URLhaus Database

You are currently viewing the URLhaus database entry for http://nhuusr.nhu.edu.tw/css/protected_2331283301523_pl9L1TGn5k4k18XQ/zpmcwey_qb8sp7ns6qq0g_cloud/71dbkxae9srv77d_89220z20377yut/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:301931
URL: http://nhuusr.nhu.edu.tw/css/protected_2331283301523_pl9L1TGn5k4k18XQ/zpmcwey_qb8sp7ns6qq0g_cloud/71dbkxae9srv77d_89220z20377yut/
URL Status:Offline
Host: nhuusr.nhu.edu.tw
Date added:2020-01-29 22:07:07 UTC
Last online:2020-02-04 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-29 22:08:05 UTC to hostmaster{at}twnic[dot]net[dot]tw)
Takedown time:5 days, 15 hours, 18 minutes Bad (down since 2020-02-04 13:26:13 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31arc-20200201-W2653.docdoc 330f7be161fda368ebf4eaf133ceafc6116a52b8546523b6b91efd725393cc8aVirustotal results 32.26% Heodo
2020-01-31rep-20200201-322172.docdoc 11719e43c0400c0e599a1d1a217da8178b2c7d62f66262fef88cffdd100c5246Virustotal results 31.75% Heodo
2020-01-31Arc G117.docdoc 786338c65b78c5ba2c61da98f185fd1ea8efa6d26cdce817ebd143cdbf5aa79eVirustotal results 32.26% Heodo
2020-01-31Dat_2020_01_31_541.docdoc 7751baa036a3377751c1d23c593f017114859e8b8285f6ea41fde8d82e19be57Virustotal results 34.38% Heodo
2020-01-31MES-20200131-VBR619.docdoc 1bbba6556de9b7552cfe85621ad8905c44d0a59782a9db60bec73e07847e7767Virustotal results 31.25% Heodo
2020-01-31inf-20200131-164.docdoc 31ad07da3bccaaebc18676212e40fcd30a280ae55fd101eb55e89302c9532580Virustotal results 26.98% Heodo
2020-01-31Doc-20200131-501032.docdoc 075d1f5b7944bb5b788d8b9036b9ade54bf6cda3e8d6809c6846900039d90e18Virustotal results 25.00% Heodo
2020-01-31mes-20200131-KT07746.docdoc 98d4100547490c9809f92a82a3afc57c4927ce1e84664bad304d005b9754a02fVirustotal results 20.63% Heodo
2020-01-31Arc-J9595.docdoc 5d3c3461c678241da390d525ded034273d14a57ccd4d0169627f753fcc9fd91aVirustotal results 20.97% Heodo
2020-01-31file_5155751.docdoc 691d17ec9d017071172822819531217285cc8e76d799f1db55410a3212d81586Virustotal results 20.31% 
2020-01-31ARC-20200131-956.docdoc db228ded279197fb7ce5217f5acbe468bb95de701e9ad48bf751e1025b5f71c3Virustotal results 20.63% 
2020-01-31file_0725766.docdoc 8cc142a77c13d730954666978d567d01fcdd588eee8d825d12b6b642b2212426Virustotal results 20.31% Heodo
2020-01-31list 20200131 RDA0880.docdoc 95c8cf64216794e220da4ea2be433e97ba4e1ff99696be784f418e8bd023c313Virustotal results 20.63% Heodo
2020-01-31Rep-20200131-3418.docdoc 43582ceb15e33fde13dc6eb4d0b6785e2747e73114a7d1fccc032ab32b4a6e7cVirustotal results 20.63% Heodo
2020-01-31Mes 51939.docdoc 479acd550fee84ce07d46ca359554323d14b0874e9402267f9f6cedc7ea64065Virustotal results 20.31% Heodo
2020-01-31Inf_2020_01_31_JL167316.docdoc 6fd2e08f2dde33eac79877702712cc2d0e58ce9acd50807a6393b64bef1cc2f1Virustotal results 40.32% Heodo
2020-01-31file 20200131 E8617.docdoc dd7ae3bc161b941e8ee4831dd583f504907c07c32c1d64d330d1f08e2030707aVirustotal results 39.68% Heodo
2020-01-31File.docdoc cbc9edb78b6f27bf631b12f4f66cda0b48a2e5dfef8389d8be55802cfae8e99dVirustotal results 38.71% Heodo
2020-01-31List-2020_01_31-153.docdoc 6fd53c9b4fa1bcdf1ef2a095d2af6db48d7d4034e1d5c9e32b23c12853ab6c10Virustotal results 35.48% Heodo
2020-01-31FILE_2020_01_31_9596.docdoc 02d4150ccb8c0569ecd99cc1a860f5c711f1cd2ba567aa5728b830b9f1789f46Virustotal results 33.33% Heodo
2020-01-31Arc_2020_01_31_705803.docdoc 8ac6cda8c7b4094b736c508bc231f782f410a72cecec097edb943014ce610585Virustotal results 33.87% 
2020-01-30File 20200131.docdoc 38ed0185799cc1cb1e2fcfea1f554229ad2ddee7695a8eee704426cf83a6b7e6Virustotal results 33.33% Heodo
2020-01-30Mes 1253508.docdoc 710bca7eb8f1b38ff3ff591ffce42780c42d513d5db8e8edbed62b2a30a41145Virustotal results 33.87% 
2020-01-30Arc-ADQ373.docdoc 5d669f3035b344006960d92b8e182bc4805b2f45783fc1393e39b27498e25cbaVirustotal results 34.92% Heodo
2020-01-30DAT 934031.docdoc 72b6ec3c1e924a2f6b1bbf4f5359a7dff2c8d0cd96062fa882119a929ff9b6faVirustotal results 33.33% Heodo
2020-01-30file-20200130-YD536.docdoc 88d2169711b161c4ef3ad2a293d5d31f96681e8341468acf5a7d8f77296a0649Virustotal results 39.68% 
2020-01-30Doc_20200130_NHA7486.docdoc 754cbbb7ddc67e1475afc52e76a09e3c2f2caf788795fec9c7859e82dc81d9e6Virustotal results 38.71% Heodo
2020-01-30Rep 887825.docdoc 8f4a6501b7d0a50fd6e8efa50f1eb0cf68d343cd44f5e4b28c47fd843d56fe6fVirustotal results 37.10% Heodo
2020-01-30doc_2020_01_30_MPN298933.docdoc 11078ef33eb1bccdd13fee326af0b5a51e5d9bfb1335c25004cf281c01ccfdc3Virustotal results 37.93% Heodo
2020-01-30Inf_20200130_HL3035.docdoc 33bff75b0b0477fe5ebb1baa53a6e72f2c569227d8ab61eddac59592d02d28faVirustotal results 32.26% Heodo
2020-01-30List_KEX444.docdoc 2d865b1d71a6827ca4eb3b7f884d08cc2acbcea2e862ce53a15cea4128959e8cVirustotal results 30.16% Heodo
2020-01-30FILE 2020_01_30.docdoc 8fccb53dc5d9058d11d344f7fbd34609642b1b1d2a9e4699134d165ce6ab21a0Virustotal results 25.40% 
2020-01-30doc-20200130-F871.docdoc ddf014e6d9e70bc1709c2ccde24524fc72092f929ea37df901ee88f152ae4c43n/a Heodo
2020-01-30Rep 2020_01_30 817407.docdoc 6926bc1e1548f432acb621ea14a0a04189aacc9b0d3730cc275ea5be5ab2ddf7n/a Heodo
2020-01-30inf 2020_01_30 SMY270800.docdoc 1db0c100dfea192f88767bedda9beef583fcfb5c7797f32d7f93dcf045d3239cVirustotal results 25.40% Heodo
2020-01-30MES.docdoc 05540ab9749b214e8557c647443d6b4f997326d9e3ec01cf69b855c519c53887Virustotal results 25.40% Heodo
2020-01-30FILE_YDQ529550.docdoc cbfd00a796bdd447134f7dc1f38823e8e2eefb7075068cc197ec67c044ecfc24Virustotal results 24.19% Heodo
2020-01-29arc_567390.docdoc 0c899fbd963450fdf0d3d487fd91c0ef00e8c4191115d99d58a6b75476b06254Virustotal results 22.58%Heodo
2020-01-29DAT 20200130 KXK715.docdoc f3e0ea1e9f70b58a16ab7b737be16e81a1868a88fcdd4de0c1fb6c4a3aa6b3b9Virustotal results 40.32% Heodo