URLhaus Database

You are currently viewing the URLhaus database entry for http://niholzamin.dst.uz/wp-includes/6x8s90y-kkrjt-976702/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299097
URL: http://niholzamin.dst.uz/wp-includes/6x8s90y-kkrjt-976702/
URL Status:Offline
Host: niholzamin.dst.uz
Date added:2020-01-27 19:31:08 UTC
Last online:2020-02-03 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-27 19:32:04 UTC to abuse{at}axol[dot]net)
Takedown time:6 days, 20 hours, 10 minutes Bad (down since 2020-02-03 15:42:04 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29invoice-MYA30_18122300.docdoc 96e156e2bbcfd1c45dcde407f6e4382203e5c4809f2447c652847121850ef07bVirustotal results 29.51% 
2020-01-29invoice-516_1229872.docdoc bd1eac417a2f82f5ed9f7dc86783678343738758322a16a7d21d77cd587a4f55Virustotal results 30.91% Heodo
2020-01-29Invoice-XS107_782727532.docdoc 70b79f7a9104113770865d6b9495150c39a6d3f9a5f98750ea69871f38ac5566Virustotal results 29.51% Heodo
2020-01-29Invoice-9_40163466.docdoc 8a502f32c4e9b027761b883615a99071262858fe124e0f76a51ee65583ff4c59Virustotal results 27.42% Heodo
2020-01-29invoice M34_67782580.docdoc 4ebbc029641c276924244405d1b630b683f1fd7b23da40587548e7afcf5bfda8Virustotal results 26.98% Heodo
2020-01-29INVOICE_HUA5_911439.docdoc 9ab92e41150dd1c132be3b79097a4b4fff2a151a9a5d77bd3e0aaeb41a5b862bVirustotal results 26.23% Heodo
2020-01-29invoice-UU1914_095484.docdoc 6eb3be35a52b1bbd297eec41d1d5871bb1f27a225f381a75a1040eea80a20ae4Virustotal results 26.56% Heodo
2020-01-29Inv-RLQ8_818809.docdoc c96340cadc0402f8b3d1f4b131d2d467aaf51925719357486faa7300f9ea8c3bVirustotal results 30.65% 
2020-01-29Invoice-O3_8650582.docdoc b49c9eba58537f8d856daded80bc9493a83c508d73423b98686d4e8b232d61c3Virustotal results 32.81% Heodo
2020-01-29INVOICE-J8280_554601.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29Invoice-688_507920.docdoc f51d2aa766b1b07701a52e866f50132c0fcfaad288c1aaf13c781a66db3168daVirustotal results 47.62% Heodo
2020-01-29Inv VZX5_985336.docdoc 11b4519b76957b0758381f8e19c5e15d8744f7974716642aeb586c615dde38faVirustotal results 48.39% Heodo
2020-01-29Inv I1011_6525332.docdoc 4a272dd4a5c6261e983d667dd676875054dd4a4ea11620f16c553fcfd2c44861Virustotal results 46.77% Heodo
2020-01-29INVOICE_H6_207876412.docdoc 89a0147dec8d6838f14815b577ae41dbcf54953c66e7f5f999ab91fea6ec08faVirustotal results 46.03% Heodo
2020-01-29Inv-TKWO3_0016206.docdoc 8c0a8d6876a6c7fe44962883561d9f48615ee67f4544872ec98f47edcf516509Virustotal results 47.62% 
2020-01-29Inv_YYX8440_664223.docdoc 849aedf219a4f6ab15e2c5c653a8bbd6fce909c51d2e95984bf6241f6b939e89Virustotal results 48.39% Heodo
2020-01-29invoice_QDAX83_360830.docdoc c25db0a6d33ba3de2ea0ea992b98117d92ef8cc0a1dc6d9ff79788db6ce7e06eVirustotal results 47.54% Heodo
2020-01-29invoice TN31_729192.docdoc 0d1de45954adee600bf2a41e5b1de25ba4ead4b3938d1c987f6bdf8e48fb9a42Virustotal results 43.55% Heodo
2020-01-28INVOICE-XA21_62691682.docdoc f9a330484e52de8ab57a920eb93d6308dd150ba0001e7ba7cfb2a50edfec5ca0Virustotal results 43.55% 
2020-01-28Inv SC1392_81880335.docdoc 9e9d8e60ea0a7b028513b69e3f41360a4d6a4be4ec05af3fae645bcbca37f827Virustotal results 42.19% Heodo
2020-01-28Invoice-LO581_398304821.docdoc 9dbf7690bf328942e99f61b0eae8db502e74c272b7499da4342e6ee7d915bda2Virustotal results 40.32% Heodo
2020-01-28invoice_CGHV6_67526100.docdoc 85e978955f2d5b46e50d3a259f837643be8e5b3e0c643465881342f1cc7f3d31Virustotal results 35.48% Heodo
2020-01-28Inv IF30_761040.docdoc e6551fa9814756f1d99f86fe2713d695e930e5930e397affed4aa07d4ea63ba6Virustotal results 29.69% 
2020-01-28Invoice 432_10121599.docdoc 92c3a1a03abdc8976c1b9e1b200a2b08e114d2e6dfa54566f81f16a2671e9735Virustotal results 26.23% Heodo
2020-01-28invoice-75_462650.docdoc c17c75821c89a7ad0099092a5b55fcc514e74124e43e60fcf669de6436453b82Virustotal results 23.44% 
2020-01-28invoice_JG340_04293669.docdoc a7cd0e0d4371256091f7a81ff6100974822424c0c06e2dd5e07956b1ab62c19eVirustotal results 24.19% Heodo
2020-01-28Inv-O59_409432482.docdoc 9db28f01c7a26ba6a757542ddb44145a167395b639df0eac4d9f48a926d8f810Virustotal results 22.95% Heodo
2020-01-28Invoice_4_55171099.docdoc a6b9f25b3f632a071e548d1e092d8557eedd074094e5e1a2dd684a724fb07fe6Virustotal results 26.98% Heodo
2020-01-28Inv WL977_329540272.docdoc 32a27468a4355d462e5de6e29290189f023ad6b51836d3134dcb19a74f615f51Virustotal results 25.81% Heodo
2020-01-28Inv_NTG02_3993723.docdoc fad431f81e098efc657ea4c9787427f6080e70ef1ea7631dbf51f35578e79438Virustotal results 26.98% Heodo
2020-01-28Inv-B283_228327.docdoc c281f5dc7b7f7e91c714324444133165bc38d375cb72d3a5624d452111fa3af0Virustotal results 27.42% Heodo
2020-01-28INVOICE_408_368946285.docdoc 42cf3dc2c05800ee63913c2437b824f17dc2999d761edc2c318a7b94fd9ac4a4Virustotal results 22.22% Heodo
2020-01-28INVOICE_76_829549404.docdoc 0f30073111c54d8f89bd3d4c031b77db7d32447f0bee27914ac94ffedc2baef1Virustotal results 23.81% Heodo
2020-01-28INVOICE-89_628256858.docdoc 37f7008209b0cf19267afa8ccdab629b76f4bfa992d7f77ce2c098e5e473c8dbVirustotal results 40.32% Heodo
2020-01-28INVOICE_23_67599436.docdoc fbe992a68ce37d101a4005da5062aee9e868e5885fe5b4c69e69c0981c8eeaffVirustotal results 40.98% Heodo
2020-01-28INVOICE_ASVS30_43448909.docdoc 8a7392680f73456eb56ede477a8e74a726b92658f8440ce85894f2a2de8daa19n/a Heodo
2020-01-28Inv-WJY9_219691.docdoc 4894a2fb49eee40ed615f4dc24ee4965b5343992df774c0871b9f6d6cc7c6f97n/a Heodo
2020-01-27INVOICE-ZB87_665027758.docdoc a1f54f1d2950aaf223d4c560f120e042e26c7e738c3ce67c87e0550edb7228acVirustotal results 25.81% Heodo
2020-01-27invoice_NXLE61_1714682.docdoc cf6fc0c9b296a21a605c029d19eab5d466b785cdc4efb16d18963b598f82ccden/a Heodo
2020-01-27Invoice-XOXL9302_3586196.docdoc b8234c3a29dfe136921812c6011604fac4f3860df104d73b44365fd690d34e17n/a 
2020-01-27INVOICE 5176_746916302.docdoc 67eab02ca37edbc7fe1d863ffae8925ad26433b6b833f411fb1cbd7fecabf669Virustotal results 22.22%