URLhaus Database

You are currently viewing the URLhaus database entry for http://angthong.nfe.go.th/753976906install/ew0-541-30606/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:271662
URL: http://angthong.nfe.go.th/753976906install/ew0-541-30606/
URL Status:Offline
Host: angthong.nfe.go.th
Date added:2019-12-18 13:31:08 UTC
Last online:2019-12-24 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-18 13:32:03 UTC to abuse{at}totisp[dot]net)
Takedown time:5 days, 13 hours, 21 minutes Bad (down since 2019-12-24 02:53:56 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-20INVOICE VO881_62284.docdoc db8e444c711cef67b19c3c153ae825882c400ee7e7fc1c3aed6412d701e62bb3Virustotal results 29.03% Heodo
2019-12-20invoice_X196_23689.docdoc b554687e67437c34ba161bf732d8c04112d581e589a111f9a45772172f3e4f1dVirustotal results 28.07% 
2019-12-20Inv YLR290_80931.docdoc bf01172cddf77c0603bacf6e680d1cab2079dc3286de51c482be408c20c236a8Virustotal results 23.33% 
2019-12-20INVOICE GOJ750_0910.docdoc f4bbbc4da5a28f015bb779c44f4387bbd0f6fd0b67104e4e3c043fc9d1de03a7Virustotal results 22.58% 
2019-12-20INVOICE-OC11_44.docdoc 851b896a27a840ed2aefd9b109e320f08fe2077f47fe545aa9f6894cee342bd8Virustotal results 22.95% 
2019-12-20Invoice-NHD840_316.docdoc 8e6e1845b87676c69b6f2b41ae820b16ed738fcc5bc8f19db5f1e5c004c31862Virustotal results 24.59% 
2019-12-20invoice IJ81_91.docdoc e8f4adbc33575dfdc6cc8046ec0478baee34237bda285c3e9fd4798aea4ea516Virustotal results 37.10% 
2019-12-19INVOICE-TUI29_19520.docdoc 18d783c0e60c476cf900850e6a3e4402ff66e1665d70e3969111daf23e83d103Virustotal results 35.48% Heodo
2019-12-19Inv_L676_9754.docdoc 4a27ff712c8357a71de39f7145a2d7d507c4307740f4926edbcf3dc5c04da625Virustotal results 29.51% 
2019-12-19INVOICE S59_5566.docdoc 87be47eb44b548bcf19b0d1b0d66666f3ae61b8a6f728ed9c5cd38a28d2096d1Virustotal results 29.51% Heodo
2019-12-19INVOICE EKX17_83818.docdoc c81fa6a0d384474c75454f40007dee1c7c00275f1e049246ba3025a46be69bcaVirustotal results 29.03% Heodo
2019-12-19Invoice-SO13_159.docdoc cab696d2c8bb5158dab72ca062d69416c2d2e91231bbf09cdb49eadcf557c98bVirustotal results 31.15% 
2019-12-19Inv-QI784_384.docdoc d3a47fd928e039e74aa4b0679efcdd9bec08262a9376ce1250d046d1002f057dVirustotal results 31.67% Heodo
2019-12-19Inv_VTG896_54423.docdoc 85b1d02279a15d8613bee732ef60c217f623f8447308e61e9cc713f5d65bfa44Virustotal results 32.20% 
2019-12-19Inv-F31_09584.docdoc 0208cb1d62bb0797e256c4c55b25e87e50b767223749649ee46edac6c67d9b54Virustotal results 24.59% 
2019-12-19Inv_SZ25_51171.docdoc f5243c73d53726bb52ebb46b99fb728fefd35ff8f34e8047624b78ecfd15d91dVirustotal results 22.58% Heodo
2019-12-19invoice FQL85_63.docdoc 50502b1309e5510dc666c2dd81f978bacd097de74ad3839f00cf37bd162c193aVirustotal results 27.42% Heodo
2019-12-19invoice DML46_40738.docdoc 74eefd0de4d3fbf6ab471fcade6b5883135744fc85f876bdc446f9262fe16e2aVirustotal results 24.59% Heodo
2019-12-19Inv_XBN03_871.docdoc 4794705e3b14bb04104db0a8f1970880570d2a68f86f73f1348161fe35999468Virustotal results 22.58% 
2019-12-19Inv-CKB759_48048.docdoc d56126c1a995b08b9a058de9101b8017fbcba9450ff193263a59aeb19b52c190Virustotal results 22.58% 
2019-12-19invoice VQ09_70425.docdoc afa118fb028f99925a4dfcdb486daea725e1a1143c16905ca1133478d6b82cc7Virustotal results 22.58% Heodo
2019-12-19Invoice_L74_262.docdoc 826145f8cd7d41889db4b1423dabac9725d7b7f665aac33dce2b1252cf1e6b43Virustotal results 27.42% 
2019-12-19invoice_RQ72_14558.docdoc 25a29c462340890313dcd127d3831fdfb15f53c202ae7e9994994f75e9f0c13aVirustotal results 27.87% Heodo
2019-12-19INVOICE_OHI389_1835.docdoc e5f1a582de4635159d5f72058d57f15f832ea11f8def148197b632790bb22ec2Virustotal results 27.87% 
2019-12-19Invoice B739_59475.docdoc 1316399f83cd2feb390a8416d544825ecebcdb410cdcc9bac129e86a541c300bVirustotal results 26.67% 
2019-12-19Invoice-JJL66_25.docdoc efc63c54fcad9a31e5861a998a765a7f9e67a409fbd30309c6bc39d370c2ff87Virustotal results 22.58% 
2019-12-19invoice BS992_07.docdoc 3b1c9207eeebd276ffe9e27a7e40dbba142970a416aa5adcd4b6655cb5eeeeabVirustotal results 26.67% Heodo
2019-12-18invoice-W437_15.docdoc 641829a4ca6829e1f8d92e69d5b81ac91fa99655e4667aab0476ec546f83b2e1Virustotal results 26.23% Heodo
2019-12-18INVOICE-BMB623_276.docdoc 3296ebb9128f8e0f94ac37f3ecf45fe5e51aeb840602030db4ef35c257326e1fVirustotal results 26.23% Heodo
2019-12-18Invoice G419_623.docdoc e6f94030c55e6b0efd8f98cd9e3127ff431b89b6f8211560edfbcb49f1924364Virustotal results 25.00% Heodo
2019-12-18Inv_D674_330.docdoc db1afb0cb6d67e9f10fee9d59aa1e9fdf67960b6aedd49454bf31accf524ea8eVirustotal results 26.23% Heodo
2019-12-18INVOICE F370_80194.docdoc 6d78d247c25603598357c7c652a7ef77f8ab908fd1c3536dac5dd0756c260bafVirustotal results 22.03% Heodo
2019-12-18invoice-BB972_944.docdoc 099d9114cf9b28c2283d5da4550cec51027a271f0773a2af0f45e9249ee2da81Virustotal results 26.67% Heodo
2019-12-18INVOICE OS979_253.docdoc e79f6c7e4e78af1d8bdf1c9588101d86ce41d820176c1fd9b587913fc7e64f26Virustotal results 25.81% Heodo
2019-12-18Invoice_DXM00_43.docdoc d22c8e86b7d5db3a413c4879c66e490f4914ea9a1733a3a6f5dcd23d664121e8Virustotal results 25.81% Heodo