URLhaus Database

You are currently viewing the URLhaus database entry for http://indrikov.com/cgi-bin/9zji54xcntxi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290457
URL: http://indrikov.com/cgi-bin/9zji54xcntxi/
URL Status:Offline
Host: indrikov.com
Date added:2020-01-16 23:47:08 UTC
Last online:2020-01-17 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-16 23:48:04 UTC to abuse{at}cogentco[dot]com)
Takedown time:23 hours, 38 minutes Good (down since 2020-01-17 23:26:08 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17ST_PO_01182020EX.docdoc d95e601b3c631dc51b76b89d7887d80e8325c6ef6575e361610416fb03db6e6dVirustotal results 16.67% Heodo
2020-01-17FTC_010120_UDF_011820.docdoc 88ee00f1e6c6c5ced74872d12f95b20b3f01b44dea9b62ae7f846308c2d3d794Virustotal results 18.33% Heodo
2020-01-17INV_05446651.docdoc 6970ceba8cc4d7b6c8a57fa91f1352cddc2733c26f83f17ef97f3df471837214Virustotal results 19.67% Heodo
2020-01-17GO_ST5007606051XX.docdoc 4c599d62c5811475285b14bbfa88fdec394d420b82d93c20e51a4630adac0828Virustotal results 19.35% Heodo
2020-01-17SW_043421977330.docdoc 6df7b608d7e2a56411e15da30b8aa599224f4fefa427543be20165a67eba79d2Virustotal results 19.35% Heodo
2020-01-17Y_LT5705266968QR.docdoc 26ba3fe65926140305a8fa605d09b8bd2fb8251648eac9b3165fb884a506e837Virustotal results 18.64% Heodo
2020-01-17REP_504911080425000474123.docdoc 01803cd4cad276de7bde227f5eac222a512d1cdc85252fc4c34d23c36296fb05Virustotal results 20.83% Heodo
2020-01-17PY5486656378GX.docdoc b5ac425bbd42f1b2ed152ff5780b068beed93876115fb53c98f459235d0543acVirustotal results 41.94% Heodo
2020-01-17REP_IH2856064530TO.docdoc cab5a457395c329bad38f329fe4d098cc23a094dd70ab7f4af0d5a34f6643349Virustotal results 41.94% Heodo
2020-01-17JI6919816519WD.docdoc 558da20be7ed20e08aefea0a9ab18f1ebe7c3729141f9fd83e90cce6f1c6ddb7Virustotal results 40.98% Heodo
2020-01-17I_320967636816.docdoc 92f80243e6766c07a9eb3c8ef28eff839d1f23a112c0387911cda51154751b9aVirustotal results 38.71% 
2020-01-17REP_PO_01172020EX.docdoc 2ef30359fa19b8295e05830296af78c6c2326d58fa4425b89cc5fad87b12cd45n/a Heodo
2020-01-16FILE_3NZN368E234LH27H.docdoc 2624ff7d5f6f9aa4bf51bdb7e4c78fbd95ed35654c85512f3a85dbf86d9dbb0eVirustotal results 36.07%