URLhaus Database

You are currently viewing the URLhaus database entry for https://www.thesanowell.com/Database-BKP-28-7-2020/2ObmKQ80yMCSo4MY4z/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:949638
URL: https://www.thesanowell.com/Database-BKP-28-7-2020/2ObmKQ80yMCSo4MY4z/
URL Status:Offline
Host: www.thesanowell.com
Date added:2021-01-05 19:59:06 UTC
Last online:2021-01-05 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-01-05 20:00:05 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 0 minutes Good (down since 2021-01-05 22:00:17 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-05FI2ZJHB2U7Q86M.docdoc f41191d034c431b657fe3879db9d982768d93e77fff9ba0cae2f7aa6de52a6e6Virustotal results 42.86%Heodo
2021-01-054BRD58HW6TSS6.docdoc db13b0bb816476742e2920b6a33274082f378ab0538824d8027c8a2b9947d102Virustotal results 42.86%Heodo
2021-01-050Y58VJB8SQI.docdoc 8c829198897d8ba3dd5a5b1f86741c5e5295a0eafb900bfa440802d1c622c469Virustotal results 42.86%Heodo
2021-01-05JT1QGWTK.docdoc 961a80ccd1b1e38897c5003ee920895e6fc6cbb1799b7b68c4429d8f5b5f9c64Virustotal results 42.86%Heodo
2021-01-058OYGPAHLIZ5.docdoc 4e30a0c0d464a13919be9367c51ec2d36f2972e27861997410add5b113bceaban/aHeodo
2021-01-05TY31KP3MO3TAF.docdoc 7f9e6b9183a6a254ffcd68100012d645a5fb91caaf3b727bbbd76f4262595bb7n/aHeodo
2021-01-05J6L3UJ6FRZC0DN.docdoc 6792a8737e9fa557cdbfc232021a5c2efb01b55d3bf1d560e9ca9671f8af9fbeVirustotal results 42.86%Heodo
2021-01-050H7CNFA.docdoc f523129d974646f058a7140e90962995cd50693902db2105edf607d7b78213deVirustotal results 42.19%Heodo
2021-01-059YCDJH7MYXBNQB28.docdoc 3c8d3c07935afc4bbc31b8c4a7a6b2cc77bdf0c2985a9595ec9edd6d3e8a5279Virustotal results 42.86%Heodo
2021-01-05Y82N8IJW6H6O.docdoc 80454b5f97454034a460b2976c3161f4efcf1131cb3ba594669114a46e069c98Virustotal results 42.86%Heodo