URLhaus Database

You are currently viewing the URLhaus database entry for http://angthong.nfe.go.th/0yj9uy/public/elsjoi88tf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:274288
URL: http://angthong.nfe.go.th/0yj9uy/public/elsjoi88tf/
URL Status:Offline
Host: angthong.nfe.go.th
Date added:2019-12-20 15:05:06 UTC
Last online:2019-12-24 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-20 15:06:03 UTC to abuse{at}totisp[dot]net)
Takedown time:3 days, 19 hours, 44 minutes Bad (down since 2019-12-24 10:50:29 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-21EFJ_120119_VSE_122119.docdoc ad253e6647362deb3c0d03399e7f512ef78a155763d032eab642d24c4bcec1b8Virustotal results 50.82% Heodo
2019-12-21FILE_XOE_120119_LOD_122119.docdoc 0dfb5cda8b86af6c45b6bd4bc68f9e23f7b6723b29f905008f1da435bfb93bdaVirustotal results 49.18% Heodo
2019-12-2125889311.docdoc a44031feb2a71980a0980377c8f7b6f3b5b9dfa0f708556dd420be323c7e1a38Virustotal results 46.77% Heodo
2019-12-21ST_FQ6981657504RU.docdoc 08bab149c893a44f23ec39c10a85432c1180d99c868dfee6e7603a215f1c37e5Virustotal results 44.26% Heodo
2019-12-20SW_EW1061386623QE.docdoc e23bc5ee382cc5f5a5c5a62deca1d119ee4347bfd72aa40765a336f933d1f7f8Virustotal results 37.10% Heodo
2019-12-20REP_JUQ_120119_NDJ_122119.docdoc 085190935b08f49102610d5161e97892089f567965412b270f354cf088338edaVirustotal results 32.26% 
2019-12-20PAY_PO_12202019EX.docdoc ecbc0f7535c155d29b19aa8ce7a84f407c12211f523ca59c165cb9b5216e49dfVirustotal results 29.51% Heodo
2019-12-20PAY_7573374787738.docdoc 8c3f2d0b5b55dc7b3de092f33fbd964798ad9801328e4e9b3350014af6353436Virustotal results 29.51% 
2019-12-20REP_JR7692678360YX.docdoc 4a29df28aefd47fa261bdd7bee4ffdd88ff0788c3da9578a8439a969745d5231n/a 
2019-12-20SZN_120119_JRR_122019.docdoc 63391cf39177e85cd0ebcb031486946fcd768a6125b2086609298b12af35345bn/a Heodo
2019-12-20FILE_PO_12202019EX.docdoc cca96c0c2190712f91777aca07a89dab7d7853c40dea619c993e633e3f82dd92Virustotal results 27.87% Heodo
2019-12-20DOC_67241031042044.docdoc c19e4f9564e304e11d679ca37dc75ab35b3feb1f6e63df36add9dc12cc43e6ban/a Heodo