URLhaus Database

You are currently viewing the URLhaus database entry for http://esgfiltration.com/cgi/Iu9Rxxzz9LEYPNh4Si0qPlnnCJswKNN9qgy7xzZ6NNGYhdwd8cx6/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:938882
URL: http://esgfiltration.com/cgi/Iu9Rxxzz9LEYPNh4Si0qPlnnCJswKNN9qgy7xzZ6NNGYhdwd8cx6/
URL Status:Offline
Host: esgfiltration.com
Date added:2020-12-22 17:26:05 UTC
Last online:2020-12-23 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003189877 created on 2020-12-22 17:28:05 UTC)
Takedown time:23 hours, 13 minutes Good (down since 2020-12-23 16:41:24 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-23INUY4817JARRG9O.docdoc f989bb90fd752549af52988b47a9cf55638f97c26ea723457efd21cdab409da5Virustotal results 22.22%Heodo
2020-12-23U06QXXG.docdoc a8a5d52ccfe6f7bcc1ef7c99087ec90083ea7e3851e760b0653bd4189d54bc9en/aHeodo
2020-12-23U17W47.docdoc 383bbcf6e40f5db6ccf0a07f33eb55614c381daaae647ebf0ed8db148d4ab7fbVirustotal results 20.97%Heodo
2020-12-23MV5ZPEQUAAC.docdoc f0a4ee510f94aaef257225740c62c4a65b2da3ced23ca6b1513b9fbe11fd3cd8n/aHeodo
2020-12-23ELT3QOAN.docdoc c31a2ac228c882d72c112ad120473d012e0ba62c8d157e83cb7738293120eb15Virustotal results 20.63%Heodo
2020-12-23DVQYAAU.docdoc 3fbfd6e982d209b8a17b661954954d34ed049c93ae235bd736f558199b81aa94Virustotal results 41.27%Heodo
2020-12-23359L0UXXFVD.docdoc 93901d975d0df11ab32c4eaf841b43684882ce002e1222696c629076b1b81792Virustotal results 41.94%Heodo
2020-12-23KLBW01B.docdoc b1094f6feb1a423a3b72309f5d023edd3d9509d5444912064029530fe0e8842cVirustotal results 39.68%Heodo
2020-12-231T2ZBAKCEQIKOW.docdoc 69c857ec1c8b113638e61d8da49ffbda13878a0785aab5d567bdc3fe251fd3eeVirustotal results 36.07%Heodo
2020-12-23TNWB035.docdoc b534c439ac7a89c6af82331ebd70e5b5ce5e13a2e871bb7ab122b00004605e97Virustotal results 36.51%Heodo
2020-12-231ANWKKCAT20N1.docdoc e1624ae5f5ab385ff8468ca483e628d08be7ee14d23f030d3682a3f97d360c5cn/aHeodo
2020-12-23Z9B5YJ3VTJOMHP0.docdoc 14b878d7208fdf92d601e33a77f38b05f586c568ff44cf3e7e73b8b2e1dadad6Virustotal results 31.75%Heodo
2020-12-23PBR8KH.docdoc f857002c29ef1a357a541a2a1dc3821d6f7b739ac3602a22be8c6861d0f4b8b3Virustotal results 31.75%Heodo
2020-12-23ZJE9NV3.docdoc 525689f16129765cbfcab859edd5d99fbbec461ea04160605819b2f4b6150042Virustotal results 27.87%Heodo
2020-12-23MDOXLRH.docdoc cd26f4220386d91ffb1a0233ece99c207f4335aab6a4c6227d64756f16500ef7Virustotal results 31.75%Heodo
2020-12-23G8Z8W1NY2.docdoc e9c79c389f9e0132834f2da34cf19158e44330446302146e5636b0516d65ed51n/aHeodo
2020-12-23AXXPKDKHZV.docdoc 168fe6ffe9e78f01a7f784833ba9306ef1edad3ccea334df35937424ef0220bcn/aHeodo
2020-12-23ZNTM0CPO7E19MK.docdoc ba96b09e7eeac72b4363f7b0749f36b0f3b68ecb4b3c40462d0f9d426b4cb483Virustotal results 30.16%Heodo
2020-12-23PWI63L9YJZY5O.docdoc 64df2f4241becefb0876d62be5908b4d62620e2aeb97828cb2819d952d106f11n/aHeodo
2020-12-23XN6NIU1C2AL55Q.docdoc e56e47b889fb43e8b9f183ee7abca3a349cede2826008e189de20df4b7bb481cn/aHeodo
2020-12-230TQ4XC2U6AOJG9.docdoc 9a8b914d6bb8ae09a04b32fc897fdb9a9ffc073975b436b031ac837b7eeefb0bn/aHeodo
2020-12-23KEKU6E3N2XXZV704.docdoc 521ef9721a64f893dc83cf84caab9a76ce0b537e5605d20126c954d3489d89e9n/aHeodo
2020-12-23X7R1WA5IBH2.docdoc 47a492a3a0bfd3d8e0e6c5b72d0594fc8f387d657c457da34d5b7c097f8ab9den/aHeodo
2020-12-2387H0AT0.docdoc 9d2ad424f8d1a39e1cf83b8d64131bc94d8b8ecf787b626e1118e348fc967f10n/aHeodo
2020-12-22WV2LZP00C0A8EB1.docdoc 815857993a030da4586f91406591e013e670d9a286faac31e529668bb9a169c8n/aHeodo
2020-12-2258XJKD91YVN780.docdoc 32dbb92d892c9f50e99fc70db5b9f3efe0721a6464984a3f84e6592cda81684cn/aHeodo
2020-12-226HD6EO7UMKZ9FPV2.docdoc 54a40564f1605df3d177f233fb61ed59c38f1c8adea1284aab637fed81289a4dVirustotal results 25.81%Heodo
2020-12-22221BTI5.docdoc 893d0822b033e0d5ea0484d9a61ce0354833603684cfb54e8e493f2740641784Virustotal results 22.58%Heodo
2020-12-22KR7P8BRVMA56.docdoc bc80ebc602752fe60bc486b8620ac2692c2cf2f368e79cecd3a281ce807855e8Virustotal results 20.63%Heodo
2020-12-22SN3TA8KHHAN7LSE.docdoc bdfab9675a34c6da34487f2c70f297960002e6c3c2a8e6fdc60ae7edbe67101eVirustotal results 20.63%Heodo
2020-12-221TCVIJ0XX376YJ.docdoc e2e85f53c26daaa6cc7e1fe602e51f272ac256cc0c23725350d37b4a5a888520Virustotal results 19.35%Heodo
2020-12-225EK0HEITKJ.docdoc 3a6a1a101ff166519b8b881efee09a67e6b3fdd9de23e64eb8811d52604d9923n/aHeodo
2020-12-22R57MCD0BYBBCHI62.docdoc ea9e0d2591e09cdea3ac66cbd5410ca96f9bbb033f240fd580c71854292003b9Virustotal results 20.00%Heodo
2020-12-22GJCBOTT.docdoc 29d2dd0591e75e000a0c6b8b889a9a1cafe79ce1f5b6a3468d55e31d7a820490Virustotal results 20.63%Heodo
2020-12-22QDJ2M6SJB7R5MN1.docdoc fdae3e00f4bbdb0f496d2b32042e4e5ceb4c10422ae4c809777f5677e0f4a2eeVirustotal results 20.97%Heodo
2020-12-22SYMDT3Q6F6F73X.docdoc 98ac350c9b7c510b5ebc70b57008f105b7c25a1db9f0b50390dae799a242f9b1Virustotal results 22.22%Heodo
2020-12-22PF90EOC31FQATP9.docdoc 4f5599c715d0f5df48a422eccd4a26ea4241f806855c3ef36fcc7db874c976d6n/aHeodo
2020-12-22L2O8NFY.docdoc dd46d8d699adb12be39a346f3c02ca28633986b1a1bbe3f578a4a073100bd653Virustotal results 19.05%Heodo
2020-12-22MZ31AJTO.docdoc 964002e25b6ff27acd3902a75ecc4293ba67968a23055e94748a0ba2c31c8d78Virustotal results 21.67%Heodo
2020-12-2213YSE04URD.docdoc bcac6e544a85109fa2e8fcfa76dd269f02ff7b933aceb784575da053e1f940ddn/aHeodo
2020-12-221KEA1GDO776.docdoc 8d0a380012f874d975499d45632b01438dc0e7a4d6bdf4791c400e375b02acb4n/aHeodo
2020-12-22N72GQLH8IEG.docdoc fabd2798310f1b90dc1321bffbfa1ee8c41695839459d40fd6e32618d3df7ccbVirustotal results 44.44%Heodo
2020-12-22V0QX4D2GAJX2OUE.docdoc cf6c363eb34d0c34ebdf5b4e79c44e7bbf6a2831b189f929102e3da045fd0b26n/aHeodo
2020-12-22AQN3Z38W2FLYG8JF.docdoc e5b0d3a8fd2f8c0876aba637820cea0b01866dde8e089454066e1f6ece8e7669Virustotal results 42.86%Heodo