URLhaus Database

You are currently viewing the URLhaus database entry for http://angthong.nfe.go.th/am/common-module/individual-profile/NCRWEZVn-HHnqtlrHmv6/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:294160
URL: http://angthong.nfe.go.th/am/common-module/individual-profile/NCRWEZVn-HHnqtlrHmv6/
URL Status:Offline
Host: angthong.nfe.go.th
Date added:2020-01-21 21:58:05 UTC
Last online:2020-11-19 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-21 22:00:03 UTC to abuse{at}totisp[dot]net)
Takedown time:10 months, 2 days, 9 hours, 21 minutes Bad (down since 2020-11-19 07:21:04 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-17rep 2020_01_23 415.docdoc 30bf2c32e57dc6da119370516c0d6e8fc0641e683a6cbd82f8927a203e0ba5bbn/a 
2020-02-08rep 2020_01_23 415.docdoc 6d5783fbd7eba0617ed787b16f412419a4a71d2d4374c6570b398381c548c967n/a 
2020-01-23rep 2020_01_23 415.docdoc 29da9d017cd0bbe2d5b57ebf2919938de9914e669199f58175412bfd7b44861cVirustotal results 31.75%Heodo
2020-01-23LIST_20200123_J445433.docdoc 93bb9d052dae7e7965182fcd79c48c1e7e88e30f37ebf761462d4c5c5c629049Virustotal results 30.16% Heodo
2020-01-23arc_2020_01_23_ROI82434.docdoc f72e74ea61f7b7a18e525ffa6453d67872f898f2be8def76d3ec300684b9be38Virustotal results 33.33% Heodo
2020-01-23Arc-4240.docdoc 5b0fb8dce07f4914ec55fd9e0f78084158aafaba83ad9e5d8bf9b16da196ababVirustotal results 25.81% 
2020-01-23mes-MCB9058.docdoc dffcb098e0de2da6e716338b746fcf3725fa0264609c66d7a1126b062dab6131Virustotal results 28.12% Heodo
2020-01-23Inf-776.docdoc fa356cafd2c2edc009a85933b576ce9298a6fb4638ee0a1b792402e225913215Virustotal results 28.12% Heodo
2020-01-23MES 20200123 586.docdoc b63585f5efab051c9a793dac78be7af0a7bb002f803b2d67a828065ee6ce54fdVirustotal results 27.42% Heodo
2020-01-23DAT_JBP585.docdoc 2e70d384c273ebd587c2500ab07a5ba05deb68924b2a67b85e1e3cb267e7dc24Virustotal results 22.22% Heodo
2020-01-23FILE_2020_01_23_PR921.docdoc dd46168d7017d454d5b01dcb489a4fefe457957a8b0ea67e4bec9678a91cff94Virustotal results 32.81% Heodo
2020-01-22FILE_785.docdoc 75b1388d52a749fbd2389454eba1d3965fbb1bbf8776355dd9995b6cc718b1c5Virustotal results 31.25% Heodo
2020-01-22St-IAC073.docdoc e86ac3e7a2d96b9747573864789dfe89e259be7303ca1a5e36fb98703c966f55Virustotal results 25.40% Heodo
2020-01-22File_20200122_0279.docdoc 2ad3eac84cebb1c035141e43e0b9a5cf7ef8defb6dc62580737446cc39f9f7f7Virustotal results 30.65% Heodo
2020-01-22ST_20200122_035.docdoc 7fbe379add317de99ee6671bf1ca2f42860be56657cf096cb44f89b8b1e0e318n/a Heodo
2020-01-22inv-244215.docdoc d51bc288487e5fdcfc17a5ec6e0fa384a022cb77f0474947a0d2059faa19446bVirustotal results 31.75% Heodo
2020-01-22Pay_2020_01_22_7782.docdoc d5d9a7450867f6c951b33c65e5c363becf43297041b078e61259006714be9da2n/a Heodo
2020-01-22DAT.docdoc 5bc4aba04bf607cb2929cff17be475692235eb53deac2ac537fecb79ff8156b8Virustotal results 19.67% Heodo
2020-01-22DOC_85229.docdoc a8968c2f9d45a8df5c0744b681ad2a215faebbb1c4a3ec36f5a882d40c91e298Virustotal results 20.97% Heodo
2020-01-21INV_0247.docdoc fbc0fb3b339db0716a9cb4ec9fc14cb367f2a8597bbfcdd7dd553c1a96ccc410Virustotal results 20.97% Heodo
2020-01-21List-852968.docdoc 48dcc7b6fcac5eb751b1b33aa2eb59cfb2e94b0e0a5cdab668b4bec913df421dn/a Heodo
2020-01-21list-20200122-WL997264.docdoc f7fde1b0a4c37cd62f25367005e6ede3a0a31498f6a753e144c2553d6ee86d3aVirustotal results 19.35% Heodo