URLhaus Database

You are currently viewing the URLhaus database entry for http://a-tech.ac.th/2016/TYOP/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:287517
URL: http://a-tech.ac.th/2016/TYOP/
URL Status:Offline
Host: a-tech.ac.th
Date added:2020-01-13 23:16:12 UTC
Last online:2020-01-27 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-13 23:18:03 UTC to noc{at}cat[dot]net[dot]th)
Takedown time:13 days, 12 hours, 4 minutes Bad (down since 2020-01-27 11:22:03 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-15Inv_I478_24.docdoc b0df47bfe2792f1966190215f153e275c76a9347a7e9a5ae079c232d0548eaaaVirustotal results 42.62% 
2020-01-15Invoice-O013_4524.docdoc 0f0f2f15c319d7abd2bf1f48a46a0cfcb8f4b08e03340187d2a119f1c64576abVirustotal results 36.07% Heodo
2020-01-15Invoice_TSL742_96979.docdoc 7a1bb65a845c067f7a327d08097b85e17646c11d6f7b226176e89d16474d54b4Virustotal results 36.07% Heodo
2020-01-15INVOICE_UE88_737.docdoc ced74a717f09aa4ee30f883e7140c28a91a1911384510acf14127ecd77ae577cVirustotal results 35.48% Heodo
2020-01-15Invoice UQ580_53.docdoc 387b842a9903f350b0aec6eedf20fa0547a981cbf44f98732b4df63992a1558fVirustotal results 27.42% Heodo
2020-01-15Inv-TMO616_64257.docdoc cbd62f353e9ef09180c0a35dbf894ad121dd1a51931f58b158b328d65c292e2aVirustotal results 26.23% Heodo
2020-01-15INVOICE-RO926_4313.docdoc 6ef5232af84b7434c26bf2a0288fb6ff5121a2a331bcfe7b9c95e1236025ecfcVirustotal results 24.19% Heodo
2020-01-15Invoice-L890_75061.docdoc ff25de613a694810c4fbe525825171ac6e62d0485038503e971f87fbdd2049e3n/a Heodo
2020-01-15invoice-A964_33.docdoc b7d6a9d883ceb3098ae6e82cb15a930133fd838486587f4f1fee1145cfc87b3eVirustotal results 22.95% 
2020-01-15INVOICE-KO198_007.docdoc b0fe1c13c4769acdbb0ca4f5e4811be6e1c74664f6b09081af35c1be907f9424Virustotal results 18.03% Heodo
2020-01-15Inv_H155_91129.docdoc 0be95290124a09aa4fb39e3c9069ee6c8078349d8fedc5694c2bf8e6291b4839n/a Heodo
2020-01-15invoice TQB644_8415.docdoc 90c1afaa5b3ec11b45a05c31ae4bcae3f687b28bf8620503dd175905dd945c02Virustotal results 18.64% 
2020-01-14invoice KNI27_203.docdoc c912fbd5e3979ce3299c6cab4db775c4d86fcd1c779d4c2b402931f558484d99Virustotal results 16.67% Heodo
2020-01-14INVOICE-ESU22_49.docdoc 9b812d6f768e7de4be8e12a32a010e64596ea5c583a830f8ef344e00df6e1d20Virustotal results 17.74% Heodo
2020-01-14Invoice-GK23_43570.docdoc 5d9da74a6dc0774b2b16363d6b66d0096cfac919d1ff46d45a4a1e374bd19234Virustotal results 18.03% Heodo
2020-01-14Inv C83_37112.docdoc 31dd37db91178b7322fb636945b684261911cf6efb80da7abe31315f8f5980afVirustotal results 16.39% Heodo
2020-01-14Inv_X09_59629.docdoc 88d703fe59f728817d930aefece5014cd75324b02568f6d2a9f69efae7915871n/a Heodo
2020-01-14Invoice NXA381_91.docdoc e1715c9535e08f080219e8b45c63a15623241299900b44a82bc44446b9c912abn/a Heodo
2020-01-14Inv_UVA830_46.docdoc 0a1e8f7bbb45314ed303115d58763e0c7c2462257edad8748e7cb51fbdff890cVirustotal results 13.11% Heodo
2020-01-14INVOICE P162_275.docdoc c9e03d9b15a357f412a9ea5302fa6183e4f06d8ace5d5b43dd1cb67d11e0146dVirustotal results 13.11% Heodo
2020-01-14INVOICE-IL718_57625.docdoc 4ea787c535cc1b104a564ce9f2d486ab607566bc93f9eec342a6df99cceafe18Virustotal results 16.39% Heodo
2020-01-14INVOICE_GS871_67537.docdoc bff484c3a259993eded74499820830eb2da53828fcc763b8f600261572c42b98n/a Heodo
2020-01-14Invoice-E727_71238.docdoc 1d56a829a8b53c984eda84373182767912fbf9d5211e5c1cbd839b753410172bn/a Heodo
2020-01-14invoice U86_6321.docdoc 34808b889d159c685324dfa60012edfd13eba370971ce74e0e9242fe3c170ebfVirustotal results 17.74% Heodo
2020-01-14INVOICE L54_4061.docdoc 61ef44b898c732da0b07cc34493e971778b8835edd28386161473dd228025581Virustotal results 18.33% Heodo
2020-01-14Inv PJ43_952.docdoc a23d9b67a7511a6e6aac0ab8c5e30422cc1c25e8c1f66f6427f47cb812057f44Virustotal results 16.67% Heodo
2020-01-14Invoice_I64_58.docdoc fae7e292b443e97b48949f711e94e1ee3c23e5e01cdcb3d890bb6c20d459d756Virustotal results 38.71% Heodo
2020-01-14INVOICE-X064_88.docdoc b39987017e022d0ba9deb280486992ee0ee0338e50e564915d25a97a777af0faVirustotal results 37.70% 
2020-01-14invoice-IL12_25.docdoc 6384027a4dbfc0dcd5712a79436c9ad2cec5de14f6986091c07ce25b32e3d802Virustotal results 30.65% Heodo
2020-01-14Inv LFV97_94843.docdoc bbec91babc2513939b05530c6c50549b7d096c7bbd57e557b07d145f9d2c66e8Virustotal results 26.23% 
2020-01-14invoice-ETG53_333.docdoc 18b7a070ad16b8cfff48c011226af98c8df66202cf67b83d9229cad680bd053eVirustotal results 25.81% Heodo
2020-01-13invoice-URA781_3532.docdoc b096f29afe1925988127c55e6888cd8ef0c2a0f035841e7297e82ba223d66663n/a 
2020-01-13invoice-GSL466_379.docdoc 6b8f8f775aeb070e6297c8c186c98f9c1039fdb4e3911788412238821f8b30b9Virustotal results 39.34%