URLhaus Database

You are currently viewing the URLhaus database entry for http://med.tomsk.ru/images/stories/Rechnungskorrektur/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:29619
URL: http://med.tomsk.ru/images/stories/Rechnungskorrektur/
URL Status:Offline
Host: med.tomsk.ru
Date added:2018-07-09 20:58:32 UTC
Last online:2018-09-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: JayTHL
Abuse complaint sent (?): Yes (2018-07-09 21:06:45 UTC to lir{at}tomline[dot]ru)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-10rechnung-CI-02075064/66.docdoc 9925020e79ac83a06b0828d6bdaa352aba4121c0d41334d13c2ac1a29d4ff806Virustotal results 36.67% Heodo
2018-07-10Rechnung-WH-0325236-73.docdoc 463fe15318a983c8adbb28bcc68c5ad867fdf4b9c7ce6af284e1b982ff053c05Virustotal results 43.10% Heodo
2018-07-10RECH-BHJ-033351887-24.docdoc 84b5e3235e3e651e446b71aa7b68bb61afec3c7fb60e6189883f23f3779fda68Virustotal results 42.37% Heodo
2018-07-10rechnung-CWZ-0383327/0.docdoc 3af191c8f9577b27d8f8756b4ef37cf76bd33adb01feec6ee737181f1e64e219Virustotal results 33.90% Heodo
2018-07-10rech-FP-09/3165310.docdoc 7413b134a63bf6c0bd02c784ff8c9b5716af9512ef029b0fc1c745656c2ea76dVirustotal results 28.81% Heodo
2018-07-10rechnung-WJ-042943780/15.docdoc 47d769cd763ce91c81fac2ac56d3371b592a973e4c6c1e3f266d35acf36566d5Virustotal results 30.00% Heodo
2018-07-10Rech-TWD-02992971-92.docdoc 4d909f80fda16d515cb3b5d45b4e9b868742de09c57282d015c9d44d3ba85d86Virustotal results 28.81% Heodo
2018-07-10rechnung-NJ-04-117668.docdoc a6af6325bafba6343bb8e39ff465f0daf339c9cfb7bcd7119ea4e0d0597667c1Virustotal results 27.12% Heodo
2018-07-09Rech-DHU-09-47353716.docdoc 0ac052c968388147a8d8701f8eea4919649f9a7a98b1f79786344f14749ef805Virustotal results 30.51% Heodo