URLhaus Database

You are currently viewing the URLhaus database entry for http://nhuusr.nhu.edu.tw/css/common-sector/external-warehouse/44043891-op5zTcWg9A6/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299187
URL: http://nhuusr.nhu.edu.tw/css/common-sector/external-warehouse/44043891-op5zTcWg9A6/
URL Status:Offline
Host: nhuusr.nhu.edu.tw
Date added:2020-01-27 21:33:21 UTC
Last online:2020-02-04 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-27 21:34:05 UTC to hostmaster{at}twnic[dot]net[dot]tw)
Takedown time:7 days, 15 hours, 52 minutes Bad (down since 2020-02-04 13:26:45 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29File_2020_01_30_4353.docdoc 4b3526d436b61ea105e5200c575036f5e105a00e3c941f5e2d40efb75ed41810Virustotal results 37.29% Heodo
2020-01-29MES_20200129_920.docdoc de39c0b0ba341eb6a6c1cc3bff5a3dede93907976a77563396df5165f422ac7fVirustotal results 33.33% Heodo
2020-01-29Doc_2020_01_29_418.docdoc c5bee30abc8770da84f8bbd7f058c8345679dc510a04e67ae7a663820250019dVirustotal results 32.26% Heodo
2020-01-29REP H690442.docdoc d9e6778d130d18c51ae971d9b67674e2efc88e36d86b1d08e74ff54214d601d8Virustotal results 30.51% Heodo
2020-01-29Dat 20200129 DT45698.docdoc b09c8d39fe17d600ac2beffd9540076f55d944b41ae3c11b26600252a272b3ecVirustotal results 26.98% Heodo
2020-01-29INF-XN121.docdoc a6f8d6e5f80b47b55146e82c61a78c5ed8c451bcb68d157dee574d02c768ba30Virustotal results 26.56% Heodo
2020-01-29List 20200129 48381.docdoc 41f2df35fe03375e39b939c95142a9c04e1613e60bcdeb4f50ea339349d04243Virustotal results 26.98% Heodo
2020-01-29FILE_XL3159.docdoc ec9b05ca4512e2e594339751e698ee57b1373c749a8c8b26cbe5c79dc1e978ccVirustotal results 26.98% Heodo
2020-01-29LIST_2020_01_29_52332.docdoc 0b0243567f8017cba7be007b4d797731af10a9c7e9971cb09881d0a646bf88a2Virustotal results 30.00% Heodo
2020-01-29List_807.docdoc 66ecd1fbf53f10ac6f349605be071821abddb87b684dbf9e12b5add72eb5a61bVirustotal results 26.98% 
2020-01-29Mes 20200129 CBE979111.docdoc a4edb0742bb50f5c20c88508ef0dd1028d985dcf0b9ced6c6c9bdf800e1c6748Virustotal results 25.40% Heodo
2020-01-29inf-20200129-873624.docdoc 2c68f8e2764dd94c2229034f644bf7cb24cd34b1fa153e999d321e0e4eb8e73fVirustotal results 24.14% Heodo
2020-01-29Mes_20200129_879177.docdoc 44a4ef90160d6dbd60b003ccbce9172073b7b939f37503efc4fc431e906010d8Virustotal results 23.81% Heodo
2020-01-29inf 20200129.docdoc c2b2cd3b90f72db2fc325fdac1161626765153b7cb874ee42bea9fe3caf0eb6cVirustotal results 25.81% Heodo
2020-01-29Inf_2020_01_29_357185.docdoc f58728aa5f5dcea800d3602a7ca76d8890d5d931c79d094bda9e1c1e04a1798aVirustotal results 45.16% Heodo
2020-01-29Rep-Q3560.docdoc 46881f26fc411584779fac4746c5ebae0b755de88a4b21e239940ef2b4ad2068Virustotal results 43.55% Heodo
2020-01-29Dat-20200129-VD62859.docdoc 8c05cb88caacbc8eb0e4a1e79a0d1a707959b45fb39f5e694923b6b069ebce75Virustotal results 43.55% 
2020-01-29Mes 20200129 NK40974.docdoc d0587297f7b5699b364592f59c0d93057b42defb42c714d6381d54a6142953edVirustotal results 44.44% Heodo
2020-01-29Doc_H015757.docdoc 623303d6b597c92e43276ac21c6338a64cb078760e9a74bd08050666a3aeca13Virustotal results 43.55% Heodo
2020-01-29Arc 2020_01_29 F5456.docdoc 85359d87138be58de0c049e5c520f4de37adde9310893971769a0c640ba0a0fdVirustotal results 44.44% Heodo
2020-01-29List 20200129 N63974.docdoc e26c4466ac96339cf441036fb05d86cba2f624e2c7481c1ca86209c19122cbc6Virustotal results 40.32%Heodo
2020-01-28List_2020_01_29_479.docdoc a5b8d8907e0cf3e09b5a2e7bd993dca67975830d84b0ff832334fdafe4f656d3Virustotal results 39.06% Heodo
2020-01-28File-20200129-2552725.docdoc f2a6a0283ff20ad3d0855ce7825d84920a0a27c55825a5a5b9ba91408388a402Virustotal results 41.94% Heodo
2020-01-28Doc-2020_01_28-Q933597.docdoc 9a1962dfceb1a62ff349d932160c03ec9304954e3a0fb69e25b672fbef7b90b4Virustotal results 36.51% Heodo
2020-01-28MES-2020_01_28-RI85458.docdoc 4f0657b4834de2757799949da41f3ed5391b919f6539122e9dd06523c75df20bVirustotal results 36.51% Heodo
2020-01-28INF-30606.docdoc 76288b03aada28f313d41a8856e42320372dfc03b255335b3d8c0427cb01c4a1n/a Heodo
2020-01-28file_2020_01_28_BG249737.docdoc 905563c6be86ed6e853e1f2bc9f4cdffa60c74647a96e1fe871a53a585ae3a10n/a Heodo
2020-01-28FILE_20200128_PH0248.docdoc 59428bbec1459b7f3517f508013242a3dd7f4dbdee059380b5ff1c265abc6197Virustotal results 26.98% Heodo
2020-01-28mes_XY151.docdoc 17de704a282307408b556e2328dec5c5715d0cd7136dcdc1d6fe54f841dc2bc4Virustotal results 23.81% Heodo
2020-01-28List 2020_01_28 31138.docdoc c50c6dc106e4d46b561eb4f45f329818ee1c5077cf4d4b4010ce38d01e437756Virustotal results 22.58% Heodo
2020-01-28Arc 2020_01_28 83392.docdoc 267aa23c9031b06e6dc7fac45daca30a65d4f08843fe0976c2ad7201d9646dafVirustotal results 28.57% Heodo
2020-01-28inf.docdoc fccf3876128e78c8d3a6385aa312b1333c822a2b9efafb26daf1d2ffea296d59Virustotal results 25.40% Heodo
2020-01-28Doc 20200128 G612.docdoc c5666d80df3d2361122568d511e336c58a58b27576a1cd78b434c425d8b2e809Virustotal results 22.58% Heodo
2020-01-28mes.docdoc 256954bf735b73749d5fd67afbf6e789abb356f02cec192954e129996801d642Virustotal results 22.22% Heodo
2020-01-28Mes_20200128_2688467.docdoc 9cb664f1e4189925744979c21e305e2af11f98b2fedd6d32c4e3d5745b51ce07Virustotal results 22.95% 
2020-01-28DAT-01515.docdoc ae1c2a1ebc838f4092123a0fed626a10f1325e7796629f6d370111fd50d8154dVirustotal results 22.22% Heodo
2020-01-28Doc-2020_01_28-722443.docdoc 0827a2ab4aa1c0caddd493489b6197943bc03b6da0d9f52c54071449dee6538cVirustotal results 40.32% Heodo
2020-01-28INF LKR89810.docdoc 33d3ef3b1fb0f8ed8ed87b487e184b207ff302b60481dac9da9487ca210247e9n/a Heodo
2020-01-28dat-20200128.docdoc 20cdcb97c92b8c58397ab1170823f96ce0db2c3e93d4859bd06fb23302687d30Virustotal results 41.27% Heodo
2020-01-28Rep_2140974.docdoc f79992105131cff7dd4570db1648129b246323085d2843087e402a966d52503aVirustotal results 41.27% 
2020-01-28List FY687870.docdoc c13b52eb583794eb0a50cdcaa031505507d999bc95725e77c29eb6b1adcfffa8n/a Heodo
2020-01-28Inf-2020_01_28-4251794.docdoc 5d122705ee27c72e755eb8df3baab283269868ae0095c36474b8195aa96048daVirustotal results 41.94% Heodo
2020-01-28doc-20200128-43314.docdoc 15e7acb25aa2624c378b3a89937810c058af5ebec4e48fd733ccb400b783b1a9Virustotal results 36.07% Heodo
2020-01-28Rep_VC0491.docdoc 3927da4014a56e521774e33625a1ac60e65e39edee26dca5fc703fc240bc0c99Virustotal results 37.10% Heodo
2020-01-27rep-20200128-104.docdoc 8a5d48bf4570d69fd4c9398857cb6bde479600de838113e497e4d139720ab207Virustotal results 34.43% Heodo
2020-01-27rep_RTK557493.docdoc 105d24ebb512c02c992f5b330459830f12ece2b54011cd65914e673f0617c8c7Virustotal results 31.67% Heodo
2020-01-27Doc-2020_01_28-41027.docdoc 1f6c87016d40196a51afa52762274419597e756b2942b0b6267f78fc90bc3a59Virustotal results 29.51% Heodo