URLhaus Database

You are currently viewing the URLhaus database entry for https://www.cwa.mx/himalaya/ziqqBxu4F7CwSORdFXKiHmhwFCC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:938217
URL: https://www.cwa.mx/himalaya/ziqqBxu4F7CwSORdFXKiHmhwFCC/
URL Status:Offline
Host: www.cwa.mx
Date added:2020-12-22 12:29:21 UTC
Last online:2021-04-12 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-22 12:30:27 UTC to abuse{at}tierpoint[dot]com)
Takedown time:3 months, 21 days, 9 hours, 8 minutes Bad (down since 2021-04-12 21:39:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-23SG4VA67QQ2MT3.docdoc 8f1c045c52f380a3dee934291859c8a03f17ef3f96084c3819678fe14f22c0c1n/aHeodo
2020-12-23XC2U6AOJG9XSPST.docdoc 49f4475b4c4b63927d612bfcfc707d4a25237813c727333fbcb42fec441757dcVirustotal results 23.81%Heodo
2020-12-2359ATYW7V4L0N.docdoc 8538d00638c32a97eac2e8a9e1766a39268d8effa55c28026d3b75fe114dbc18n/aHeodo
2020-12-23D47JTZU844LWG.docdoc 59beb0cb64d142274d978c425b55fc8a7e7053f2f8840c09b9d751e56cd6f7d6n/aHeodo
2020-12-238KZU05Z5OTW46CGQ.docdoc d5231db757615d38ce982ea1272ef281efc93dc8105418c890e8f9e59d76ef0dVirustotal results 22.58%Heodo
2020-12-236V53ZQR17.docdoc 1b7862cdd7e11129f0b2efba625efa4a4298cc9610881f0e2ecfef4299a10afaVirustotal results 22.22%Heodo
2020-12-23PLJ8RB.docdoc 318cf158cf886f17e7e947feaaf989f25e514c91bec35e9dcca2a4f2ef4baa95Virustotal results 22.22%Heodo
2020-12-23QDPF0V.docdoc 383bbcf6e40f5db6ccf0a07f33eb55614c381daaae647ebf0ed8db148d4ab7fbVirustotal results 19.35%Heodo
2020-12-231XGNXP2.docdoc 60029fa95c17ba479a9ed424abc3a3f684111997424360741b67de478d0bcd4dVirustotal results 20.63%Heodo
2020-12-233Y6BIB9B9Y5.docdoc 0b92e01b938b2941f4f0940c53a2f53da1f523d08ac18e2f8bc4dd9cc96b52a5Virustotal results 41.27%Heodo
2020-12-23E9Q58R0EZ7.docdoc b1094f6feb1a423a3b72309f5d023edd3d9509d5444912064029530fe0e8842cVirustotal results 39.68%Heodo
2020-12-236QBRWB0SW.docdoc 5f5a9d7e2e333beb6d779e447aca446f5bf88a9e05585ef90b1be35599c57ca3Virustotal results 38.10%Heodo
2020-12-23RBPNFR8WY7XZJ34U.docdoc 9e353b38f1dd65bbd6f1e50dc63ddc1350f17b8e382a9fe24328cf1f1609b181Virustotal results 38.71%Heodo
2020-12-231LW3VBX1CUCN.docdoc b534c439ac7a89c6af82331ebd70e5b5ce5e13a2e871bb7ab122b00004605e97Virustotal results 37.70%Heodo
2020-12-23FBROHWOO.docdoc f5e18d77f12c97a41d3afb41a6e69789d19fde04ffdf39ab1f53acd22185b83dVirustotal results 36.07%Heodo
2020-12-23LVGYNTE9P28C.docdoc 14b878d7208fdf92d601e33a77f38b05f586c568ff44cf3e7e73b8b2e1dadad6Virustotal results 31.75%Heodo
2020-12-23DQ7GKCRKV.docdoc c80244df2388e37d8c799e9968c52c9ad8c72b789ad85a2a91c35f8c28b0afd3Virustotal results 30.16%Heodo
2020-12-23P7MJDQB37FE4EO3.docdoc cd26f4220386d91ffb1a0233ece99c207f4335aab6a4c6227d64756f16500ef7n/aHeodo
2020-12-233MVNTNUV.docdoc 1f0dd0263393040d067ed555d604d764634263e4eb014755feb5d319af9db68dVirustotal results 30.16%Heodo
2020-12-23KXA9OP.docdoc ba96b09e7eeac72b4363f7b0749f36b0f3b68ecb4b3c40462d0f9d426b4cb483Virustotal results 30.16%Heodo
2020-12-23PUQAT9K.docdoc 80eec607b84d6c759ebbb5743e91d1ce1581bb83128c11b70467d1dd2e4beff0Virustotal results 27.87%Heodo
2020-12-23PC3OZBJOP1.docdoc 158e3c1a9e0f1942aec57f44ff4569d2a576bad56846a77053f5b4f726c14258n/a Heodo
2020-12-23CETKU53KGBC.docdoc 9c7952a624d186c2b830ab71d66e1e4369b998c0cfbf98bbc7530f5369530000Virustotal results 26.98%Heodo
2020-12-232OFERPNKN05.docdoc ec49319ad4b8ab163292c8a1332640a715616436de18d6b1124f4cc51b3cb4c4Virustotal results 26.98%Heodo
2020-12-231RSMA7BDXLOO4U.docdoc 47a492a3a0bfd3d8e0e6c5b72d0594fc8f387d657c457da34d5b7c097f8ab9deVirustotal results 26.98%Heodo
2020-12-22LGUNIZJ8XWKM3IK.docdoc 000b049debe1595e96d46d2cb910795e269d9d3f1b3210bfa45901356b3b3b3aVirustotal results 25.81%Heodo
2020-12-22ZK4SKLSM6.docdoc 54a40564f1605df3d177f233fb61ed59c38f1c8adea1284aab637fed81289a4dn/aHeodo
2020-12-22I3LCYP53N.docdoc bc80ebc602752fe60bc486b8620ac2692c2cf2f368e79cecd3a281ce807855e8Virustotal results 20.63%Heodo
2020-12-227WGADA6X.docdoc bdfab9675a34c6da34487f2c70f297960002e6c3c2a8e6fdc60ae7edbe67101eVirustotal results 20.63%Heodo
2020-12-22KMFGG7IRK.docdoc 9da1b2de73b87188343a6af1fb13673f844abdb2a7396f528f08b6498cc2d4c5Virustotal results 20.97%Heodo
2020-12-22QU623LG0F0H76R.docdoc 9f7aad87f317746b7406ba4aca0dd08523157fee59f582eb3e1022e92fad7f73Virustotal results 20.63%Heodo
2020-12-22BZ7KCTJ.docdoc 0e0a8e32415a80ba95b8af747d13f3b6312498145d1677df7641ba3c9cf8e9b6Virustotal results 20.00%Heodo
2020-12-22WZ469SIR74Z.docdoc ffce79e8ecfa61f2f82aa9b40d611c100e6cd68cde6fc34b012ebbd21750908dVirustotal results 19.05%Heodo
2020-12-22BAGHL3PYZSJWE.docdoc 012f7f15e9d4bed2d2d8ac3019cc2197b728f54a3650cd0a5d8463e6a2d95525Virustotal results 20.63%Heodo
2020-12-2243ZNLPXKU8UUIS.docdoc dd46d8d699adb12be39a346f3c02ca28633986b1a1bbe3f578a4a073100bd653Virustotal results 19.05%Heodo
2020-12-2275Q0QX7A7.docdoc 4b89dfb2fe2832ee2b48fda59db6b7394a32e427c0363058b6d9caa2eb21d3b6n/aHeodo
2020-12-22US8O3I1.docdoc 282e189a38374ce617073f353580971897a17a1eae677743234fa85c73cb5225Virustotal results 19.05%Heodo
2020-12-220R4D8H5MDN65.docdoc fabd2798310f1b90dc1321bffbfa1ee8c41695839459d40fd6e32618d3df7ccbVirustotal results 44.44%Heodo
2020-12-2235V7APU7.docdoc f9cde2aedc4f7b8ed8a2795c97febd0fa0caf980946d9d19819e7ba870f2ac23Virustotal results 44.26%Heodo
2020-12-22QM0KFWMQ0Q06N.docdoc 6191dcfff06f36e7ae3ffab9272718d60482913bac94ce985ce8a5eaca930e26Virustotal results 43.55%Heodo
2020-12-22RP4OC0.docdoc 46d74826799bc3bea6197713c8b199ed1faed920028c4d3acc7cbcc186276b6fVirustotal results 42.86%Heodo
2020-12-223JDL6IUR3QTG44N.docdoc 5f4018dc3b1690532b9c475183c9b2d86113ccf0da5fea7459275baa9a0af22eVirustotal results 38.10%Heodo
2020-12-22FUQEQP4H.docdoc 14bd83ddc0151fe3a56edd4209b619cd49a7ec1d198bb98d31972295a7b0375aVirustotal results 38.10%Heodo
2020-12-22OL95PC.docdoc d119b2da995343a322c42995a220a5d61f07c6fd252ce79a3ece58d89bb66690Virustotal results 35.48%Heodo
2020-12-22N53C3R7D6.docdoc 0334ec20d13ffa407ac139926ba5f520502351288061eca20ca7d31cc9100d26Virustotal results 34.92%Heodo
2020-12-227IF8OPAU.docdoc f1d7afa9f6fa472313a13e477f62a40c8a9bd241db908f877589ba665eb6fbdbVirustotal results 34.92%Heodo
2020-12-22XKT0LSKJOF.docdoc 6e80cf87bd4ef21287958848ca5250a78cf17cf17f09a9b1b11cd37a01a24202n/aHeodo
2020-12-2223EPGDO7V7.docdoc 7ec200a834392208ae8521c4804d11ff669137b4265b732a17660527ccf3cf36Virustotal results 36.51%Heodo