URLhaus Database

You are currently viewing the URLhaus database entry for http://ctm-catalogo.it/cgi-bin/KdvcV-64SQxY1rnOCtK7_unkRZWqe-vDc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:179136
URL: http://ctm-catalogo.it/cgi-bin/KdvcV-64SQxY1rnOCtK7_unkRZWqe-vDc/
URL Status:Offline
Host: ctm-catalogo.it
Date added:2019-04-16 22:41:02 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL :Not listed
SURBL :Not listed
Quad9 :Blocked
AdGuard :Not blocked
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-16 22:42:02 UTC to abuse{at}staff[dot]aruba[dot]it)
Takedown time:13 days, 9 hours, 21 minutes Bad (down since 2019-04-30 08:03:44 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-04-173438476-Z9-20190417.docdoc c1b0c4f67991d3ab081a20b0d018ee2bf4d310e751b44625ee47be0f9e9265bfVirustotal results 46.55%Heodo
2019-04-170395729-IX-20190417.docdoc 323153d98abb66d7f847dafa200187b6998dfbec52a13bc8e5db2f22f1cb2240Virustotal results 47.37%
2019-04-1799216154-2P-20190417.docdoc 6d24d29c50ef972b44f93ef0a4485ac1efde90c14c184aa2867c38a16c538bden/a
2019-04-177854798647-3-20190417.docdoc ce70a0d3e4ff34a67d5afae375a13450288eedd8734af6ce559bd070a261a87aVirustotal results 42.37%Heodo
2019-04-1791020921-0-20190417.docdoc ee888a9886b820609006301402c052364caca93f3c5f747a8be18ac0857e253cVirustotal results 40.68%
2019-04-171522868_X_20190417.docdoc 78c7f1c6bd57c9b5fd9deccd6c8eee1d22dbcab88b6093c634c49f50d92d8fe9n/aHeodo
2019-04-1738774535001_N1_20190417.docdoc 277f3c8d2bebb7ba81bc20c3f884f7ba97fa475595a794b701718526c739aa05Virustotal results 35.71%Heodo
2019-04-1727867158030-B-20190417.docdoc 672214a0abbd2153bde3cddb09d46ad3cf5a6a473fa339648ed22fbc4c7ba717Virustotal results 33.90%Heodo
2019-04-17957579881-N-20190417.docdoc fd6b351aa651a795ccc36478ab92b5fb40497dc6e48bc99f46dcc8ff9ef8fc49Virustotal results 32.76%Heodo
2019-04-1629228713229-5-20190417.docdoc 575dde62d6879599051db95345289d694bf6500cf6e0200fdbd87665498ab758Virustotal results 31.58%Heodo
2019-04-16598809282_V_20190417.docdoc a96996cf8b9f60a7cf268b030e84e316e1d3e25c4f3d290c918c059a541368a1Virustotal results 29.31%Heodo
2019-04-1631607929-6I-20190417.docdoc 4c6e32f15e3e4c6e3995fbaa852e28193a2dee4b6ccd33a25fc9c6681873f114Virustotal results 30.00%Heodo