URLhaus Database

You are currently viewing the URLhaus database entry for http://rgitabit.in/newsletter-pdb3VTGfl/public/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:288611
URL: http://rgitabit.in/newsletter-pdb3VTGfl/public/
URL Status:Offline
Host: rgitabit.in
Date added:2020-01-14 23:13:05 UTC
Last online:2020-01-28 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002245646 created on 2020-01-14 23:14:06 UTC)
Takedown time:13 days, 21 hours, 18 minutes Bad (down since 2020-01-28 20:32:56 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17FILE_86970884.docdoc ab1d14d16f3b1aff666897ac06850603a97d469b3ff8da6c29575ec7458a7e84Virustotal results 37.10% 
2020-01-16PAY_HGA_010120_JLW_011720.docdoc ec7daa97138174c5878ea751f64fc280edd5c475f1ad353be67afe6c74b2e857Virustotal results 37.10% Heodo
2020-01-16VFD_010120_RBY_011720.docdoc 8aa03e0069da2642cdf2b5951f6fc50e9bbdacd01a38e0e6c8d636a1afd522c7Virustotal results 38.33% Heodo
2020-01-1635324059254.docdoc d13b7bb583d3175a5a66a45e56f859a8ad4f514b8461da2c589fd74c69bc4b3eVirustotal results 35.00% Heodo
2020-01-16PO_01162020EX.docdoc bf08f22796d9bd2305d29ef668a5b81ee6ef9d07b49827d05b88f97c74a4b249Virustotal results 32.26% Heodo
2020-01-16INV_PO_01162020EX.docdoc 67e4ad463f707098e9dd3aa9ef44543687de41237cb6bd15500e428aa17c34c7Virustotal results 31.15% Heodo
2020-01-16PAY_YHQ_010120_PMJ_011620.docdoc d2ce1838da599f490397183272a746696999155f408cdd5da5d82c3ae1df24faVirustotal results 29.51% Heodo
2020-01-16A_AZC_010120_PTT_011620.docdoc fd2d1b1001a52d28c40d06dd25d9adcabc14519667f22eb0397886939046b2bfVirustotal results 28.33% Heodo
2020-01-16I_PO_01162020EX.docdoc dc84907bac7d3d44f584659178821e29b5e8af4436b4b1c74792d338a761437dVirustotal results 26.23% 
2020-01-16EZKD_THCR8QCUI.docdoc 95c0c04d9077e6700cdae6bd1f365a488cacb9ad029a7db67bcc29e9992331e7Virustotal results 26.23% Heodo
2020-01-16BGCG_YJQ_010120_LYS_011620.docdoc d8e78e236ed8030ea028ee13a3b779ce7f998a8c15e25e6e441b01544dec5666Virustotal results 25.81% 
2020-01-16V_LF9QZGRY147QAU37.docdoc 8f7528de459c08404bb34b2b574940ad939445c0f2c6c701f5f220e4de5d7cd9Virustotal results 25.42% Heodo
2020-01-16ST_3AMG3700FCIDL347.docdoc 21222de7dc129cc2ceb960d884aab5660f053b0186d85f48f302257ae6075bd5Virustotal results 25.00% Heodo
2020-01-16RP_06075247.docdoc a7d3f5474bdca4af088225b9280da969e8678960b6768ab6944a72866252c9dcVirustotal results 25.42% Heodo
2020-01-16L_YMI_010120_WNJ_011620.docdoc 791dc93ca83900c29d93fc3641d199b853413a23d3899b119ed619f9223cb20dVirustotal results 22.95% Heodo
2020-01-16PAY_PO_01162020EX.docdoc 771ad3b2889d51eae42be0c3c53f7ab24667105d94fcd6e6dc93bca8ebbfcd85Virustotal results 44.26% Heodo
2020-01-16JW_AT1486296009ZB.docdoc fc68dd9971f85e873151fa2dae765c3406a74e35a608879a7b46cc250986b63dVirustotal results 43.33% 
2020-01-16INV_CO0956620725DJ.docdoc 95b02c0e112270751b5fe7a49866ed9d31594f0b8d26e823e2242bcc3b902b26Virustotal results 42.86% Heodo
2020-01-16C_3951196889497882471541.docdoc 13aa89755abbea10d5958e7b1d6d8440f1b6cb0d866e6ae70de9a7513e80e409Virustotal results 40.98% Heodo
2020-01-16INV_XKZ_010120_GCT_011620.docdoc 01d706d0a5e27c62abe9a72200925c5e23ed3c309ea88354dfcb55b36437c3eaVirustotal results 40.98% Heodo
2020-01-15ST_XI0845778702YO.docdoc 8a8e9cf03bf716afc717c9f37e86050a9d95c576836b48423d8c1b495831a54aVirustotal results 40.00% 
2020-01-15RP_APA_010120_RVH_011620.docdoc 3b91b18b63fda2d06afc7d6f8bb924da52b9cedb373615783fbe7ab73477ba15Virustotal results 35.00% Heodo
2020-01-1561910144.docdoc 5cef7f012587358911420986b0a10b3afc376e71cbcb62ae2369409a2949e714Virustotal results 34.43% Heodo
2020-01-15FILE_JF8017827295HL.docdoc 60d2c8f3e62e237ab3c9d9f1e822485b7cb0751b9c389cb2230222adfd189a97Virustotal results 32.79% Heodo
2020-01-1501043812.docdoc 3bd995e4229e3d5adb81c3572c5278e730524b0774cc7a8c4ea710bc4be1ae33Virustotal results 32.20% Heodo
2020-01-15ST_03694701.docdoc 2004c6f1abd300fa135b56f65c133ebad43e42aafae2b9b9726e3dd274424ea0Virustotal results 32.79% Heodo
2020-01-15FILE_HO4B8MEV9QW9ZKB.docdoc 1ed83f7ed0265fbb7fa1006f405773d31c4b7069ebfbbb6086f0196160f3d143n/a Heodo
2020-01-15RP_9090878139950.docdoc d402892bded1fe7f48f7fffef9c87ada82d08ef2c2ea534d8b28ccd94d08e2c5Virustotal results 25.00% Heodo
2020-01-15DOC_1572507769093.docdoc 04f04f3107a199ae3c5a4ffb960173fc3be31f5c86183d0cb27a23c927d6af45n/a Heodo
2020-01-15ST_91015021.docdoc 2d5822aff83315cc778085dcd69fd73f82a4cfe94592529b93dacb256fb97713Virustotal results 21.67% 
2020-01-15SW_PO_01152020EX.docdoc 0e0a399c81d33e87b7aab322fbf562d8c4aae27cc067a553ee092f13bc71221dVirustotal results 24.19% Heodo
2020-01-15INV_PO_01152020EX.docdoc ae23c3284230d31527a8b2f8a4721cfa9d31535c93604fcd9be10894eeffc01bVirustotal results 18.33% Heodo
2020-01-1507766479.docdoc b58af543a114f02eefa12324cd48a81e69239da04a6fd4bb9cec8b32fedc9cd2n/a 
2020-01-15BAL_PO_01152020EX.docdoc e4fa19c4736ffb554aacdb6de08c4ad081fd55105dddc85b31eac5c6082e601bVirustotal results 18.33% 
2020-01-15BAL_837996396.docdoc d3edd09e8e4e9e89dbff176e69131f189175abf1a598c18593a3bb194fc45c2eVirustotal results 37.10% Heodo
2020-01-15UXUB_7521554225067432.docdoc 632e28a523c920e3035782ad086e6d3f0e39445486e86e7ce6a05c0e4f337292Virustotal results 31.03% Heodo
2020-01-15BAL_798818919969.docdoc 17cbb232fc64e8c775b7ed47a28ec7a2cfaf6cca790994fad3c41fb60a648062Virustotal results 33.90% Heodo
2020-01-15INV_QMC_010120_TKV_011520.docdoc 0edf4c05fd5e483a3ca303151f3f58c87155ae9f1cec75be9ffd0aaad884f4f9Virustotal results 29.51% Heodo
2020-01-15INV_GZM6KFDXAT97O8A.docdoc 64a7bbb5697dab97fb723824a2f3456c67f88435cb51e3be9f99b0b9c6652186n/a Heodo
2020-01-14FILE_06682595696.docdoc a1baf5a0d42e54e55ca8951b6c1a58a9dce4268a95a768b7474c6f4a59e5e84bVirustotal results 26.23% Heodo