URLhaus Database

You are currently viewing the URLhaus database entry for http://nxtgreen.co.in/cgi-bin/dd8i5tlwzxg88z_it4287fb-83343559963074/// which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:190399
URL: http://nxtgreen.co.in/cgi-bin/dd8i5tlwzxg88z_it4287fb-83343559963074///
URL Status:Offline
Host: nxtgreen.co.in
Date added:2019-05-03 16:56:03 UTC
Last online:2019-05-06 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-05-03 16:58:03 UTC to abuse{at}hetzner[dot]de)
Takedown time:2 days, 13 hours, 53 minutes Poor (down since 2019-05-06 06:51:18 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-04FILE_4388906819US_May_04_2019.docdoc 9547c3f40f790fab370c5620245c7736282c4931b82100c519746d8f3b072bd8Virustotal results 33.33% Heodo
2019-05-04DOC_352130609484US_May_04_2019.docdoc cf3d4fc7080d12f23a1a7718b0fdbcb958eef9121a01f094080652c4c5af354cn/a Heodo
2019-05-04FILE_8198279007US_May_04_2019.docdoc b5943cddfd81d8e13ebc274ab01b43b892335e54df790fbf375dec25d70437a5Virustotal results 35.48% 
2019-05-04FILE_877747001676US_May_04_2019.docdoc 3b7b28b3da34f41ddbd1a6ccfe94bb0726c1d50bb42ca83b48db7fb0ca542ce8n/a Heodo
2019-05-04SCAN_257178778297US_May_04_2019.docdoc 57a5bbcdb5c82c0ec00aa7171455f15b71140821c09c757cc99cce411dbd3cffVirustotal results 32.79% Heodo
2019-05-04LLC_96918505339US_May_04_2019.docdoc e35c59d2dc2d98f655064a3efc2e7a994e4efe4628f60a06e84fc079d8c2fe91Virustotal results 35.00% Heodo
2019-05-04FILE_959861012021US_May_04_2019.docdoc 321e1dfdb20d4f1a378472a4b3055a9c98804173e5e0c362039c3a118ab8e24bVirustotal results 32.79% Heodo
2019-05-04Document_2571405592US_May_04_2019.docdoc f29605f7da73e128b8c8a3b3c984b6d2fad00a690d29fe40e88712fa1cd4c943Virustotal results 30.00% Heodo
2019-05-04DOC_81313874712US_May_04_2019.docdoc e0de872319d3b08cb7322884af7dac8f10632fec564862c9c6364ff2c01a07bdn/a Heodo
2019-05-04FILE_185926295478US_May_04_2019.docdoc 953c247099818d7f8eb6e694a8b4513d61329b90afc651d75664df86837ca012Virustotal results 33.90% Heodo
2019-05-03INC_1540000232US_May_04_2019.docdoc d94ff5aadd33871bf10b2316e3d14e19520506724771f95749210248b7931effVirustotal results 32.08% 
2019-05-03Document_81906854703US_May_04_2019.docdoc ce0dd149d783089c8567d59c766017c31a84863a4bed4db476786851cf827943Virustotal results 33.33% Heodo
2019-05-03Document_1304461491US_May_04_2019.docdoc 0282a70dabec4f4b6cc1f477cab7a97e23558677a0b6d8bb55f329b9719deb5en/a Heodo
2019-05-03LLC_28431871159US_May_04_2019.docdoc eeec0046cd334722d51b9db31e8c18d1d6ace4246c790bbbc311d553c2f3ddd4Virustotal results 33.90%Heodo
2019-05-03LLC_9768909813US_May_03_2019.docdoc 9f00e70566d4c513207f676149a70437674345f52f057b83af8553fb8b7ece4aVirustotal results 26.67% Heodo
2019-05-03LLC_18143515184US_May_03_2019.docdoc 0731dac1d684fd9c6150d9d0c20e52073cdf8b9a8a2afbe06578f553c315bc86n/a Heodo
2019-05-03DOC_232924862732US_May_03_2019.docdoc 89f70f1ea8bb56015eb8427c1900918320be4468fdd858cd59c410ff5f6fc1f2Virustotal results 28.33% Heodo
2019-05-03LLC_72923322530US_May_03_2019.docdoc 96973059c987c115d57614d9f730f3acf54956b3c502610929bca5221e635134Virustotal results 28.81% 
2019-05-03FILE_03976634596US_May_03_2019.docdoc eae344e3a366bf381768a4bbcb9eed3e7165de9a509d7e6d77c4ff95cd1ddb85n/a Heodo
2019-05-03INC_426829111325US_May_03_2019.docdoc bd9b6ce1cae013cad0255aad9eff9d868cd16397eec708612695ffdf9fd4f277Virustotal results 28.33% Heodo
2019-05-03SCAN_44254010414US_May_03_2019.docdoc f3b7ffe06885209783ca9db28c2256d194dc5cc09b6eb0d5a40bdfc43bfbe3e5Virustotal results 27.12% Heodo