotal results 20.63%Heodo
2020-10-29DAT_FZS_100120_PEQ_102920.docdoc 2427ee3cc0798fcee02c718a1fb58d735d9cf3b0ebd9bb10c14cb9326bb5e489Virustotal results 20.31%Heodo
2020-10-29ARC_581588589.docdoc 1e63648100763f7fe5822fa5fedd5b5b9c87d1bca425b6745c236e3bff92bd0cVirustotal results 20.63%Heodo
2020-10-29doc_45898862.docdoc 585ab6cc0502c04dedbca9318f5d7d278050dcfbeb477a09e8fee5b66916e38fVirustotal results 42.86%Heodo
2020-10-29Attachment_BK8164602469RQ.docdoc a68e38ba80539aaa99e4624f37df31a53410de47b3a76df0fbced21744a74d0bn/aHeodo
2020-10-29file_39447396.docdoc dd50631890eedb25005e6c54404ae0debc8cc80a8fd10b6e71c9251bf760c9a3Virustotal results 41.94%Heodo
2020-10-29Attachments_92716597.docdoc 203c3fd643e932d50df0ccb5aa112bf49bbf44dd16e722b4bdc67551bf3fb133Virustotal results 42.62%Heodo
2020-10-29rep_591524384.docdoc 63df7914667bd2adc0b6e4b2db5b67f07a6154956568765321641b6dc1469cf5n/aHeodo
2020-10-29Arc_AUZNS00K40ZZY.docdoc 5d0b92f454b00f1679bc6b090749bf784d1fa854eac55bf453eec083b6aa2076n/aHeodo
2020-10-29File_O3CC6B6CN4M1.docdoc f98cdce14c9b9c64ea8402566c9db1499eb129104bd476c96c503f1a81a858f5Virustotal results 38.71%Heodo
2020-10-29doc_PO_10292020EX.docdoc e3a96d2e3adca1fc3dfea0ac14af9b1d4cec3a20d9d7c6874edf1c6fec60d90bVirustotal results 38.10%Heodo
2020-10-29FILE_41261978.docdoc 4c8eeccd2a16f80874acd0057d5ec622d3701e32a3198bdb763f39e39ea28982Virustotal results 38.10%Heodo
2020-10-29dat_20631005314113.docdoc 1053508dba9607d8d25a553d3059249c8ff3fc0f143ea47103c1842a20098c2cVirustotal results 37.70%Heodo
2020-10-29REP_PO_10292020EX.docdoc 7a6c44adda3ae4a87e18e7b6224fe08a361d32f37ad5a302faed9e8f83b8dd14Virustotal results 38.10%Heodo
2020-10-29List_60101051.docdoc b97d2b5410d55c774746d336facb4fac9b81552a5f84073496d20901af3c5f71n/aHeodo
2020-10-29VXOF4P5.docdoc 9f2ed62dea3b679b6dfecbb79905a34ef056e81af2e92c4249fe4521711b047fn/aHeodo
2020-10-29doc_B5OQD5E3TVHR.docdoc 17d6d17702d158eda616b2096600e47fe0808914ae353ec5009763a5de5fffe7n/aHeodo
2020-10-28inf_PO_10292020EX.docdoc 2a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7Virustotal results 25.81%Heodo
2020-10-28110314912393610682.docdoc b004139f56a3790ffec0ba6852e8ead3947b000f2cbc61be1754b91a69633354Virustotal results 25.40%Heodo
2020-10-28arc_CC3074364146TT.docdoc b453a71649f01fe941d53cdae60f24c08a2ef3294472d662be990ed0b961d3ccVirustotal results 25.40%Heodo
2020-10-28Untitled_KY38VS3WGJ.docdoc 146747a5fe14e9c8f3de53906c757ebbcd932487aa7e6e1da69baf9ebca99e58Virustotal results 23.81%Heodo
2020-10-28dat_PO_10282020EX.docdoc 0a8f0b82ac6ca359057a79405255027ce1c2e1de5493d655a55b0374727e32baVirustotal results 22.58%Heodo
2020-10-28dat_SJR_100120_FHV_102820.docdoc f25bd084ce8d81cd2533601965f19c49105798af5fa7465757626b6cd057dd61n/aHeodo
2020-10-28File_VDQ_100120_YNK_102820.docdoc eae43aeb02650178d0fd02ed1c824f36d89c2a2950399621c4a7c29ecb8d7e73Virustotal results 19.05%Heodo
2020-10-28WTM_100120_HJG_102820.docdoc 74bb58aee05391c699fefedb79da019fc9e7b0d6d81d068d0ce1d192cc9e4556Virustotal results 17.46%Heodo
2020-10-28INF_YT2993671337NP.docdoc 3fe50d0556d64f8a7214fa4e311bb0075f31b6bb0ea009d852c70bbe51a1782aVirustotal results 17.46%Heodo
2020-10-28FILE_68959163.docdoc 54a04ad4747b88954b6501afd0c033a819bfd9e67df5354ed77031d04e8e23bcn/aHeodo
2020-10-28VTXT_80124868.docdoc 11dd803e4e682105076fd2c1d86f54e36702074879acdd270b796dc604de12c3n/aHeodo
2020-10-289912557807967801592423044.docdoc f8c7566296ab5b125218fcfca6cb017b25bf92027db687ec545e8897a62c59f9n/aHeodo
2020-10-28Untitled_4111552969.docdoc 8abc1a41fddc4a3a107138900b0401334fddf0298fa9fe0ec4e7e1f4fede979an/aHeodo
2020-10-28X_55852635.docdoc b6a96390b242aa0846471f4e8be2000c6d0a46330c8a838c25b95c0dd7874378n/aHeodo
2020-10-28Attachments_NR6818279151FE.docdoc de6aea23d0d0c49a68ce1e1762c71c2976fefcbf72b8b2676fec3c065edf9b47n/aHeodo
2020-10-28List_DKR_100120_LMM_102820.docdoc 5fcda50da77323acc30f1b703c2504b8b3ac07997068672294ea312703ef0ea2n/aHeodo