URLhaus Database

You are currently viewing the URLhaus database entry for http://v.6666888.xyz/app/open_section/test_hVeUKjjygz_inqCICVKkvJm/mYi6ZHOkr_g69giIfpwmw7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299309
URL: http://v.6666888.xyz/app/open_section/test_hVeUKjjygz_inqCICVKkvJm/mYi6ZHOkr_g69giIfpwmw7/
URL Status:Offline
Host: v.6666888.xyz
Date added:2020-01-28 00:36:06 UTC
Last online:2020-01-28 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 00:38:05 UTC to network-abuse{at}google[dot]com)
Takedown time:18 hours, 31 minutes Good (down since 2020-01-28 19:09:30 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-28MES-2020_01_28.docdoc e973fec4c3e5b5f599c5defe0c00df33eae0e9b00f1f8a1d8f9479d4e343e446Virustotal results 25.00% 
2020-01-28doc-GBP84748.docdoc 59428bbec1459b7f3517f508013242a3dd7f4dbdee059380b5ff1c265abc6197Virustotal results 26.98% Heodo
2020-01-28Inf-20200128-QND3929.docdoc 17de704a282307408b556e2328dec5c5715d0cd7136dcdc1d6fe54f841dc2bc4Virustotal results 23.81% Heodo
2020-01-28File 20200128 1599.docdoc c50c6dc106e4d46b561eb4f45f329818ee1c5077cf4d4b4010ce38d01e437756Virustotal results 22.58% Heodo
2020-01-28rep-AAP137.docdoc 267aa23c9031b06e6dc7fac45daca30a65d4f08843fe0976c2ad7201d9646dafVirustotal results 28.57% Heodo
2020-01-28Inf 419.docdoc 1ac8d894b4e2be7cb2d7fc3dee2346677c5fdc5871be74589848518155c5ff8cVirustotal results 25.40% Heodo
2020-01-28REP 2020_01_28 726.docdoc 68938178a947046088472c9c687caf7843271233fbba2b888ada13c2bb5a5e5cn/a Heodo
2020-01-28mes-20200128-BY27885.docdoc 12934d2c01ab4c7e7639e04a3a27c545f2501b1f835fc9ab5ca4f1ba97c63e38n/a Heodo
2020-01-28file_2020_01_28_DA5220.docdoc ae1c2a1ebc838f4092123a0fed626a10f1325e7796629f6d370111fd50d8154dVirustotal results 22.22% Heodo
2020-01-28Arc-2020_01_28-364.docdoc 61d0d2aa3f2b0af2db0d2e4037ac0753965f1d03e0231b17a3695337b66ddd79Virustotal results 40.32% Heodo
2020-01-28rep-JE013031.docdoc e5f579ac649c7d63c79885d849d0631d7a0fdddabb60cc9fe78f0583a9d00396Virustotal results 41.67% Heodo
2020-01-28REP-2020_01_28-HLJ365.docdoc 20cdcb97c92b8c58397ab1170823f96ce0db2c3e93d4859bd06fb23302687d30Virustotal results 41.27% Heodo
2020-01-28Rep_20200128_05033.docdoc f79992105131cff7dd4570db1648129b246323085d2843087e402a966d52503aVirustotal results 41.27% 
2020-01-28FILE 2020_01_28 777062.docdoc 5d122705ee27c72e755eb8df3baab283269868ae0095c36474b8195aa96048daVirustotal results 41.94% Heodo
2020-01-28arc_2020_01_28_8899.docdoc 15e7acb25aa2624c378b3a89937810c058af5ebec4e48fd733ccb400b783b1a9Virustotal results 36.07% Heodo
2020-01-28Rep_2020_01_28.docdoc 8dc7dbd04fd5915a55894aaa51358d9e8d061606cc70a89011628aefb91a8c8dVirustotal results 34.43% Heodo