URLhaus Database

You are currently viewing the URLhaus database entry for http://intranet.utrng.edu.mx/actualizar-front/common_zone/close_618847054_oBIuus0FEN8/288387031425_6iJ9c2PRgC8c/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300348
URL: http://intranet.utrng.edu.mx/actualizar-front/common_zone/close_618847054_oBIuus0FEN8/288387031425_6iJ9c2PRgC8c/
URL Status:Offline
Host: intranet.utrng.edu.mx
Date added:2020-01-28 19:58:20 UTC
Last online:2020-04-13 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 20:34:03 UTC to abuse{at}uninet[dot]net[dot]mx)
Takedown time:2 months, 15 days, 8 hours, 33 minutes Bad (down since 2020-04-13 05:07:03 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-30DAT-2020_01_30-86936.docdoc 2c685c8ff0a8e26d07febbe64029b1fbb7e69915b034cd003beaec0dad1256b1Virustotal results 34.92%Heodo
2020-01-30rep 20200130 807.docdoc 88d2169711b161c4ef3ad2a293d5d31f96681e8341468acf5a7d8f77296a0649Virustotal results 39.68% 
2020-01-30List-RB47594.docdoc 6edd33f15c012fa0a5a49cc0ffa73234c8c178849d41a7b60cececefd9c852dcVirustotal results 38.10% 
2020-01-30Rep-BRJ742.docdoc 2b5bdd3bfb73fa7e1bd1b322c377a0ffd4386f783c6658748a15a25679b09b51Virustotal results 38.10% Heodo
2020-01-30INF 20200130 61596.docdoc 4bcb5f3bc2310560505835c95ebf2173c58ca2d1f0e50139bc2d8141b4b6510dVirustotal results 34.92% Heodo
2020-01-30list_20200130_VDW1515.docdoc 27e174efb0d6e8b05cf666fd50c3163d91cd9bc9416197af58f70c1f027d2a0eVirustotal results 32.81% 
2020-01-30Rep-H6063.docdoc 2d865b1d71a6827ca4eb3b7f884d08cc2acbcea2e862ce53a15cea4128959e8cVirustotal results 30.16% Heodo
2020-01-30rep-2020_01_30-58241.docdoc 767b17c9708aa05e3d52db97aa2842a873f2cf8e9d75f19e3e8c84fd32442e32Virustotal results 25.00% Heodo
2020-01-30Inf_2020_01_30_OB38108.docdoc 7099bcda5f0b4caadc077f6bc794a4dc8933e66863535f49c23c8b19ec793b7fVirustotal results 28.57% Heodo
2020-01-30LIST_2020_01_30_CB3587.docdoc 6926bc1e1548f432acb621ea14a0a04189aacc9b0d3730cc275ea5be5ab2ddf7Virustotal results 28.57% Heodo
2020-01-30LIST-20200130-599201.docdoc 093fe06865cc5cd449e9684d621efaf181505881f5e0e818b0ec9c4459ef1ba9Virustotal results 22.95% Heodo
2020-01-30Mes.docdoc ded73d524fe7544ecb69b5779a5bddbef01386b55ac338c83fb4d25d31745584Virustotal results 25.00%Heodo
2020-01-30file 20200130 JXK739973.docdoc cbfd00a796bdd447134f7dc1f38823e8e2eefb7075068cc197ec67c044ecfc24Virustotal results 24.19% Heodo
2020-01-29Arc_2020_01_30.docdoc 0c899fbd963450fdf0d3d487fd91c0ef00e8c4191115d99d58a6b75476b06254Virustotal results 22.58%Heodo
2020-01-29Arc_598703.docdoc 2c7a2ffff7a4a2fcb7a86235dafda3b02ce67330155e00a22408d6c14b2f5cafVirustotal results 40.32% 
2020-01-29Doc.docdoc e49d66744b97eaa47dae870c0fdd5f6b3a52e1b2245e8567ffa6b8a344663fe8Virustotal results 34.92% Heodo
2020-01-29inf 20200129 D9067.docdoc 49e28f382793143c68d57be83f8e7252dea8674a30f06b9063dd9ccfc4f25e85Virustotal results 33.33% Heodo
2020-01-29DAT_46449.docdoc 93e6b158ccceb81017a551ff0ede39622381a6ee79e572a206f2756b342a47fbVirustotal results 28.57% Heodo
2020-01-29Arc_CA24564.docdoc b09c8d39fe17d600ac2beffd9540076f55d944b41ae3c11b26600252a272b3ecVirustotal results 26.98% Heodo
2020-01-29rep_B6273.docdoc a6f8d6e5f80b47b55146e82c61a78c5ed8c451bcb68d157dee574d02c768ba30Virustotal results 26.56% Heodo
2020-01-29INF-2020_01_29-GW341.docdoc 41f2df35fe03375e39b939c95142a9c04e1613e60bcdeb4f50ea339349d04243Virustotal results 26.98% Heodo
2020-01-29Rep_2020_01_29_2209.docdoc a570252bf1c2fa10675c88c55f9ef2362c2c7d3ac6e6bc1400102a49f2aac861Virustotal results 27.87% Heodo
2020-01-29MES-VC757507.docdoc 02e02e6f3d5f2447a5269982bfa0714b129e54897d7616443ca03430d0a3188bVirustotal results 25.81% Heodo
2020-01-29Doc-2020_01_29-65201.docdoc 8c178af12cf53e214a99e4c9125f73724ad6029bfb2e095b3c6257cb3a25109cVirustotal results 27.12% Heodo
2020-01-29doc_20200129_267419.docdoc 9e66ad03e7885710b534addc2f0c5637987970b3c6185b27cb42a4fcfa06dfc9Virustotal results 24.19% 
2020-01-29dat 20200129.docdoc a1245dc00abc837e5b912c2aab2cc8eb34eb70db4bad71991edb4854fccadfb9Virustotal results 24.19% Heodo
2020-01-29Mes_608145.docdoc 7c22eab322ac6b786498c54df9abb223c3466203f681028b1023147f081fd6caVirustotal results 24.19% Heodo
2020-01-29LIST-2020_01_29.docdoc d6548725e281a6fac0ace4af505c15a21b8e1582ab951ad62e29dc42cae45885Virustotal results 43.75% Heodo
2020-01-29dat_30543.docdoc b7cb7ac3c2e6b877b9893ed5651e3dfe2937135d7a2bc612ee70c3abf4a8d654n/a Heodo
2020-01-29INF 20200129 LU895.docdoc f5c5c5efd56a06272577f6aa8fde6fe22660095ec9332d7449f3e0769fa11b8eVirustotal results 42.86% Heodo
2020-01-29mes_20200129_118.docdoc 6a23106b558df36e6d88bb5b5dd187430087eff0c8a2ca1586f8538e8259e01dn/a Heodo
2020-01-29Doc-2020_01_29-R95907.docdoc 5ed01ecc76724ef8dff654d4ef2b359c600c6dd3da2481677304b851d0c752b7Virustotal results 43.75% Heodo
2020-01-29FILE_513216.docdoc 85359d87138be58de0c049e5c520f4de37adde9310893971769a0c640ba0a0fdVirustotal results 44.44% Heodo
2020-01-29rep 20200129 04003.docdoc 705a21a458e18ec2353f1141cd6971cd6ffe76398c6c0bffea9c4f3e2c370c87Virustotal results 39.68% Heodo
2020-01-28file_20200129_603.docdoc 522de927311fdb0ba76d51ac880c13fa8dce461eec5a120570a58e27fc82fa06Virustotal results 41.27% Heodo
2020-01-28dat-206458.docdoc 20f6d17240c7bfbee9f9691efd1bef583201bfdddc09ab886887cf5d4993773dVirustotal results 41.94% Heodo
2020-01-28Mes_20200128_19292.docdoc d92bc4efa28b232e6331a4e9b5f75992659ad3e64268f5adac60ea14f9932f5dVirustotal results 36.51% Heodo