URLhaus Database

You are currently viewing the URLhaus database entry for http://kuznetsov.ca/thumbs/yEY-BOIx-45/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:270246
URL: http://kuznetsov.ca/thumbs/yEY-BOIx-45/
URL Status:Offline
Host: kuznetsov.ca
Date added:2019-12-17 02:53:07 UTC
Last online:2020-07-08 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-17 02:54:03 UTC to abuse{at}apyl[dot]com)
Takedown time:6 months, 23 days, 23 hours, 43 minutes Bad (down since 2020-07-08 02:37:19 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-17Bonus Payment Notification U947155361.docdoc d05e1066ebc3cbd548b33814566736de37f1841a5f93d7f2b287a57cd049a33cVirustotal results 25.81% Heodo
2019-12-17Pay Payment Qd184.docdoc f02bbdeddbd63128dca626ebf310781748d96d3d662873bd212e89a37851f086Virustotal results 25.81% Heodo
2019-12-17Bonus Payment Notification W907581.docdoc 61238acfcc8bdd6c0bfdb44167021cd20457a4b50e10e0aa4eac11a9172dc59an/a Heodo
2019-12-17Bonus Payment Notification Zv7856.docdoc d559467faddfd252937be53ec6b8f8f182cbdebef502484860f4f7ca575f1282n/a Heodo
2019-12-17Bonus Payment 180375398.docdoc 98fa164dc5b7ff65c981a5d715f9a513de7b03d62e2fbd3be633c84170a4f657n/a Heodo
2019-12-17Bonus lK328.docdoc a0a0e9f2908955f2e6533d1c10a96868fa4992f37397a64071260f4726b602aaVirustotal results 30.65% Heodo
2019-12-17Pay ooE608149.docdoc b9b0c03120993dc7dbdcc3b67fd748265011d399453d8c916e051e0a58f61594n/a Heodo