URLhaus Database

You are currently viewing the URLhaus database entry for https://kaushalgroup.in/02esu/524009455-Yymssddk-bT4t2U-9jGHGGKDGLE5e/8quog4a-7tfyw1-portal/KxguJG9evsXs-pqKam52qym0z2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299369
URL: https://kaushalgroup.in/02esu/524009455-Yymssddk-bT4t2U-9jGHGGKDGLE5e/8quog4a-7tfyw1-portal/KxguJG9evsXs-pqKam52qym0z2/
URL Status:Offline
Host: kaushalgroup.in
Date added:2020-01-28 02:02:04 UTC
Last online:2020-02-06 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 02:04:14 UTC to abuse{at}a2hosting[dot]com)
Takedown time:9 days, 13 hours, 8 minutes Bad (down since 2020-02-06 15:12:17 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29Mes.docdoc 0c899fbd963450fdf0d3d487fd91c0ef00e8c4191115d99d58a6b75476b06254Virustotal results 22.58%Heodo
2020-01-29arc_NR4605.docdoc f3e0ea1e9f70b58a16ab7b737be16e81a1868a88fcdd4de0c1fb6c4a3aa6b3b9Virustotal results 40.32% Heodo
2020-01-29LIST.docdoc e49d66744b97eaa47dae870c0fdd5f6b3a52e1b2245e8567ffa6b8a344663fe8Virustotal results 34.92% Heodo
2020-01-29List_2020_01_29_52421.docdoc 7e8c0e91d30b485bed7963d9d3169c243edb3f5f2ce5e8049df4731007ea4d61Virustotal results 32.26% Heodo
2020-01-29Arc_DM274806.docdoc d9e6778d130d18c51ae971d9b67674e2efc88e36d86b1d08e74ff54214d601d8Virustotal results 30.51% Heodo
2020-01-29List TU029.docdoc c0ebbfa695c1e2d054d32b340956dfffb4c155a4e420caaf593b0f1bbccbbd18Virustotal results 27.87% 
2020-01-29inf 2020_01_29 384134.docdoc 5ae7e30b55476614975a3dcc125e78cc5e84eb3a8c413ce9a42be9d99ed7150fVirustotal results 24.59% Heodo
2020-01-29Dat-20200129-95291.docdoc ec9b05ca4512e2e594339751e698ee57b1373c749a8c8b26cbe5c79dc1e978ccVirustotal results 26.98% Heodo
2020-01-29Rep_2020_01_29_ESI973.docdoc 49b8fd89ee5214a640b987bf72e14b9ef0ce65d9d14143e63ed55e8e8113f7fdVirustotal results 30.16% Heodo
2020-01-29List-20200129-SD532069.docdoc aad9025b37d955a0929dc76185e7b87d374e735e3a30a258bd549dcfc7a1bf27Virustotal results 26.98% Heodo
2020-01-29Inf-2020_01_29-29921.docdoc 4ce6a896a0567a69e25ea3254fe92c371b623f1c8b224dd077da760274fd4a95Virustotal results 25.81% Heodo
2020-01-29dat.docdoc 9e66ad03e7885710b534addc2f0c5637987970b3c6185b27cb42a4fcfa06dfc9Virustotal results 24.19% 
2020-01-29arc-05389.docdoc a1245dc00abc837e5b912c2aab2cc8eb34eb70db4bad71991edb4854fccadfb9Virustotal results 24.19% Heodo
2020-01-29Mes-2020_01_29.docdoc c2b2cd3b90f72db2fc325fdac1161626765153b7cb874ee42bea9fe3caf0eb6cVirustotal results 25.81% Heodo
2020-01-29rep_20200129_5806064.docdoc fb8b1e69574f8ec2121b612f1339a516d01536a2174f432585e94c98fba7ab8bVirustotal results 44.44% 
2020-01-29Mes 66425.docdoc b40831be7daa247208f2f37c223101e825eca3eaedbae7a72de040e21852ae00Virustotal results 42.86% Heodo
2020-01-29file_R778.docdoc 8c05cb88caacbc8eb0e4a1e79a0d1a707959b45fb39f5e694923b6b069ebce75Virustotal results 43.55% 
2020-01-29list 20200129 985.docdoc d0587297f7b5699b364592f59c0d93057b42defb42c714d6381d54a6142953edVirustotal results 44.44% Heodo
2020-01-29arc-20200129-BL514827.docdoc 26e9b52ab2150b5410b69fbb020642053c81b652e8c997a7bb304da089232cacVirustotal results 43.75% Heodo
2020-01-29INF_498969.docdoc 85359d87138be58de0c049e5c520f4de37adde9310893971769a0c640ba0a0fdVirustotal results 44.44% Heodo
2020-01-29MES-0931058.docdoc 99f4cbe6a9549c0dd8d99cdbee3c8ffe2c85d61f8a3cc94d1e57a962e4497be1Virustotal results 41.94% Heodo
2020-01-28DAT-3716642.docdoc 3184cbfa34c1ffcc3a308983dbff824aa454bb50b733e4cfd2cbb343030b9d6bVirustotal results 41.27% Heodo
2020-01-28Doc 2020_01_29 9193.docdoc f2a6a0283ff20ad3d0855ce7825d84920a0a27c55825a5a5b9ba91408388a402Virustotal results 41.94% Heodo
2020-01-28Inf-2020_01_28-G333714.docdoc 9a1962dfceb1a62ff349d932160c03ec9304954e3a0fb69e25b672fbef7b90b4Virustotal results 36.51% Heodo
2020-01-28REP-20200128-U686933.docdoc 4f0657b4834de2757799949da41f3ed5391b919f6539122e9dd06523c75df20bVirustotal results 36.51% Heodo
2020-01-28Dat_2020_01_28_FUV635.docdoc 76288b03aada28f313d41a8856e42320372dfc03b255335b3d8c0427cb01c4a1Virustotal results 31.75% Heodo
2020-01-28ARC-20200128-ADV302384.docdoc e973fec4c3e5b5f599c5defe0c00df33eae0e9b00f1f8a1d8f9479d4e343e446Virustotal results 25.00% 
2020-01-28Dat_2020_01_28_A89990.docdoc 59428bbec1459b7f3517f508013242a3dd7f4dbdee059380b5ff1c265abc6197Virustotal results 26.98% Heodo
2020-01-28Inf 746.docdoc 2fac5572f786da32ea0810309138075fa6d25b8fae0f0f92a0c7e539353ca05eVirustotal results 23.81% Heodo
2020-01-28MES-YD477.docdoc 45f4837dd3c4164db2df0fc600696eb225eff9a66e0dadffa9ff07c9f797a8e6Virustotal results 22.58% Heodo
2020-01-28FILE-2020_01_28-82659.docdoc 267aa23c9031b06e6dc7fac45daca30a65d4f08843fe0976c2ad7201d9646dafVirustotal results 28.57% Heodo
2020-01-28Arc 2020_01_28.docdoc e3ba2559956e5915407cc1fb85cbb6d4a50bfb9d028a5ba9dd33505953aa5ddbVirustotal results 29.03% Heodo
2020-01-28Inf_20200128_JSR07671.docdoc 1ac8d894b4e2be7cb2d7fc3dee2346677c5fdc5871be74589848518155c5ff8cVirustotal results 25.40% Heodo
2020-01-28ARC_2020_01_28_432.docdoc c5666d80df3d2361122568d511e336c58a58b27576a1cd78b434c425d8b2e809Virustotal results 22.58% Heodo
2020-01-28ARC 2020_01_28 UYD674752.docdoc 12934d2c01ab4c7e7639e04a3a27c545f2501b1f835fc9ab5ca4f1ba97c63e38n/a Heodo
2020-01-28Rep-20200128-R453138.docdoc 9cb664f1e4189925744979c21e305e2af11f98b2fedd6d32c4e3d5745b51ce07n/a 
2020-01-28File 2020_01_28 583.docdoc 61d0d2aa3f2b0af2db0d2e4037ac0753965f1d03e0231b17a3695337b66ddd79Virustotal results 40.32% Heodo
2020-01-28inf-ZUY6050.docdoc 33d3ef3b1fb0f8ed8ed87b487e184b207ff302b60481dac9da9487ca210247e9n/a Heodo
2020-01-28rep_KR764.docdoc 20cdcb97c92b8c58397ab1170823f96ce0db2c3e93d4859bd06fb23302687d30Virustotal results 41.27% Heodo
2020-01-28dat.docdoc f79992105131cff7dd4570db1648129b246323085d2843087e402a966d52503aVirustotal results 41.27% 
2020-01-28arc-20200128-486.docdoc 8cb18a21aef9805decc7d61eaa26ca10084c526c94d804dcf1c187edf63799d9Virustotal results 41.94% Heodo