URLhaus Database

You are currently viewing the URLhaus database entry for https://uml.uz/administrator/abierto_22337803723_7FsFKyYFLnvEjeyE/close_warehouse/963596_tKBqBJZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:306650
URL: https://uml.uz/administrator/abierto_22337803723_7FsFKyYFLnvEjeyE/close_warehouse/963596_tKBqBJZ/
URL Status:Offline
Host: uml.uz
Date added:2020-02-03 10:27:34 UTC
Last online:2020-02-05 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-03 10:28:02 UTC to admin{at}tps[dot]uz)
Takedown time:1 day, 20 hours, 47 minutes Poor (down since 2020-02-05 07:15:19 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-05FACT 02_05_2020-966855738419.docdoc 49935d065197043a5954f5c0af2fde686f0dc8e83a648ca5377b249246310ddeVirustotal results 36.07% Heodo
2020-02-05fct 47849476198.docdoc 87b1933c9a37e955daf97fd9640da17cde0f579c30a655b8d1af0fcf8ecfb7cfVirustotal results 36.51% Heodo
2020-02-05FACT 01789572-4701319.rtfdocx e96b3b96851ad8f49fa155f44b5dad11bedded8a6c96898fa814e872822f3eecVirustotal results 35.48% Heodo
2020-02-05FCT_02052020.rtfdocx dcdcefae226e1eccadad30728bc5d5a86fcc042676c0e98078e62ccd82b564d2Virustotal results 33.87% Heodo
2020-02-05FACTURA 02052020.rtfdocx a25acb77ff59454781d30445e527d286c6b22fb2040cc8e0c0ae31e14c603e5eVirustotal results 30.65% 
2020-02-05FACTURA 02052020.rtfdocx 0eeaeab309fee32e71f3c9e221e6583285eac868bd06ee8bd594d06621c97e16Virustotal results 30.65% Heodo
2020-02-04facturacion-02_05_2020-HF982377620.rtfdocx 6464ea34b63546f7d2cdcb780b772b1250731bd38c105c2feb70e0928d49b1abVirustotal results 32.20% 
2020-02-04fct_X198588 5366536357.docmdocx 3e807f7cb48c71df4ce8ba0a0024238ec14712f1e68e7d0c959ab376f2fbd524Virustotal results 32.76% Heodo
2020-02-04factura-L078013_89439.docdoc 03657e4b0103d718978b4736846da1ebdd18f8ba892ff4709eabbae4d7f14c10Virustotal results 32.81% Heodo
2020-02-04FACT-02_04_2020_7532210.rtfdocx 226e3d9397801a0c20fc12e65373887d6b8e32d5d47ea818a8b891be4513e330Virustotal results 33.87% Heodo
2020-02-04FACT US0632314530.docmdocx b652230d0ab5eba2fd05573b7ef10013f6563c1bb9f64d5f5106b15cc8a5ade7Virustotal results 31.75% Heodo
2020-02-04FACTURA-02042020.rtfdocx 265e4a2697fbfecc43edb76419d9e4a8928492d01b548cd7d6804226d6b2a593Virustotal results 37.10% 
2020-02-04Factura-q77m0460886p8n.docdoc 786563efb876e891aa804967d96e0a176417ad2c731e93a1fd788cc7d15d57a7Virustotal results 37.70% 
2020-02-04FACTURA-K0186431284834.rtfdocx bcd2e7bff910e30d17d51c87683d5d167b62abe697d788a5e188ecc0aa3e938cVirustotal results 37.10% Heodo
2020-02-04facturacion 02042020.docdoc eae488ffdb03ebc22a57d1d52d7800cd8353390239b1572d79632416250516b0Virustotal results 37.10% Heodo
2020-02-04factura 02_04_2020_42609447691.rtfdocx 4797cddac2f4b88206c147e98842f78fb081f26db474df81a02a7a05c59865beVirustotal results 35.48% 
2020-02-04FACTURA-02_04_2020 333982577529.docdoc 3e2e9a5442d6c6826dad3dd23433234eb8d095c3ee6f0cde53e92e675e6f8822Virustotal results 36.67% Heodo
2020-02-04factura-n40q6n6.rtfdocx cf2fa78d90fcfab9100f273c1e9ffe890840d22f6a0dad51aafde1684d179222Virustotal results 34.92% 
2020-02-04Factura-559689889856.docmdocx 984f78a258a00908226548dffffe34e73ede38e1eeab45004cbab8430d705c71Virustotal results 34.92% Heodo
2020-02-04FACT-02042020.docmdocx 29d71c405f029109b5b6a5eb51f5f957a706b5130105c3abd7e3e97cccc66c2dVirustotal results 36.67% Heodo
2020-02-04factura 6q3m929om862no.rtfdocx 858ee445063f1b88571bdab7e35dd7dcd5a6d9eee82259333dc76b277a2c4c81Virustotal results 33.33% 
2020-02-04FCT_2006m8o075890.rtfdocx 3df4c20b912377bb69db29aaf085b27d9eadd660678c6c0d113a502c36257532Virustotal results 33.33% Heodo
2020-02-04fct_580792816.docdoc 7769ae1cce4e29c3e8bd982600d46a07804c1f66a2772bf00ea100aa24c227baVirustotal results 40.68% Heodo
2020-02-04FCT-D0738024996.docdoc 06ef3b76fdfb2eccd0a672a1023ffeff68a0dea6d2a4da527eaa596842391fc1Virustotal results 38.10% Heodo
2020-02-04Factura O2639572606.docdoc 4760951e633f0cb7a23dac2e021ba1199b4d4fdb92ab2cfe0d5a1d3c87d80405Virustotal results 38.10% Heodo
2020-02-04FACTURA-02042020.docdoc 735d5dfcf2fcda1f728db7a6dab5f4e4f8ac7acaa668c41f55bf7fca5a58beb2Virustotal results 38.10% 
2020-02-04Factura-11538.docdoc 3331178cb99b81f405f5cd9f9856d581a217dd6b65ebf3746cb823d38d2df988Virustotal results 35.94% Heodo
2020-02-04FCT-R01270540623.docdoc 133d966b980eb291760a47d0e9344a2900a4917c5983c098292115d55f6c8bc4Virustotal results 36.51% Heodo
2020-02-04factura-02_04_2020 07G3338.docdoc aa3931cb2f3ab736b14ffab1da3e306231e5ca42842da644913c4ba7ed5730b2Virustotal results 35.48% 
2020-02-04Factura_8pm529om0.docdoc 96ca41fe85593ec2adee71cbe9ddeae3c084689d3bd049ba0b3a548895583c11Virustotal results 33.87% Heodo
2020-02-03FACT_8mo0m6.docdoc f1ca3ac8b29ff318670eb9fec48430c20bfd5c159a0e78ea322110f711f0b3caVirustotal results 32.26% Heodo
2020-02-03Factura-775368971376.docdoc d48d382a360c44f8990a525f7ee79c00056b9091d438e3d641396d8353374bben/a Heodo
2020-02-03Factura-74q9pnq909.docdoc 638b50da8c574f4785910dca412d1afe1520c754d676c4f8838455d0de5d637cVirustotal results 32.26% 
2020-02-03FACTURA-n994082p4636.docdoc a76a7c2029ae2435701beb379d26d8d9d8d033af5dc49715a117b071173d4da0Virustotal results 32.26% 
2020-02-03fct_02032020.docdoc 07203376cb50ab736270e81db3c3c4503371a701b5015e88407c407326388750Virustotal results 31.75% Heodo
2020-02-03factura 02_03_2020-2H8804.docdoc 5f570674404dafed0028b479c8a05c8d21186b07e803f2837cc21ed2e4708139Virustotal results 31.75% Heodo
2020-02-03factura_ZKF8212411.docdoc 9681ccc3cf58b12d30d0c4be40f0de86eaa804c3f72922a4e654956134e1b831Virustotal results 31.75% Heodo
2020-02-03FCT-81396.docdoc 0768e6328bee4367126b667fb15ade01f9437381461015bc3b02ab3f79331e92Virustotal results 31.75% Heodo
2020-02-03FACT 02_03_2020-E02268.docdoc d33c0e00439f2ef24087636b3317355dee8eb2fa050ec652a5b795c996bb9b03Virustotal results 29.03% Heodo
2020-02-03Factura_73n52o68n8n6q.docdoc c395f4d101a2ad5ed466a19426a403517c2bdc222651eaa30a43f69f4018b239Virustotal results 30.16% 
2020-02-03Factura 309128255-085589420743.docdoc 1ed54620b27cd872b7110c4c93c0f9bc5838419fa980138fc9042bea2d2d08e0Virustotal results 30.65% Heodo
2020-02-03Factura-ZY24424_7464.docdoc 04c71248d275d113a2bf8b63c91e522a80a9d12f0f286af5eff747ef1c11e06bVirustotal results 30.00% Heodo
2020-02-03FACTURA 26681110176.docdoc b350f7f6eb277e32c26a9994eb507eb2b92c8c366e1be83ae4b92c4686ba345cn/a Heodo
2020-02-03facturacion_1q2mnq.docdoc 7e135018b258b8d97df56af993510521df69921fcf3e6e35693376bae8aa399bn/a Heodo