URLhaus Database

You are currently viewing the URLhaus database entry for http://abtnabau.go.th/log/TUbHv-uPD6KtBL-module/special-amkufq3w9ek2m0-5xz/WoDLTrm-idufmlk8ur1Kp8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:293810
URL: http://abtnabau.go.th/log/TUbHv-uPD6KtBL-module/special-amkufq3w9ek2m0-5xz/WoDLTrm-idufmlk8ur1Kp8/
URL Status:Offline
Host: abtnabau.go.th
Date added:2020-01-21 17:07:01 UTC
Last online:2020-01-27 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-21 17:08:04 UTC to abuse{at}bestinternet[dot]co[dot]th)
Takedown time:5 days, 13 hours, 53 minutes Bad (down since 2020-01-27 07:01:04 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24Inf-2020_01_23-R584.docdoc 00dc24c1692d52dd2e3eee657a2c85794a8e4938577f398005aa1593628a8da0n/a 
2020-01-23Inf-2020_01_23-R584.docdoc b496b3baebe6716d7dede9b4b98c8aa07dde4020ddbde770b43a202a3d16b3deVirustotal results 31.15% Heodo
2020-01-23LIST_UFV8203.docdoc e5afc379b50bce74cf1a04bf9c3c7076606bccf43f6fd011c95beb8859b95245Virustotal results 25.81% Heodo
2020-01-23List_20200123_9843986.docdoc 4290328c2f63e01b783944553083370929fbec839c7d50cfec24569d9f670f57Virustotal results 20.97% Heodo
2020-01-23INF-CSW546.docdoc 0602a260f7babf69b17ea0c106902e0aa1210f18240011382c3d1b89cbf2a78fn/a 
2020-01-23arc_Y670.docdoc 129967e7908c933478dbe958d62c4d0edc10802a33da0f9055d834958c0257d6Virustotal results 33.33% Heodo
2020-01-23mes 20200123.docdoc a5b40116b0e7fcee6fbf05e3425ae17e7812e5a1bfa387e8588f0002fff8911eVirustotal results 35.48% Heodo
2020-01-22List_20200122_050329.docdoc 6eb3a1de5779c87ba943671cbe8f29213ae390f189e8bd35f9520393e1edf6deVirustotal results 26.56% Heodo
2020-01-22ST 20200122 89892.docdoc dad1b60c001deb55fd561c435e1825db93fd1dc33d40fcf6d99a469e56d0f6e0Virustotal results 27.69% Heodo
2020-01-22inv 20200122 0880224.docdoc 2ad3eac84cebb1c035141e43e0b9a5cf7ef8defb6dc62580737446cc39f9f7f7Virustotal results 30.65% Heodo
2020-01-22inf 20200122.docdoc 7fbe379add317de99ee6671bf1ca2f42860be56657cf096cb44f89b8b1e0e318n/a Heodo
2020-01-22LIST_2020_01_22_IN833763.docdoc d51bc288487e5fdcfc17a5ec6e0fa384a022cb77f0474947a0d2059faa19446bVirustotal results 31.75% Heodo
2020-01-22INF-20200122-ZBL423.docdoc d5d9a7450867f6c951b33c65e5c363becf43297041b078e61259006714be9da2Virustotal results 30.65% Heodo
2020-01-22mes-2020_01_22-MU324491.docdoc 63e4f747e3e1e3b0013d5e079ba505deee4fac664d83b0e250297677230bd592n/a Heodo
2020-01-22ARC 20200122 LAP387.docdoc 90855aa3bc7cbb5168ba1ec9ce13d058fb143e67f3cbd23c64e816868c837b59Virustotal results 27.42% Heodo
2020-01-22REP 20200122 1761510.docdoc 9f43e4ef8ca595416c11f8bdd8f4f34aa0d8dc6f388cbdad8b2a5277ea5f97b9n/a Heodo
2020-01-22dat_2020_01_22_EQ300.docdoc 234cba08fc425f95447f2c72a2dae3ffbc5b47f1d14013c13cdcecad60ce1802n/a Heodo
2020-01-22File_20200122_8976.docdoc f215874c38b91208764829b0950f3658cbed0e5931060ec4d658ff212f019642Virustotal results 19.67% Heodo
2020-01-22Dat-20200122-7664.docdoc f57549b2d5b329a8c83b05e2a6ea4f288e4215882c24d2650cc818e65fcd6239Virustotal results 20.00% Heodo
2020-01-22list 2020_01_22 TZP9440.docdoc e32b84c7d967bd21ca4def6c66ed1441afca25b720e896b926f4c01906891918Virustotal results 19.67% Heodo
2020-01-22FILE 2020_01_22 BF1528.docdoc 822cab01673ebcd4b1d6de1afd0e2cba9d227f59b4be13c5df84c1427ef64389Virustotal results 20.00% Heodo
2020-01-22Rep_H930865.docdoc 55e7c45b115a1b3f5841cff784e524e1a7db1007c8b7dab6c0ac641891d18a4bVirustotal results 20.00% Heodo
2020-01-22Pay_20200122_Q20784.docdoc e79c48d70bcccb3548449658faf87fa391a8c26fec22e26249f864eae4d78783n/a 
2020-01-21PAY 20200122 312238.docdoc 2119f3e51c12625d689a0d06dbbbf6d19fc6555e7f33b67a54e3df778f1a09fdVirustotal results 20.00% Heodo
2020-01-21doc 15673.docdoc 9694a4c6d10eb061dd240367cc5d98afa97954e04e12427d65332c4de96887fdVirustotal results 20.97% Heodo
2020-01-21Bl_2020_01_22_814448.docdoc 053f8aa722cb6b921c25cdf4e020bc1272f3869f35f9eb9ac4e1314906f9451dVirustotal results 20.00% Heodo
2020-01-21St-2020_01_21-I110.docdoc 011423eab82e47c067f2e01970d903718cfb94cc1a92becd1df0736040f1a2dcVirustotal results 20.34% Heodo
2020-01-21Inf 2020_01_21 D2604.docdoc 83e74cc68f7c71047741f8fb8766dd41e6b640de167738ab90eaee6f9a32aeecn/a Heodo
2020-01-21PAY 409.docdoc ba4ef1d048b24b46bb2462c1dd1a88c778bbb7bf1a4a4e251fbe5f45b635a0e9Virustotal results 19.67% Heodo
2020-01-21Inv-20200121-34455.docdoc 1ee7e51a66e0fa4fb6a8239cea1cface0d8fd07b578a5acbeb6ccc19caf2ceafVirustotal results 21.31% Heodo