URLhaus Database

You are currently viewing the URLhaus database entry for http://taltus.co.uk/ddkt-XkBNaaLqYLYqOHQ_LyLSihwC-NZo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:192414
URL: http://taltus.co.uk/ddkt-XkBNaaLqYLYqOHQ_LyLSihwC-NZo/
URL Status:Offline
Host: taltus.co.uk
Date added:2019-05-07 14:34:03 UTC
Last online:2019-05-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-07 14:36:05 UTC to abuse{at}bigwetfish[dot]co[dot]uk)
Takedown time:17 hours, 17 minutes Good (down since 2019-05-08 07:53:11 UTC)
Tags:emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-08PAYROLL_8869YEAGEWC.docdoc 1445c07e94df1aab9b8d29c8bdc0d2dacaf61c5af509c9fd4e77b252a4259f71n/a Heodo
2019-05-08PAY_80GQBOEI_05_07_19.docdoc f13b12b90d3f13577fb85c79d91b639adcfb07d1ac2216c74158f64a6e4659can/a 
2019-05-08PAYMENT_872079GDJSJALD_05_07_19.docdoc ce782d77e724997a02e7e03c49b96bc419eea745c44d47076e7c0bba8317bfa7Virustotal results 45.00% Heodo
2019-05-08PAYROLL_0097OADDIDN_05_07_19.docdoc a4c4dcf79d6b070599d3a813d8b542c8688a393b69f816012924b9f4d7f04059n/a Heodo
2019-05-08PAYROLL_19517POFHBCL.docdoc 41289082e20c3e62e9f052b546c976a55040189acbb92e08c27bf88ad815807bVirustotal results 43.33% Heodo
2019-05-08BIZ_91MIPOAHP_05_07_19.docdoc 945d2d135ae3508e486be34ea2bea9305c48a699ae6447462ee1f251e4fd3b15Virustotal results 26.23% Heodo
2019-05-08SWIFT_013983REYJRBYB_05_07_19.docdoc 6c74e8cd204af8dbbb5ceaf66e4a09d1b5d0ab931f0d10f8fa3e5d392505c355Virustotal results 40.98% Heodo
2019-05-07BIZ_06HQOOLGSJ.docdoc ebb1ef08bf0dacbff6724a7d5852c5c3553d30ea64399c5f8e5b9bc40b3e5207Virustotal results 35.48% 
2019-05-07BIZ_176459DUOPHZQE_05_07_19.docdoc 6359cfca4c3a4f6c657c285c6840af0bc66e00fcede8f7e2d3aa8e5bb96a24c4Virustotal results 34.43% Heodo
2019-05-07PAY_009ZUGXOFSW_05_07_19.docdoc 07a44560da37fb475f59d60fcb3da3094ef2754f807a5cf136cc3fa2cc8ebc00Virustotal results 32.26% Heodo
2019-05-07BIZ_3YMOIVMKH_05_07_19.docdoc fdabc899b0c2bc25cb3b6ec69d5fa312aa2522202c2db571919fd227df45b278Virustotal results 31.15% 
2019-05-07PAYROLL_8PLMNNTES.docdoc 7abd6dfea23905d558c92b1278fe6689b1c916bd37855afcd1a3544b30d1c072Virustotal results 23.33% Heodo
2019-05-07ACH_24271KFAKEGE.docdoc e92bfa4b3acf4c91be1bd1771a6befc7a39e64922f489936c9381add86ee7556Virustotal results 24.59% Heodo
2019-05-07BIZ_37117OETNEYWF.docdoc 60bb2ce43e570332c0be1d94bfa8515064915d9ae18ddad233b1388cc77e2e8cVirustotal results 25.42% Heodo
2019-05-07PAYROLL_191PXQPXN_05_07_19.docdoc dea431a8c3fe4a3f34f537e08d4beecb5caa79d55fe2356950a38dec23a70b6cVirustotal results 36.67% Heodo
2019-05-07PAYMENT_03875ELDXMKY_05_07_19.docdoc 4a5c99b2edb5cc45de476a297659e47de1e1ad4a6bf55be8d712eaffe6a26d6aVirustotal results 25.00% Heodo