URLhaus Database

You are currently viewing the URLhaus database entry for https://salooncloud.com/cgi-bin/mxz8WoIrYUmtkzJjOOshrWIFITnGKR2DnbAop0zgAUR/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974584
URL: https://salooncloud.com/cgi-bin/mxz8WoIrYUmtkzJjOOshrWIFITnGKR2DnbAop0zgAUR/
URL Status:Offline
Host: salooncloud.com
Date added:2021-01-22 22:56:05 UTC
Last online:2021-01-23 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-01-22 22:58:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 31 minutes Good (down since 2021-01-23 00:29:14 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-23VPURXT.docdoc d5da4dc5a6a3fc416aca8ffbfaa3b6cb18a1efd11b94eb7f40a584fd96813f8eVirustotal results 46.77%Heodo
2021-01-23M6JJCDG.docdoc fa5a2480a61176d9ef8d383ec2a77a0902bd417188b64418d1920e74505ffc1bVirustotal results 43.55%Heodo
2021-01-22CSIR4M8O.docdoc 70ac185fdce6d551871ebe57cb2bd1b36cc4d721755c57e27a21fc81beb31ce2Virustotal results 45.16%Heodo
2021-01-227IOR3KA2.docdoc 106d381e6f7de228eeca31e1ff0745404f3277db77946b9c462163b70bd5dd1eVirustotal results 44.44%Heodo
2021-01-2271L39DPU43MCVZM6.docdoc 4a53e1dd32dd8820593de18379151f5fd51cc261df4c37218b3a209525a3f427Virustotal results 44.44%Heodo
2021-01-22D6WT2L8HOO5.docdoc 32e2565a19640e807ad76200f596703df5b37e10700339c32dd915fcb495bf9aVirustotal results 44.44%Heodo
2021-01-223VYN21.docdoc a9298f2707a11dfbafc02b9880250f2fde9e11b3ed26c80bd952ee4c5f41c667Virustotal results 46.03%Heodo
2021-01-22HWXXQUH2.docdoc 6776f53efed3f91af5955bfaf11f47dbf6fcf5b5a419e1bcc5a29fb89a61ea49n/aHeodo