URLhaus Database

You are currently viewing the URLhaus database entry for http://bitsnchips.com/ar_html/available_nt64pdh_aquatf9/test_htALx_ePrLdQpC0Qqz3r/3ibkmyirj3_1zxx321344/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308964
URL: http://bitsnchips.com/ar_html/available_nt64pdh_aquatf9/test_htALx_ePrLdQpC0Qqz3r/3ibkmyirj3_1zxx321344/
URL Status:Offline
Host: bitsnchips.com
Date added:2020-02-05 11:39:34 UTC
Last online:2020-03-21 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-05 11:40:03 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:1 month, 15 days, 5 hours, 36 minutes Bad (down since 2020-03-21 17:16:19 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-22mes-2020_02_07-1092.docdoc 474e2fbd1c5c0c5381cca8120950c3c5e97e874d8ca46d6645807e16f09658c8n/a 
2020-02-07mes-2020_02_07-1092.docdoc 44bd3ad6d45806c1680a529ef5a2c4f23cd33ec47c954735261d55218c9ac024Virustotal results 24.19% Heodo
2020-02-07File-C74334.docmdoc 5a4fc3c23be16cff577a8b9af743cdfc330a1a3a8efea386690c226398d246ceVirustotal results 25.00% Heodo
2020-02-07Doc-2020_02_07-E255067.docmdoc e3adf368b634569aa1ca2545bb340ffb5df4c918cf629e3afec00b6f43d444fcVirustotal results 24.19% Heodo
2020-02-07REP_2020_02_07_MB741.rtfdoc 8f3a0e19e00397efb39708dacfd129d2722146fa6d169e6a7c601c0cc02a1359Virustotal results 24.19% Heodo
2020-02-07INF_2020_02_07_LB66439.docdoc 006766d9879f75d74de2c385ce8418fb838989af2046d8d329ad6ae7dc6d26ebn/a 
2020-02-07DAT 20200207.rtfdoc 88d2e0f1e728a7142e0fa0f277f4020c91bb5e4222ccfd8162d9e0b6beb60e5aVirustotal results 43.55% 
2020-02-07dat OZY0529.rtfdoc 60a2db35f6a200f89387811492bf70f40551c72578c80be36bc21dc7abbcce67Virustotal results 43.55% 
2020-02-07File_20200207_BEL5255.docdoc d562f29bea1e4d4bc55ba156a65431f8a2cff0ee1dc9a10e774b53ac61d8b82cVirustotal results 42.62% 
2020-02-07List-20200207-UWG1375.docmdoc dda86e610dc7cd7c6dc32877c7933dc7c341e6e57f35219c82c674fb4f85f7b4Virustotal results 35.48% Heodo
2020-02-07dat_20200207_95979.rtfdoc 4de743bb5a807944570907fec4e4ca12efe2016c5c50e04f718ed117b26a76eeVirustotal results 32.79% 
2020-02-07Inf-20200207-066929.rtfdoc 92b8d8f3f3a3e0ad2e5f751cc4b2df9f4d01027617eedbc44823360bdcf35491Virustotal results 30.65% 
2020-02-06LIST_0643.docmdoc 2ab5454468bf092401bb674e12f9577b0102b97450e07cc6ffdbaec61eb40953Virustotal results 29.03% Heodo
2020-02-06list Q88522.docmdoc ac7760c7ac85f9e8058a9af1862e8b503ba18efe9bf1ebfc820845a33714ea8aVirustotal results 29.51% Heodo
2020-02-06LIST 20200207 506.docdoc 76ed65f4166ab70a504fa0c58b5fa4d5afbbdf92c3b7770185b137ac87aa37edVirustotal results 29.03% 
2020-02-06file 2020_02_07.docmdoc b6a866cd6767e85ce9779e18601e4ff38f6a25e8bf459d47936489b9d58ba9c9Virustotal results 27.42% 
2020-02-06Arc 20200206 058681.docmdoc 69caf04e8e1e56614bea23015c10066190147415d1c1699accdc79c49531cedbVirustotal results 29.03% Heodo
2020-02-06Arc 2020_02_06 118.rtfdoc e62205f9ad8ce110e6f628a4622e7f12d9db3b4c2cc100e1d464b06f2a2b0afbn/a Heodo
2020-02-06MES_2020_02_06_ZAM370.docdoc 43f10fe26a0ef0775cf82202ccdb01f65cd38e6aab4086fa49b4b2391da9f0a8Virustotal results 29.51% Heodo
2020-02-06rep 32230.rtfdoc 00810a12662ed1714ce797c700855a606ab35c246a1c1a2ada47b503d612a82dn/a 
2020-02-06Mes_ZRE495397.rtfdoc e2242f427a47cdd239a61505c64bb7956f2c451a95ae9dfcf44f845fafeab46aVirustotal results 25.81% Heodo
2020-02-06FILE 631.docmdoc 4648b2033b6b4ad3c5ed18b2f671ffcd7946daa96f301e47b75471b658483be2n/a Heodo
2020-02-06Mes_11598.docmdoc a2a0d4396733a29e832691fef191647fea4230db515ac8274376ac423becb5f0n/a Heodo
2020-02-06FILE-2020_02_06-D7635.docdoc b99125a74c2d36d2875478ee03096a69ad74f272c1ced98d2e22ea0f2a3d3191Virustotal results 22.95% 
2020-02-06MES-2020_02_06-RC45599.docdoc 5c65f21a3869e1e15433c2263d8dff3827f622520c972b12f4686250b8e68018Virustotal results 23.33% Heodo
2020-02-06Mes 2020_02_06 DF4935.rtfdoc 6359275fa65b551a691c324e03fa5c3c73ace835ca4f3d90087dc3332f76ececVirustotal results 22.58% 
2020-02-06INF_20200206_P17398.docdoc d0ba1020328bfa59129c6d94b6bfd8979bd652574b24407bcfdadc75fcf28fb4n/a 
2020-02-06DAT_2020_02_06_EMM02864.docdoc 7713e180e8a62f6041738a796b29f6efeab8431f8b6425016a4242f64df7061aVirustotal results 20.00% Heodo
2020-02-06MES_20200206_UYM715491.rtfdoc fa37e0cba4786db4ba847c2e4f9b4ee78aedbf0eea4491228705fc00980af4e8Virustotal results 32.79% 
2020-02-06Arc-20200206-0060000.docmdoc c7662c41a76803dcb646c8d920e316033baf7eaeda42b42305d4bab1a3a49fbeVirustotal results 33.33% Heodo
2020-02-06List 216.rtfdoc 43e38902740c39567550fd0e4c87c00947c5fe577765eb00051f0212c05d7cabVirustotal results 33.33% 
2020-02-06rep-2020_02_06-K03057.docdoc 9e7490ea59c003826b03252f70bd3fc3a4c910d44aa5c1cf377a0cb24491118eVirustotal results 33.33% 
2020-02-06rep_4779789.docmdoc 9005832cf404bc1202dcad8865b5250a9826f2fa18a6e23ee0a7e705c1d63ab0Virustotal results 33.33% 
2020-02-06Inf 20200206 MG062639.docdoc 74491fc6dd7ba85729f150a091baf5019a4a9cfcfa8e7bb6d450c9edf7762fb3Virustotal results 32.79% 
2020-02-06LIST 20200206 JH343661.rtfdoc 58f94895848e841464a8b36d26e332a50e9b082bd7df37c1c054168929b7b34eVirustotal results 31.15% 
2020-02-05Doc 144.rtfdoc 335e92129e141d12928fdc17fbb6c1dfe8b6fa59b2ff2a4ad0c60f4f0637ee83Virustotal results 27.42% Heodo
2020-02-05Rep EG039.rtfdoc 1ff329d123574f88d28f8fa9b93d185f2e70000a4bc1a630ee58c293b6d365f5Virustotal results 26.67% Heodo
2020-02-05REP 2020_02_05 69769.docdoc d71b1f1fe58257b5ea9344fec17f59a7440eb0cdc62052dc2410c7207923fe2dn/a 
2020-02-05REP 2020_02_05.docmdoc 79b3a51440b181671112045cb234739a360169bc4c6ccdb30a3907a50a055963Virustotal results 26.67% 
2020-02-05DAT_H5484.docdoc c0b9c90ce017a4e5196e744c7948464ff57431da4a1d820793c5aea57cc0a095n/a Heodo
2020-02-05rep 20200205 6517.rtfdoc da0b1e331a89bd28e4338a886d224c01e9194a764a6ded30bac8b16670a589b3Virustotal results 26.67% Heodo
2020-02-05Inf-623688.docdoc 4bda34084014e21ceb2db8fb9003f36f4b3a7bd5a8bcfb9b1badbf13529a6d84Virustotal results 26.67% Heodo
2020-02-05LIST_2041.rtfdoc 1d71db32310de6088f008bda0c652b8a1715c3b98c549cfca90601bdc70c59a8Virustotal results 25.00% 
2020-02-05mes-54373.rtfdoc 6228be42f808ff1c2d59dc6df839b24c07a9e9640fffea33d21e69f3b2765a69n/a Heodo
2020-02-05list-20200205-3345611.rtfdoc e017e89646b0d091bc67504f4318ea078b5a279edd898f418ff735e40c432e28Virustotal results 25.00% Heodo
2020-02-05LIST 2020_02_05 DQ2420.rtfdoc 9db1e192ea221a0120c7e2ea8053da63e8b01ee67f7a239f41e24f54e6bc0046n/a Heodo