URLhaus Database

You are currently viewing the URLhaus database entry for http://abakus-biuro.net/Jul2018/US/Client/Services-07-19-18-New-Customer-KH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:34690
URL: http://abakus-biuro.net/Jul2018/US/Client/Services-07-19-18-New-Customer-KH/
URL Status:Offline
Host: abakus-biuro.net
Date added:2018-07-20 03:42:11 UTC
Last online:2018-09-21 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-07-20 03:58:37 UTC to abuse{at}home[dot]pl)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-21LZS40301333_2018_07_21.docdoc 01318725589e72c960c01ddb6f1647c226664be8f8daa1d396a02ad3ad78f44cVirustotal results 25.42% Heodo
2018-07-21TSI677336948033_2018_07_21.docdoc 124c8df9543922b4305c773a0bcb454a4028171c3b27c17f229f1261538f6e63Virustotal results 27.59% Heodo
2018-07-21IGX8662972648_2018_07_21.docdoc bbf87644e0ffcb36d8553e4ea33c33df9e6b48e3e92a452e969dc6a8feec8e32n/a Heodo
2018-07-21IR7253498_2018_07_21.docdoc 5f32fd3fb34f6c76263b9d56ade36c6746e142c437f22b886503ef274ac74dd7Virustotal results 28.07% Heodo
2018-07-21KPB90303_2018_07_21.docdoc 02e8fa08eed92f4546cda6239ff0d52753864dfefd97795abb8ee8e3cd09ead3Virustotal results 31.58% Heodo
2018-07-21SO582083_2018_07_21.docdoc 38adefebff603709456d0c494f9c220f49ba199a2a47fedf38c946294952570dVirustotal results 33.33% Heodo
2018-07-21NK64074_2018_07_21.docdoc d91c31eb9a5705c5f02de259bf377d12608bc9f889e3fa3a59ae291f7f11a515Virustotal results 28.81% Heodo
2018-07-21OB35371_2018_07_21.docdoc 9136a5bfe030511af47706dc05230247cd98e22e6f5446ec64f51d69dad0a66dn/a Heodo
2018-07-21XF3938576916_2018_07_21.docdoc ff96f38726a5d370bc8c1782c9768c892c6c5d2388c03aef4a5211c47a3b8530Virustotal results 30.00% Heodo
2018-07-21UYH72098140746_2018_07_21.docdoc 32799477ff89cd4e7c61b13b9071ab8f5b5235fd852a89034baa8a63d84f170aVirustotal results 26.67% Heodo
2018-07-21AE0970405480_2018_07_21.docdoc 8449b8b0faadcfab22485004ccc56e221ddf48083c8569741996115ef56452f2Virustotal results 25.42% Heodo
2018-07-20ZZ3225378459_2018_07_20.docdoc 3b989a9a60b40ee5295f0d66bf9400fb75634c9cdc72325db17dc986321403aaVirustotal results 27.12% Heodo
2018-07-20BOK3003071801_2018_07_20.docdoc ee74e5a1a06c6fa34ba5d7bf16dc5193f78ad6d8b4e143fe97ec4e9edb90ec68Virustotal results 25.00% Heodo
2018-07-20FGG9512811_2018_07_20.docdoc a9a95563040b51685780c5e9165ac451ea2479a8310f31dc57cfb57b31a13efcn/a Heodo