URLhaus Database

You are currently viewing the URLhaus database entry for https://www.vet.auth.gr/picture_library/public/b8n4gdghkqfg/xd2oi2m-9945991223-85412-gjd7w8ng-ta8987m/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:264589
URL: https://www.vet.auth.gr/picture_library/public/b8n4gdghkqfg/xd2oi2m-9945991223-85412-gjd7w8ng-ta8987m/
URL Status:Offline
Host: www.vet.auth.gr
Date added:2019-12-06 23:21:22 UTC
Last online:2019-12-20 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-06 23:22:05 UTC to abuse{at}auth[dot]gr)
Takedown time:13 days, 6 hours, 50 minutes Bad (down since 2019-12-20 06:12:07 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-09FILE_93318765.docdoc 05001d7c6641b97e4f87db3c273c72e321bacbdbd0f9941ad4960726fa9907bcVirustotal results 33.33% Heodo
2019-12-08AK_59314765687725176.docdoc 5b038e44f61912b780c4338a1aae9c8ce41aac394b8af62ba913daa5a9ca88b6Virustotal results 33.87% Heodo
2019-12-08FILE_05841596.docdoc ff17745ec6fd79d6a66b5b664f1868edb72dc4fa086b638fcbd83f32921b40d9Virustotal results 31.67% Heodo
2019-12-0818873261.docdoc f6739fbaf06d1bb449af76d6b81283eb0355c3d6684f415804881d04f2d1bc7cVirustotal results 29.51% 
2019-12-08REP_42933330.docdoc 2bbd00082d724392a6f4091948c9c9982818fa7bf02cd907a35e775c95d4a0bbVirustotal results 29.03% 
2019-12-08FILE_81677588.docdoc f67ce938734c8848d60937e247438f8ec445dd3f8e6ebfa07f83af49cd7da3c3Virustotal results 29.03% Heodo
2019-12-08EM4467357543CN.docdoc 6d7d193fcc9e64d582aae6cfd51f320c5cef760e2fad1f63f89291a0dc67d114Virustotal results 29.03% 
2019-12-07REP_99222546.docdoc 5ae58cec2d2ae0c61b426693c357c4dd2b600604d7c0bf867a4670d1944228cfVirustotal results 38.71% Heodo
2019-12-07FILE_LO5012786716FU.docdoc 9c00f19fb5fb61e7b8d62a32d388e03d88938cf911a43775e24e35934568eb9cVirustotal results 37.70% Heodo
2019-12-078800456562947.docdoc 10b9527cf19e1071ac16ea0ca10035ac7dd4f7d0d1f8ce7b36ca3ff6c98f15acVirustotal results 32.26% Heodo
2019-12-07REP_FETMUZ79G.docdoc 94a6cb719bd6134f57849a452d1e28ad78db9a7948e8aec567c718ef23eba54fVirustotal results 29.51% Heodo
2019-12-07OKJ_XJ7970223871LZ.docdoc f4417c384a9c9134cbc662b5eb478ac16a88b041766147361ea81ef5242690beVirustotal results 48.33% Heodo
2019-12-07658305897799653196.docdoc b6e74ae32c11bbd45866d7c71199c23a18ab8dd8f98b0fabc5b9d6e486655646Virustotal results 30.51% Heodo
2019-12-07TBVDW8Z74GL.docdoc dd79153bba59f7a7ffb1d13cd5b76865f4caaf258bf9fcbcca61a89170d604ebVirustotal results 39.34% Heodo
2019-12-07DOC_PO_ 12072019EX.docdoc 74a78804c1bea52811c665adf43991c28fda72808c936c2413fe9367c3efad81Virustotal results 32.26% Heodo
2019-12-07XFNPVBPDJF242K0.docdoc c447f9c1ea3cbef1568b96301f4a5044875f5d913586bfbdb5dafa5b486b3be0Virustotal results 30.00% Heodo
2019-12-07FILE_87820069.docdoc fa56f216fdbbbf64362304dd5605c24f5a40d3a1058de64d032536dff4efc195Virustotal results 30.00% 
2019-12-06J_606607283461676756863858.docdoc 6d26085c1aeb099db26abc5d5c12dfabea0d708ef8c283d29fe8683049d250e1Virustotal results 29.51% Heodo