URLhaus Database

You are currently viewing the URLhaus database entry for http://angthong.nfe.go.th/am/OCT/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:288523
URL: http://angthong.nfe.go.th/am/OCT/
URL Status:Offline
Host: angthong.nfe.go.th
Date added:2020-01-14 21:12:06 UTC
Last online:2020-01-17 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-14 21:14:03 UTC to abuse{at}totisp[dot]net)
Takedown time:3 days, 2 hours, 13 minutes Bad (down since 2020-01-17 23:27:50 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-16PO_01172020EX.docdoc db503068ddad27ff7e4724f9fc014c6ba49c7c8b1cf9405c239a48ff3150a0e4Virustotal results 38.33% Heodo
2020-01-16F_PO_01162020EX.docdoc 8376cc70e145d65b615f0bebb25306f97cbaa6d1858d5db9e40a7623b2c3fb68Virustotal results 36.67% Heodo
2020-01-16317957179240.docdoc e314c8b472db81404961016b49758c54595600e83fa2801d5cba0089cb8b2223Virustotal results 32.79% Heodo
2020-01-16IG7423219484JX.docdoc e0912e965ebf6a2bfc61b0b6a27655d238a66992db93587518fe2295cfa422e0Virustotal results 29.51% Heodo
2020-01-16REP_FHI_010120_GYM_011620.docdoc fd2d1b1001a52d28c40d06dd25d9adcabc14519667f22eb0397886939046b2bfVirustotal results 28.33% Heodo
2020-01-16ST_BUS_010120_BIB_011620.docdoc dee80fcc93fdf28fb6d796015785e587e2fbc779c948f6ebc6f3a5628d54f905Virustotal results 26.23% Heodo
2020-01-16BAL_PO_01162020EX.docdoc 95c0c04d9077e6700cdae6bd1f365a488cacb9ad029a7db67bcc29e9992331e7Virustotal results 26.23% Heodo
2020-01-16RP_UR5729484471QL.docdoc 743632f16eaf4dffd8109a5ea7c14e341db9af20a96f44838a046b9c6b183fdcVirustotal results 25.86% Heodo
2020-01-16BAL_MIR_010120_YTH_011620.docdoc 8f7528de459c08404bb34b2b574940ad939445c0f2c6c701f5f220e4de5d7cd9Virustotal results 25.42% Heodo
2020-01-16MEE_010120_BVF_011620.docdoc 149889ce5c8bb26fa5e97f596ef4a8b87614e01998f4bb57fb25c82ddd84453aVirustotal results 24.19% 
2020-01-16REP_ESS_010120_JVW_011620.docdoc a7d3f5474bdca4af088225b9280da969e8678960b6768ab6944a72866252c9dcVirustotal results 25.42% Heodo
2020-01-16PAY_LIA_010120_BID_011620.docdoc 8cf507a5d6fd40526c9419ace90c17b9d91a6949229cd0f5c8afa750836dcf62Virustotal results 24.14% Heodo
2020-01-16REP_51729383.docdoc e3f09ad051f018464518e09321d7cb7e4005a37c36fe89affc31d9615396d80cVirustotal results 45.76% Heodo
2020-01-16INV_10564656.docdoc bbc7c13dbd64502c59d3890785c0a821310d29c04a915a23e62c31ed0756aea9Virustotal results 42.62% Heodo
2020-01-16IQ5846034982NJ.docdoc 95b02c0e112270751b5fe7a49866ed9d31594f0b8d26e823e2242bcc3b902b26Virustotal results 42.86% Heodo
2020-01-16RP_3ZKQV75.docdoc 70ee982c6329ff7d11fa89375a100f4d2845d56be48ae8e61afe703324fd9950Virustotal results 40.32% 
2020-01-16FILE_9238713633820494.docdoc 01d706d0a5e27c62abe9a72200925c5e23ed3c309ea88354dfcb55b36437c3eaVirustotal results 40.98% Heodo
2020-01-15PO_01162020EX.docdoc 8a8e9cf03bf716afc717c9f37e86050a9d95c576836b48423d8c1b495831a54aVirustotal results 40.00% 
2020-01-15SW_69237641.docdoc 3b91b18b63fda2d06afc7d6f8bb924da52b9cedb373615783fbe7ab73477ba15Virustotal results 35.00% Heodo
2020-01-15XS1OBF17KGS1DC.docdoc 5cef7f012587358911420986b0a10b3afc376e71cbcb62ae2369409a2949e714Virustotal results 34.43% Heodo
2020-01-15REP_40747576393723253.docdoc 60d2c8f3e62e237ab3c9d9f1e822485b7cb0751b9c389cb2230222adfd189a97Virustotal results 32.79% Heodo
2020-01-15PO_01152020EX.docdoc d497afabc9f95e52de2b44e62a03de53764ad772a44b5435500de43e92434a9fVirustotal results 32.20% Heodo
2020-01-15DOC_SWJ_010120_CHS_011520.docdoc e4fa19c4736ffb554aacdb6de08c4ad081fd55105dddc85b31eac5c6082e601bVirustotal results 18.33% 
2020-01-15FILE_TXC_010120_HCX_011520.docdoc d3edd09e8e4e9e89dbff176e69131f189175abf1a598c18593a3bb194fc45c2eVirustotal results 37.10% Heodo
2020-01-15D_PO_01152020EX.docdoc 632e28a523c920e3035782ad086e6d3f0e39445486e86e7ce6a05c0e4f337292Virustotal results 31.03% Heodo
2020-01-15FILE_WLF_010120_NGU_011520.docdoc 53316d2f235578afb76c4e839aa953af8e9dfb9e6b17307c324a88e42d7e47f2Virustotal results 32.26% Heodo
2020-01-15SW_ZTHUU094KDPEAMMU.docdoc 958b22bd337775f2226fecdcadf9125b8bbcad2518c23d026fd87b0714af1b63Virustotal results 31.67% 
2020-01-15SW_48069808441153054050877.docdoc 64a7bbb5697dab97fb723824a2f3456c67f88435cb51e3be9f99b0b9c6652186n/a Heodo
2020-01-14DOC_SZI_010120_OGC_011520.docdoc bbf79cb4aa35f097ee65fbf27c2808626e53c4460eeec58c2a828aa669b50b74Virustotal results 26.23% Heodo
2020-01-14BAL_AWE_010120_NIR_011520.docdoc 0e6520210e46488b128dd410b19f06776ef72006a9039fd887e7e07fd289ee0an/a Heodo