URLhaus Database

You are currently viewing the URLhaus database entry for http://bakstech.com/7lqgpidi/Document/p8pgq-798-5574252-5udel-lsabwhe2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:288449
URL: http://bakstech.com/7lqgpidi/Document/p8pgq-798-5574252-5udel-lsabwhe2/
URL Status:Offline
Host: bakstech.com
Date added:2020-01-14 19:08:10 UTC
Threat:Malware download Malware download
Google Safe Browsing:Listed (Phishing)
Spamhaus DBL :Not listed
SURBL :Not listed
Quad9 :Not blocked
AdGuard :Not blocked
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-14 19:10:03 UTC to support{at}sddatacenter[dot]com)
Takedown time:16 hours, 17 minutes Good (down since 2020-01-15 11:27:34 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2020-01-15SW_XNQ_010120_CMN_011520.docdoc 9982b18660c6aa9b8419bd84843d2d578fd2afb2516782ac69f0e7f8eee4efb9Virustotal results 18.33%
2020-01-15ZPV_010120_OYO_011520.docdoc 5ce93c3671dfbeae75d738d2ffd0204b72b6628c8aea98ccda37891eb1414614Virustotal results 18.03%Heodo
2020-01-15INV_PO_01152020EX.docdoc d3edd09e8e4e9e89dbff176e69131f189175abf1a598c18593a3bb194fc45c2eVirustotal results 37.10%Heodo
2020-01-15BAL_PO_01152020EX.docdoc 632e28a523c920e3035782ad086e6d3f0e39445486e86e7ce6a05c0e4f337292Virustotal results 31.03%Heodo
2020-01-15INV_WN7918455429YD.docdoc 53316d2f235578afb76c4e839aa953af8e9dfb9e6b17307c324a88e42d7e47f2Virustotal results 32.26%Heodo
2020-01-15INV_PVL_010120_FGE_011520.docdoc 0edf4c05fd5e483a3ca303151f3f58c87155ae9f1cec75be9ffd0aaad884f4f9Virustotal results 29.51%Heodo
2020-01-15INV_NIF_010120_XLG_011520.docdoc 556f0f62580588094bb0d595bdbb880b58a48148af61569258c9a84653374cbbVirustotal results 30.65%Heodo
2020-01-14REP_WL4787300622GU.docdoc bbf79cb4aa35f097ee65fbf27c2808626e53c4460eeec58c2a828aa669b50b74Virustotal results 26.23%Heodo
2020-01-14VK6970304409XZ.docdoc 6ea68ce4d24f0f499b02dc10acfa5ba8a428ce1eef46e6423899ce4be5f31b4cVirustotal results 20.34%Heodo
2020-01-14BAL_3114845628414729328738653.docdoc e3cd5ab045097c55bcb00a1cdc84e11c8d7214e15f536baffd899dfb8e0a3149Virustotal results 17.74%Heodo
2020-01-14PAY_6253913558753699898.docdoc 81fff20e3431a41d91edd69ea442064e356603ff5f72df3fae2aaa81d9f514f3Virustotal results 17.74%Heodo