URLhaus Database

You are currently viewing the URLhaus database entry for http://nirhas.org/cgi-bin/sec.myaccount.docs.net/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:170794
URL: http://nirhas.org/cgi-bin/sec.myaccount.docs.net/
URL Status:Offline
Host: nirhas.org
Date added:2019-04-03 14:04:13 UTC
Last online:2019-04-03 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-03 14:06:02 UTC to abuse{at}e2enetworks[dot]com)
Takedown time:4 hours, 12 minutes Good (down since 2019-04-03 18:18:09 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-032019_04___BIZ_0713230109394607___2177924869.docdoc 5a25bc771de52fd4b40e90d788194e5b20d465606a2577321b10abba5df93b20Virustotal results 30.00% Heodo
2019-04-032019_04___REC_026764816741972174___0829319819.docdoc efb37a6a0bb2077d1b5c8f9a3ddc2fa70bf4b2c4e21c98df9ca91d1ae672df66n/a Heodo
2019-04-032019_04___RECH_53436150901___0839527266.docdoc ba19e0b1b55163d610eed2d666e91ce17c1af65618d61c6887436b8da54b0a44n/a Heodo
2019-04-032019_04___RECH_21547263365___7052396723249.docdoc c2ed243b37f6248036cfdbd0dc743fb664fff8dfefb92f81942028ccec1c567eVirustotal results 29.31% Heodo
2019-04-032019_04___RECH_69966766019276___3809936626.docdoc dea10b78972814eb7c996fb83f7bf9b0749cffaa83c6daac5d7aa12aa690109aVirustotal results 29.82% Heodo
2019-04-032019_04___INSTR_2855249353___576875634579.docdoc 6b706516aa4a6c84d7288790bd311b5ff46812d716913cdb7e2868b7502eb5f5Virustotal results 31.67%Heodo
2019-04-032019_04___RECH_19868864894___27526835750681001569.docdoc f6e05aea9f90a7a944d714ed205231ed0d6b0710b69140ceb6e1955194c586d8Virustotal results 29.82% Heodo
2019-04-032019_04___DOCS_9474493314047___097029589298.docdoc 9731cf4485184f19d7b72f44c3a88e41b4e58b4e523eb25946bfe51109d58b4dn/a Heodo
2019-04-032019_04___BIZ_07415954653123183___4893491112.docdoc 16c7269bba293e77681057618f2a44cc22b1259b1e06576230fee8273dfc4d31Virustotal results 28.33% Heodo