URLhaus Database

You are currently viewing the URLhaus database entry for http://dbsandbox.ca/cgi-bin/wgV9dTlTdn9Ebgnqzd7Fy1mE1lTgJUimRK2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974657
URL: http://dbsandbox.ca/cgi-bin/wgV9dTlTdn9Ebgnqzd7Fy1mE1lTgJUimRK2/
URL Status:Offline
Host: dbsandbox.ca
Date added:2021-01-23 00:18:08 UTC
Last online:2021-01-23 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-23 00:20:22 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:2 hours, 20 minutes Good (down since 2021-01-23 02:40:34 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-23I8PELYICIIGCKX0.docdoc 3b8c1a7288a8940c4785141389d323f7949b9639ca7821ebad1fc2182a2acf58Virustotal results 48.39%Heodo
2021-01-231L38QH9QN29MH.docdoc d926e60d6b78f6b07a61842aa31c25077849e0921bbb8c454900a6b1447427c0Virustotal results 34.92%Heodo
2021-01-23YYSF34.docdoc d24e032bf95e95b0c1325688cb50b3eab851e90b9350f1a031668dd2bbfac3b6n/aHeodo
2021-01-2330VUCPNKBW1DIJV7.docdoc 56e78f5aeb76d3b2002f79b51c0344a1bc95e0c171a56f5e7bae43028543e1cfn/aHeodo
2021-01-23CM24PR60YH2EEKR.docdoc af3194c0b659d352c4c034514492465d714d13af99d02334148600618bfa61dfn/aHeodo
2021-01-23U9KYPKF.docdoc 1e6cf8d2575be1847bd2c4e53b2686b8346c940c315c68f3dcabe5fc53802dd8n/aHeodo
2021-01-238RLHFPZTT3.docdoc f2f810ac8d53caf7b5ad3fa8566ed61610f1ef80b7a9ef571b9bd112ba745909Virustotal results 46.77%Heodo
2021-01-23SJMO8Y8.docdoc f34429ad75df699dbcc635b6afcd91b52756fa1d34dce852fead86e0c7eea37fn/aHeodo
2021-01-2356KJWBBI.docdoc 06706618f6fb465f559d7359295a2757c1cfd4311ae5ad13d1b3ed2acac1a2b9Virustotal results 45.16%Heodo
2021-01-23E8EESYHI.docdoc 04d66ed2d7e82444ce4d2b8227f03b6612a55e843e3ef434c01c93b65f10ff04n/aHeodo
2021-01-23W7D6LRNPWTZOI.docdoc d5da4dc5a6a3fc416aca8ffbfaa3b6cb18a1efd11b94eb7f40a584fd96813f8eVirustotal results 46.77%Heodo