URLhaus Database

You are currently viewing the URLhaus database entry for http://uss.ac.th/cgi-bin/FILE/GDddX7MX/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:184937
URL: http://uss.ac.th/cgi-bin/FILE/GDddX7MX/
URL Status:Offline
Host: uss.ac.th
Date added:2019-04-25 20:13:04 UTC
Last online:2019-06-17 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-25 20:14:06 UTC to noc{at}cat[dot]net[dot]th)
Takedown time:1 month, 22 days, 5 hours, 55 minutes Bad (down since 2019-06-17 02:09:42 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-06-16SCAN_94242995931US_Apr_26_2019.docdoc b76ce0d6d120101e5e8074077fcd2b7a6e9845ee218ff83bacf9d3da908d77bbn/a Heodo
2019-06-07SCAN_94242995931US_Apr_26_2019.docdoc 3282fa7aea31332be1e2e8a2a2341fcb787751f3e66d9f004747b5e300cfa905n/a 
2019-06-04SCAN_94242995931US_Apr_26_2019.docdoc f111c572b002b50515fe28769f4a79dfd83ced3b91cde32c6bef99a651b9893bn/a 
2019-05-21SCAN_94242995931US_Apr_26_2019.docdoc 77f9396c104754cb8af24688d6765dea7d573c5c6a7a7cde2d1f00d3a73952ebn/a 
2019-05-12SCAN_94242995931US_Apr_26_2019.docdoc 9b761329b57fbd031cb8564624553d39cba22bd5385c3e6a2654f3ebbbe17523n/a 
2019-05-05SCAN_94242995931US_Apr_26_2019.docdoc a8a1dad1c8346f6a04f85f8f8e5771195f526d3fc4ac75cabd3e6752fdbf92c9n/a 
2019-04-28SCAN_94242995931US_Apr_26_2019.docdoc 364f53325d7aec630928ba558e5ccaa0eb4cce15092ae2785bb731fac43016c2n/a 
2019-04-26SCAN_94242995931US_Apr_26_2019.docdoc 22192880794d45b84d08e6a613f41a2e63f42e659571ed003c9fddf1319afa68Virustotal results 30.51% Heodo
2019-04-26Document_8496610126US_Apr_26_2019.docdoc 2d8657ddef24bf6a614be6b191d81d604035ef998633bb52ca99eeb390630d81Virustotal results 29.51% Heodo
2019-04-26Document_74438929185US_Apr_26_2019.docdoc a6afe1b349587b22463f2ce9bea4383a631d3a2aa8041b7820f927bf2f6b6237Virustotal results 29.51% Heodo
2019-04-26SCAN_0169506048US_Apr_26_2019.docdoc 7bfa867554a7f1a6a891712cfdaaf519bd44bdf53e0047930890495c9655ab7eVirustotal results 32.79% Heodo
2019-04-26DOC_7950241651US_Apr_26_2019.docdoc 3eb7c725b886abf672613a63d1c17c479f1144f1262a6c3cd66a44fe74581383Virustotal results 32.20% Heodo
2019-04-26INC_3296820809US_Apr_26_2019.docdoc a50d314e9c13d667641b11c73695980d1fd4cc0020cd7f760bdbd88bf95b1c3cVirustotal results 32.79% Heodo
2019-04-26LLC_437713366174US_Apr_26_2019.docdoc f5bdfcce3d7b96d9ebfb828380002a8541c41c353dda36edd8c467618d471fb0Virustotal results 32.79% Heodo
2019-04-26DOC_55324269917US_Apr_26_2019.docdoc 6f5795d34e8fa33548042554f0b05b6e79e9a68783f28a196476261a0de0e068n/a Heodo
2019-04-26SCAN_83597302094US_Apr_26_2019.docdoc b1709a55b71ba9559aa839eb5304e2fc2388ae6275771b6cbbf8f49ac3e355faVirustotal results 31.67% Heodo
2019-04-26FILE_2476324135US_Apr_26_2019.docdoc 9ec754906cd974949805241075b0309f01f428c0dffc53b4aaff2e43a79265bbVirustotal results 31.15% Heodo
2019-04-26DOC_916927552881US_Apr_26_2019.docdoc b6027234bbbfca5ce87c4757557f0a4a9ed2c54960d915eb215722fa703191f7n/a Heodo
2019-04-26LLC_4424434375US_Apr_26_2019.docdoc fd84376ecb2845381d03f46851fb6328f5c0f26c51fb515c74f21b2326031630n/a Heodo
2019-04-26Document_5504721642US_Apr_26_2019.docdoc a1be08364eef857af56f506b206e780c803c212b76dbac8dc17e7983d08f65ffVirustotal results 30.00% Heodo
2019-04-26Document_71559463739US_Apr_26_2019.docdoc 8065d2137332893c6e189b09a0e6b480e2f2955e827e0b67e4418e6a268da467Virustotal results 32.26% Heodo
2019-04-26SCAN_9043934945US_Apr_26_2019.docdoc 00a73162489f59b1cc4fc07208676176c19eadbe5c4c0f16b0bd3f7c15a9a03aVirustotal results 31.67% Heodo
2019-04-26SCAN_297380919241US_Apr_26_2019.docdoc 79aa4c12cd7acda388199e7e59ac3481b7e738ae2b3a43ac06bf08dd8f6b4419n/a Heodo
2019-04-26Document_5023946997US_Apr_26_2019.docdoc 1581b1babbda10ae6971f0e9ff822a65aa8bd4d98ea920dbeb9261e6e5f3939fVirustotal results 30.00% Heodo
2019-04-25FILE_60588807728US_Apr_26_2019.docdoc 67d05dd367015c892e3f0f50e5737a5138f00f626a134a85f1c2a6496132e691Virustotal results 31.67%
2019-04-25FILE_2719300717US_Apr_26_2019.docdoc 7218111a64d849c230b9d6d315953fd4eacad8211eaaf6f03c1fc25414fdb608Virustotal results 29.51% 
2019-04-25LLC_06588703532US_Apr_26_2019.docdoc df0fb247a70c89c6562901405d16cc4d36f5052d95ecedc5b9ed5185a0125f91Virustotal results 27.42% Heodo
2019-04-25LLC_1991645464US_Apr_25_2019.docdoc 23398b697fcbad05afffa161f6335010f558d4974e81bd7d32cc4f1e07b06e59Virustotal results 28.33% Heodo