URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ppta.ps/_notes/OCT/l-72011-30922-ayp2r7z-pumil/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:289962
URL: http://www.ppta.ps/_notes/OCT/l-72011-30922-ayp2r7z-pumil/
URL Status:Offline
Host: www.ppta.ps
Date added:2020-01-16 11:48:04 UTC
Last online:2020-04-02 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-16 11:50:03 UTC to abuse{at}speedclick[dot]ps)
Takedown time:2 months, 16 days, 22 hours, 5 minutes Bad (down since 2020-04-02 09:55:14 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18WDWK_KS4928688549GA.docdoc c141a187c5b2c7a8d91a923a0f79a8ba4c1484e7295f922c5fac3d7c0d6792b9Virustotal results 42.62% Heodo
2020-01-18OARF_GOZXI95J67BDOR.docdoc 7909ceba1631db13b91572b6a331c753c1992fef87e4ab4a4bf2573851a9870cVirustotal results 38.71% Heodo
2020-01-18SW_674036942388.docdoc 3e20022ca68d8d5659df788aba0f592c903b804fead2c66b46290bedf392b562Virustotal results 38.71% Heodo
2020-01-18PM_811272947246683646.docdoc d8e4d933b44b9fa3d2068ec7ef3f07536eb0c6c06a126862e898c1d00b50d437Virustotal results 32.79% Heodo
2020-01-18TGZ_010120_GXK_011820.docdoc 966c59a517b8c7e9c1b8fdf6be7b395735edfd3de380146329be21293272a876Virustotal results 20.97% Heodo
2020-01-18PO_01182020EX.docdoc a4b002f0eb008e944757b8bb96621624b36474ce06b5674bfcc7e43affc0b919Virustotal results 18.03% Heodo
2020-01-18I_XGG_010120_ZIX_011820.docdoc 45724a1a1f70affb08b7a8e122600296375aa9807f0e1096f52f586dbfbad0aaVirustotal results 19.35% 
2020-01-18FILE_UX3697398135VS.docdoc f053ae73a989069438f06320dc3412e06ba7947414cb0cbb3ffd3abe8d998483Virustotal results 19.67% Heodo
2020-01-17INV_PO_01182020EX.docdoc 5d7a916c81626a8226edf1b4fe848dce75b71426c90ff26383dbeacfbe05077fVirustotal results 19.35% Heodo
2020-01-17FILE_PO_01182020EX.docdoc 7de2404e9638e8fab7b324d2df37fdce114f9de3bd3d24d923bba09efde0853eVirustotal results 19.67% Heodo
2020-01-17PO_01182020EX.docdoc 8902f09d161bb7ff5688ee9ae8b5c01ac7a9cc19898363dec6fa5ecc8ec05850Virustotal results 20.69% Heodo
2020-01-17K_GNFBVW6Q2TBT996.docdoc 456095be06bd4ddbb92fde65c0359c3a074642acf9ad7026c2a6daa86485bf73Virustotal results 22.58% Heodo
2020-01-17DOC_04494193.docdoc 00a28153d7dc5d00cc4d05c8410dad1fe7eb288d673332d89883258fb7f19137Virustotal results 21.31% Heodo
2020-01-17BAL_90104254.docdoc 88067e56e4765755590fc617a21d46e45f6ebadcaa14ed8377715c43c4ecd3abVirustotal results 23.73% Heodo
2020-01-17PO_01172020EX.docdoc 9f81a80998e1d5cfbe2d86ae82851ec2ad75ba32e627e1e95f803a72e7d6647aVirustotal results 27.87% Heodo
2020-01-17RP_15695730.docdoc 1cccdc74817414b1cd45f3994d81744f4c979dcc6017f6ea3f7b15b3c720faeaVirustotal results 21.67% Heodo
2020-01-17REP_IR1856378527QM.docdoc 0dd1c5a05a40d97c67e3df2e097fbbd94f9b94cc3c674c953893f275a1a08dfaVirustotal results 22.58% Heodo
2020-01-17V_2265869043609964470225658.docdoc b0e00f2c53eff02aaee7134670676339aab802de2cd8af0bdacb94262e79f777Virustotal results 19.67% 
2020-01-17FILE_ULXUXBLNXSX8F.docdoc 4c599d62c5811475285b14bbfa88fdec394d420b82d93c20e51a4630adac0828Virustotal results 19.35% Heodo
2020-01-1731125410032402720.docdoc 496e82b4aac77a47fcb312c63e8f4061b480c523124f87e037522a5ecec5aa5bVirustotal results 18.33% Heodo
2020-01-17FILE_HHYUNC9HLSELZ.docdoc 26ba3fe65926140305a8fa605d09b8bd2fb8251648eac9b3165fb884a506e837Virustotal results 18.64% Heodo
2020-01-17FILE_PO_01172020EX.docdoc 01803cd4cad276de7bde227f5eac222a512d1cdc85252fc4c34d23c36296fb05Virustotal results 20.83% Heodo
2020-01-1719081770.docdoc b5b1a9c9342c9be2197fc3f9fc5c0a9138b052bfc06583f9719773397f567e34Virustotal results 43.55% Heodo
2020-01-17ST_PO_01172020EX.docdoc cab5a457395c329bad38f329fe4d098cc23a094dd70ab7f4af0d5a34f6643349Virustotal results 41.94% Heodo
2020-01-17FILE_31831922.docdoc 534d37a11e695ad6fd5b23ac1a8cb87571a5865e5651f954e3fefbf355ac737aVirustotal results 40.32% Heodo
2020-01-17ST_4282776480764.docdoc 92f80243e6766c07a9eb3c8ef28eff839d1f23a112c0387911cda51154751b9aVirustotal results 38.71% 
2020-01-17HIK_010120_HYF_011720.docdoc aee82de11a80817171ad5f8919164b13551cb4b3bb15b91362ce6626d2c067e5Virustotal results 37.70% Heodo
2020-01-16INV_MRJMQEYNA.docdoc 228da1e8833b2deb4570eb45b4cb5ceff4c62dd963e802c3a5b769ca9d28ff42Virustotal results 36.07% Heodo
2020-01-16PAY_DBW_010120_KLD_011720.docdoc 58284dd1bedbf2c82204eb15cdad07525a70b52ff1729e051ac101c066531ce3Virustotal results 37.70% 
2020-01-16ST_HTJ_010120_OUO_011620.docdoc 384bafeed9e841a938a039e953468d9bae973ad45a1097c037ff1a4ce12bf92bn/a Heodo
2020-01-16RP_TCU_010120_SKM_011620.docdoc 86cbc728df6a04a246a877012acd772a8880f516d4dd8a9bd746a3298af1be0eVirustotal results 33.33% 
2020-01-16DOC_35543369671802070550941.docdoc 6dc7f5025f0a9ba2abeb82a8db9a479f41a3a3ec8b558455b930d54029108638Virustotal results 30.65% Heodo
2020-01-16BAL_9907918622.docdoc 67e4ad463f707098e9dd3aa9ef44543687de41237cb6bd15500e428aa17c34c7Virustotal results 31.15% Heodo
2020-01-16P_19285352.docdoc 26cdcd3d777b8213e41f264c23d27628cc359ba3e7610a06107634773e28dc4cVirustotal results 27.42% 
2020-01-16MFL_010120_ZPL_011620.docdoc 921f4885db48fa6a6113a4fdfae63ff2efa5dc1b2849e4d6178a135c990557bfVirustotal results 27.87% Heodo
2020-01-16EFRY_DK4899043687TJ.docdoc 49186715dc0431481c465e3f635a7e0b8ae3f876b618c034b80254063df056c0Virustotal results 26.23% 
2020-01-16REP_58591194.docdoc 5ff8d7f197fe82b2c5076b0b8554792a534129f815ed9cbb6b7470abb297eb1bn/a Heodo