URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ttuji.com/87/protected-sector/security-profile/DhCut-eNwm3xJG70tq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308419
URL: http://www.ttuji.com/87/protected-sector/security-profile/DhCut-eNwm3xJG70tq/
URL Status:Offline
Host: www.ttuji.com
Date added:2020-02-04 21:57:07 UTC
Last online:2020-02-12 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-04 21:58:02 UTC to ipas{at}cnnic[dot]cn)
Takedown time:7 days, 23 hours, 25 minutes Bad (down since 2020-02-12 21:23:39 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06Doc 2020_02_07.docmdoc ace007f793e2872353ded84bfb5b4a505dcb23fd2bc9772920797b48805d2a39Virustotal results 27.87% 
2020-02-06Dat 2020_02_07 P525536.rtfdoc a2f71346cd2d1bcea1a725f2bcd860a55fd65a096f8d8260b55ad45c5705e8d1Virustotal results 27.87% 
2020-02-06File.rtfdoc 903eadc1bcff1ede5e8a4887d539b907837b35b6ae79a1b7cd200ec455cee00fVirustotal results 27.42% Heodo
2020-02-06File C1115.docmdoc 0395137796e0f9fe7c273562138c7e5f0c988214841e6ed4cda2e3978a98f1bbVirustotal results 29.03% Heodo
2020-02-06Mes 2020_02_06 9221053.docdoc cddfbd7b249d0e0ebb3f68697690544c6abb69af1cb46f3b74c24cae2d3e528bVirustotal results 29.03% Heodo
2020-02-06Mes_7099504.docdoc 3e2e9332429ca46e97d6d5b2d39864b216599b31498ebda448a3fc2adfc78a0dVirustotal results 29.03% Heodo
2020-02-06Inf_20200206_TIL2969.rtfdoc 6518e632fa6ae2b5961ba05d77e16bbec58ffabe10c6f79557a2d1b48b2807a6Virustotal results 26.23% 
2020-02-06Dat 20200206 1245994.docmdoc f538db2aa0f3b0d5482fcdc4619de24a6f283718f78c5e1cea4ccb2c92b471c4Virustotal results 26.67% Heodo
2020-02-06DAT_XZ099.docdoc 20a0926fb970d58fb5681385d5b8bbc67f1abdfe2e240c721e1034857c14cb9aVirustotal results 24.14% Heodo
2020-02-06list.docdoc 186ad5a4edbbc67f97e4c4d0236f263ae46435a2687639dba2a0a91edd0d6ce5Virustotal results 22.95% Heodo
2020-02-06FILE-BNE5175.rtfdoc 426f5a4910e1d8c7973f947554016a2945b0997ec5d7bbf3756cef42d9dbbfa9Virustotal results 23.73% 
2020-02-06MES 20200206 92542.docmdoc 54d44a585a5b93e5478ad5ec770d9c665bee492e4f228946b91312637444ded4Virustotal results 22.58% 
2020-02-06File 20200206 537.docdoc 7fe4afe59b087bf542c67a12ac54ccb89eab281656477ed8bfc41ebab0e0135fVirustotal results 20.97% Heodo
2020-02-06mes-20200206-484.rtfdoc 5c3ce056d5c4c031e62f29306f27698d258d673ab890eaf2c2bd06487933aa00n/a Heodo
2020-02-06REP 20200206 56733.rtfdoc fa37e0cba4786db4ba847c2e4f9b4ee78aedbf0eea4491228705fc00980af4e8Virustotal results 32.79% 
2020-02-06INF-20200206-W86832.rtfdoc 346d01cf657414934f8c87af6f0ae07d23875f613db84e483f2174b6353ab405Virustotal results 33.33% 
2020-02-06Rep-20200206-WZN1684.docmdoc 43e38902740c39567550fd0e4c87c00947c5fe577765eb00051f0212c05d7cabVirustotal results 33.33% 
2020-02-06FILE_20200206_A0317.docmdoc 9e7490ea59c003826b03252f70bd3fc3a4c910d44aa5c1cf377a0cb24491118eVirustotal results 33.33% 
2020-02-06File_20200206_5776.docdoc 24bc1b322505611fc96f657f00be75ad4a096d02fc3e78d4b45369b13358575fVirustotal results 33.33% 
2020-02-06list_2020_02_06_82026.rtfdoc 408e410322052b154cc71d747cb64f2525be9909cc3046e32fd1aee7043266c0Virustotal results 33.33% 
2020-02-06dat-0763801.docdoc 58f94895848e841464a8b36d26e332a50e9b082bd7df37c1c054168929b7b34eVirustotal results 31.15% 
2020-02-05File-72270.docdoc 335e92129e141d12928fdc17fbb6c1dfe8b6fa59b2ff2a4ad0c60f4f0637ee83Virustotal results 27.42% Heodo
2020-02-05Arc-2020_02_06-064.docdoc 8f2fbc53d8f8bdf05da88e924c8a768a3553ca543aabe034572e0b0f2b38486aVirustotal results 26.67% Heodo
2020-02-05file_20200206_803234.docmdoc 85d825b74358c12b84824b2d46cf048e3dfe836a8c320d88d301331a46e62ec2Virustotal results 27.12% Heodo
2020-02-05Inf 175252.docdoc 1566745273aeac5249400c456f82b70e870825a50ee2457479f734c7686dfb54Virustotal results 26.23% 
2020-02-05Doc-20200205-B4831.rtfdoc 59dd4e381b291b460fa9a19705f59aa130ec42495f72ac9010d417197166b58cVirustotal results 26.23% Heodo
2020-02-05mes-20200205-0819156.docmdoc c0b9c90ce017a4e5196e744c7948464ff57431da4a1d820793c5aea57cc0a095n/a Heodo
2020-02-05mes-VG201484.docdoc da0b1e331a89bd28e4338a886d224c01e9194a764a6ded30bac8b16670a589b3Virustotal results 26.67% Heodo
2020-02-05Rep-20200205-705813.docdoc 20b603562ad65e466c27733e3ba8368c3ed83caeec165555f4a935ed0cc6d4b1Virustotal results 26.67% Heodo
2020-02-05mes_9505702.rtfdoc 1d71db32310de6088f008bda0c652b8a1715c3b98c549cfca90601bdc70c59a8Virustotal results 25.00% 
2020-02-05FILE 20200205 983.docmdoc ab556aef3f7baf74127e682541cd5bb674af38a62c4c1f89ff43f09388894af2Virustotal results 25.00% Heodo
2020-02-05rep_ZOI950.docmdoc e017e89646b0d091bc67504f4318ea078b5a279edd898f418ff735e40c432e28Virustotal results 25.00% Heodo
2020-02-05arc_PG08632.docdoc 4a45120dce1cd34a211f66e94d6a16a0e567d8aa85527c6fa830f99691cd1816Virustotal results 24.59% Heodo
2020-02-05INF 20200205.rtfdoc 4e82c0983f4287199416515585b3322785209242527d21f73fc1213fac0da816Virustotal results 25.00% Heodo
2020-02-05doc 2020_02_05 2301.rtfdoc add57fd6782c427fbdbab1e52f313746c594f78a352135f6961c6e7d3d9ea2f6Virustotal results 24.59% Heodo
2020-02-05arc-20200205-826621.rtfdoc 8da9b64f05685802f69618feda838a3f4331363e5e7ad48cc004353b8a4dac2cVirustotal results 25.00% Heodo
2020-02-05MES_20200205_136.rtfdocx 3002799efe2f36491f41e0c5e350a6c6ae06bdc8fbef3c1ddf753c6c2e206736n/a 
2020-02-05MES-2020_02_05-1490130.docmdocx 3c0292963e5af1dfc8aa14b1b0408c3d3e0873fde4dd75962bd380b5aa67eb36Virustotal results 34.92% 
2020-02-05inf-061.docdoc e96b3b96851ad8f49fa155f44b5dad11bedded8a6c96898fa814e872822f3eecVirustotal results 35.48% Heodo
2020-02-05Dat_453627.rtfdocx a464fbbd0fd6eb2e09bb5c04dd46379d3cf1c4f67eeb3f4e9f0b9f7896a2192fn/a Heodo
2020-02-05MES-2020_02_05.docdoc ab25cd8065a0df8608fcd69bd29689ae7657b263b8290a459052ff0cfcac3951Virustotal results 30.65% Heodo
2020-02-05FILE-2020_02_05-D096174.rtfdocx c88c5193f9ffea07709eeb7dbe053ec079f2a2d4f142fd26ca76ed7f55c6e6abVirustotal results 30.16% Heodo
2020-02-04LIST-20200205-7568.docmdocx f2d5330b5aa423a1c21c6f960154447080fb0b6a7747307519ce8d57a310d1a0Virustotal results 29.69% Heodo
2020-02-04mes.rtfdocx ec4146a69e81f690514da6199f759c184964dbe031f6ca7850b4af5d0d365150Virustotal results 34.43% 
2020-02-04arc 20200205 FXQ79094.rtfdocx 3e807f7cb48c71df4ce8ba0a0024238ec14712f1e68e7d0c959ab376f2fbd524Virustotal results 32.81% Heodo