URLhaus Database

You are currently viewing the URLhaus database entry for http://shifa.sa/wp-admin/NbtxKRENMNlV3FEKqxJWawuks/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:972782
URL: http://shifa.sa/wp-admin/NbtxKRENMNlV3FEKqxJWawuks/
URL Status:Offline
Host: shifa.sa
Date added:2021-01-20 23:52:04 UTC
Last online:2021-01-25 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-20 23:54:17 UTC to abuse{at}digitalocean[dot]com)
Takedown time:4 days, 8 hours, 59 minutes Bad (down since 2021-01-25 08:53:58 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-22SML0GD.docdoc 58679381a46d62f343527eddb0e188a30184ea770eac5182c427ff13ec75412cVirustotal results 44.44%Heodo
2021-01-22JOBGQ8I6IJ56G.docdoc a9298f2707a11dfbafc02b9880250f2fde9e11b3ed26c80bd952ee4c5f41c667Virustotal results 31.75%Heodo
2021-01-22OIC3VC0HZYODY.docdoc 5705fd96f5d9b9500a5efc36a759c276ba912d8eda40677ed5d0fa58f1a843e0Virustotal results 42.86%Heodo
2021-01-22U4A0CPX53FEC8.docdoc 74c41fdd82136763f1fe4daf52b1e388f2a4cf39d73e441f895023247b23f720Virustotal results 45.16%Heodo
2021-01-22JKD40IGG4Y9I.docdoc a4ca64ab0ba7ae814fe635ce9bf2febea22c4f78b6d9310948f751713214c0d1Virustotal results 39.68%Heodo
2021-01-225PNCE6YY.docdoc 572f2066bd622ffae9324046ef4e96026a4bff32a177c91ea779269d75ac98b7Virustotal results 38.71%Heodo
2021-01-220YRTI6NF0TTA.docdoc 377ccf81bc50553f09c559652bad5ec67c73c649cb60ba53cfd01f39a52e5ad2Virustotal results 38.71%Heodo
2021-01-22NOVC0LP7GAGC0.docdoc 5baed32dcd265a53a8f5f4182bfa79336ffa1acc17f1ab71e8387529a82b10cdVirustotal results 37.70%Heodo
2021-01-2296AUSE0F311WH.docdoc 8af280e70fb92f35455e9f18296c0fbaae42288517c6925a9db673a9368e9bf3Virustotal results 38.71%Heodo
2021-01-224DEYT0J.docdoc 9849abef3e272dea13e211d946b289bc80ab32efd5e83178ca17a6bb094be274Virustotal results 35.48%Heodo
2021-01-221Y0R9SV6UQWY.docdoc 912f6f38547eca79cdd2f66b1252ac5b777f454c8d4da059d319ca9a42d1cf24Virustotal results 37.10%Heodo
2021-01-2298KSIENWAWBLJ8.docdoc d25d5d359b01bb46095375c553f2b4ea91e2e4abee77df10d21d6ab08740dc97Virustotal results 35.48%Heodo
2021-01-22PJBNRMMEQ2F.docdoc 1cc3ce82c3d5c07a7ad73b7890969696e032964b0773b29a1f21a68dc55e23d6Virustotal results 33.87%Heodo
2021-01-22AXJGY21GO.docdoc a1714164bf96046b86ee335216b926f51c376447578ad9dc401301d954033388Virustotal results 35.48%Heodo
2021-01-22RUMFM0DVQOH4.docdoc 0c12f24715c776b1cca7c4fcae52f35da82d11bc17f962cbc7a01b7baf4e0078Virustotal results 33.33%Heodo
2021-01-22Q65AFTN96ZM950.docdoc df7956bed96a8d21cc40f5f0abfb5fd98df9ca8f98982661f6ad3c9bf38a2740n/aHeodo
2021-01-22C9DKV65HB.docdoc 18eeb3c4acd968e5fb4a847ef4eb4953690be2b5a9ad36d6f82a9cbc7caa7a53Virustotal results 32.26%Heodo
2021-01-22P5GPECI1.docdoc 60f3cccc565f86125180e95278bd3c6806963b46e96e1f6f1bd67aba3151eda1n/aHeodo
2021-01-228GQK1GKR6DXZ3L4M.docdoc df5ff0dd34808825942b6b896c5129f63bc36f8fbbba7f3ce145cced467c662aVirustotal results 31.75%Heodo
2021-01-227PR6719H5C4OP5DP.docdoc e35524adab62617f979bf2093ed1c81d50ea11bbf40b3f32bc000a58fe99a39cVirustotal results 31.15%Heodo
2021-01-22XPA7IM.docdoc 79901cb00c81b1c2bb626096ee6bdf18e1bb6e757f7c48c0bf1c0377e9d3cde8Virustotal results 31.75%Heodo
2021-01-22UFM9HKT.docdoc 6ff60fa0ed16508f73c39701cb9dcd8b1440b3778b8059d97ad3a25cabd65cb7Virustotal results 31.15%Heodo
2021-01-22BLB045TVW4QUJBID.docdoc 19eabf766e8a1eab6d6736638f9331a3ed1606b329cf336e4a564c8b0ab220f4Virustotal results 31.75%Heodo
2021-01-22YV6K4H75X3.docdoc ea21a75b3954d828b7a840979fb0998d7726faa8028f57af1cb53ac417955d5bVirustotal results 33.33%Heodo
2021-01-22HTJO9USS.docdoc 4645da6dadb364b09a0a89f510be736a7bf0d088e5b79a002bdd4bf430ff9fa0Virustotal results 32.26%Heodo
2021-01-22Z3J50JE6S0E.docdoc 4de1c4143ae99fd06eec658e5c44de43c165410d78622490b2ffa406a9f66496n/aHeodo
2021-01-227D48V70C0KI.docdoc 0dc0f00a3ed385b6bff2f9188766ae977a173405c9bfed86474e9f7fccfde9c1Virustotal results 31.75%Heodo
2021-01-22JI32HAXC3LZ77LE.docdoc 5c7bb8c2bd7a115517be5d5b370391154304ddb68b3d29a464c4cb93521e1bf6n/aHeodo
2021-01-22NC7O70GGTS1OMOB.docdoc 412e0d29cd1f9172956d1b322e2410c0d329e3f476d8ece5853ec00d0e421042Virustotal results 31.75%Heodo
2021-01-22X377EN.docdoc fa73aaf86c492584aab024beb61b333cb383c5a742ae789e1c20f40d599a9457n/aHeodo
2021-01-2211VTAOZ7KT9ZXL.docdoc 3db3bba8b8ca33c0e549a0903a75ff84243f83de0e5b3a86a338887689652972Virustotal results 31.75%Heodo
2021-01-22GMREN1.docdoc 98d8a069e31ddf52bebf1318faf2efcd49c1664d4735b9076ca64e8f62f94e71n/aHeodo
2021-01-22PXWXCZE57KCX4.docdoc d92a54af3f591d380ccda2fe2e6615fe25539fc09d8afb14a06ab0896e7b58e9n/aHeodo
2021-01-22YAH4QEYWW.docdoc 80ba08b994580df8c476bec4479e8fc942b9da8ea70810fce0658e56af6ca5f8n/aHeodo
2021-01-220C0O3TC2O6UP7C6C.docdoc 6b2fbb5e14a3a1018e7cbf6b37d303d86504f0fc412e8d0f0db3100162bfdd0bVirustotal results 29.03%Heodo
2021-01-2214Q7U1XD4Y.docdoc 4e181ff0a4f2c6e578ee4432182878b7972cc1f03dff754a7ebe4aa0cf51887eVirustotal results 29.51%Heodo
2021-01-21VNF5BQTRYFSMD.docdoc 3a0235b5137c1d8dffa67e97c6dbe13cfc7117e3c62dfee05d8897acdea83b5cVirustotal results 40.32%Heodo
2021-01-210URPLXAYJ87.docdoc 54385e84d22e522ecf660abd63e8cdc132b0ad766af8d7c589b13f7be5371c2dn/aHeodo
2021-01-212DX5JZTVMEX9SM4.docdoc 4121d45c89baa331a26e0dd4c638c04a81fd89a98b09675d3e1cb3c0a57c80dfVirustotal results 38.71%Heodo
2021-01-215A9PQN3K2A4U8PYQ.docdoc fe4636a4066b3525d7bc3a58f2a3ac8c430e3bb88f0e975869c95e7cdc91aa5cn/aHeodo
2021-01-21DSI5IOEP.docdoc 101b256c68bda370bc6e6d2bb174494911b42079e76fcc63b34f0900288c3f26n/aHeodo
2021-01-21XN21JVUVAYKPAJ.docdoc 734760f1587fe2caa03e721fc7f70c74e90517fae7f02f75ca4cf60cfa2c947cVirustotal results 36.07%Heodo
2021-01-21IG3RM45MZJX566.docdoc 92479f2f51bca6692c4c3d53b3f9a49bf1d5aeab01a98e9a2feb0d6d68ef6343n/aHeodo
2021-01-21D7CS3JR7FFW1R.docdoc 64a17440d41fd8eae4685249c345b5022f4e690183200645ff1e6f7f804159ben/aHeodo
2021-01-21QTHGIOAFPV63B.docdoc 4142cfc2bb8a067a21c0439bef1d08e1742025b00b3cb1c9619ff7bf0a2b42d6n/aHeodo
2021-01-21PD04ON8.docdoc 5194a406cd4f741d308341f531f690bf966b451f01de1fbfbb604dbefee7c8efVirustotal results 35.00%Heodo
2021-01-21ZV898YOK6S6HLX.docdoc 1599e10bc74eeb7b67c71bbfc12008d0f8bc8c3457297d017e2c633457a5800fVirustotal results 38.71%Heodo
2021-01-21N2N770PFW8.docdoc 5a17dee61b79152ce451f560a17603b291bd0934b4c0bdb69a3328fca8b36771Virustotal results 39.34%Heodo
2021-01-210CMW68L7HL3OF.docdoc fef516c40db60794e220e323bd96e2a26f5808d97ac911e2bd4afc4b0cd756bcVirustotal results 37.70%Heodo
2021-01-21MJIBU2DM.docdoc efefc84243ccc08a0c004247847a2e7c55dc7559eaf302919c40085ff83f5c4cn/aHeodo
2021-01-21SXHJUP0U7.docdoc 8d7efeeb6526c1ce01dd7d5a75a5f9c22d9ef5dec9e19d6504cc1d073cf8c864n/aHeodo
2021-01-212SOOQE2NGG4MD0.docdoc 66840e0ecc45de6d60dfd40a9a510bc1664f4121d4e66b498fa33e3b1cf2ae31Virustotal results 37.10%Heodo
2021-01-2150KWDXOYTEYCUFJD.docdoc f1b16a95d60e942f2ca4724096a5a078f74d16d045da8ebf4cbd11d1fcb25322Virustotal results 35.48%Heodo
2021-01-21SG7I2LRH.docdoc 1ade51b62019cdf1df087f2ebf35d2d5fe4aa1bc5a03d76324ff346bfe5d7953Virustotal results 35.48%Heodo
2021-01-210QS25OIXBFO8T.docdoc 50b410f2af280b1a288a0f94bae66b4db4278e307b1461a93a231a2ca715cb53n/aHeodo
2021-01-21TVPANHGLRO.docdoc 2d75bc655ee87200243a8c0f383323e49eb31a7b0cc6f86e4376c41f83e0f542Virustotal results 36.07%Heodo
2021-01-21YVLNLTH.docdoc 6666bd131bccf0a6bf3973a274445780cd1216aa9260c08d10a079c9ea58cd44Virustotal results 36.07%Heodo
2021-01-21V9QMK2HTNZ4OS.docdoc 2a4e442727def25a8ce8ddc73ffa52be640dd1f1016dbc26e3157f361936aa88Virustotal results 34.43%Heodo
2021-01-21IZJG86S5ZQCAV.docdoc a58be0e3ba5abd6441bef2a7efcdffa251f5f396685642160a2508363b75395fVirustotal results 35.48%Heodo
2021-01-21V6A40UZMGEO.docdoc 6696dcee2f90b0c3f0614d8197a15ce194e31f0940e923dd5f9bb95fb42fa479Virustotal results 34.43%Heodo
2021-01-21UFC068CXCDL.docdoc 46512d0921fb5626d9080c7f3930e3b4ffb9cd15bf20c8554f150e7ff47b951en/aHeodo
2021-01-213MHD4RUD.docdoc 38dd4edef2de2088eb63ab88c4213512a1b0bc748d115d2ed16ac1c5c2cf27b7Virustotal results 31.67%Heodo
2021-01-218BULW5Z.docdoc 2b74e583a0148f1e5f2c91424947740e520cd67c66c78bc6a20c22fbc34b83d6n/aHeodo
2021-01-21SNSZ6I1V237HRWW.docdoc b0b540ad237698caeabe4f0eb6faa0869a39484393d922cd298e23b304562845Virustotal results 37.10%Heodo
2021-01-2166P7VRA.docdoc ba3aa81154976cc9bdd719ecce4a925b513892f51cf40a1f511d77d1c180f1den/aHeodo
2021-01-21LVO5RIWBR9EJAP3.docdoc 58087e36eb939fe42f9ecafa00c3ba4002c238182b406a45db0ffa7ae6e83398n/aHeodo
2021-01-210SUEHGWJQ07VSP6U.docdoc 943f25050a280f1b3fc1154ce8740d31f30935391a7f7e9cd1cb0152f46ff099Virustotal results 35.48%Heodo
2021-01-21N0R6YN0I1IGCIZLB.docdoc 4ba19977d7051012b6f22a72868e1c909438f6eca3e725dde0816c11f5d7f262Virustotal results 35.48%Heodo
2021-01-21K5BVTBVDW8Z74G.docdoc c81d0f1555b356115f9478fb3e1a082fe834f56fa4361077081cc7c399d5bdeaVirustotal results 37.10%Heodo
2021-01-2132N67T663GHRT6B.docdoc 1df953e34823f8351e1702bcda5b4b75887620f2ce403968f4cb0524e89bfa65Virustotal results 29.03%Heodo
2021-01-20FLC2H5HHH2.docdoc 019f04b6b435d65725a7fea600c318e96d64c945fbf8ad3ee2f67d05900a27cbVirustotal results 29.51%Heodo