URLhaus Database

You are currently viewing the URLhaus database entry for http://mktf.mx/DHL-number/En/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:36911
URL: http://mktf.mx/DHL-number/En/
URL Status:Offline
Host: mktf.mx
Date added:2018-07-30 19:12:58 UTC
Last online:2018-09-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-07-30 19:20:05 UTC to support{at}webnx[dot]com)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-31Tracking_3703735779.docdoc 0c6be5913d4d3b50a7499557064afdf19d72eac9a9538200bcba139ef57109deVirustotal results 30.51% Heodo
2018-07-31DHL_number_935049862204.docdoc ec6613de5729b1691c711b2a8bd3edb0cd413dfe6fd8c10e758748cf52f439d2Virustotal results 31.67% Heodo
2018-07-31DHL_Express_2789661296021.docdoc ecc1495b0e25fe684a32914fb95f25020fe82be6141b6d7740c9282529872b30Virustotal results 29.51% Heodo
2018-07-31DHL_number_174462351180.docdoc 77fb2eaf3bfede8885ddf9235d841784e666780036b95fc0fa5d218189b01bb4Virustotal results 31.03% Heodo
2018-07-31Tracking_703763322989962.docdoc 9afb0bb16e3c703ff94bc500cb54208a76bdedafe4c48c48206438a835235074n/a Heodo
2018-07-31DHL_number_575208299.docdoc e66b5bc3cba149e05856d932769bef5539b522ffb4583fe194af7da4d6a081dcn/a Heodo
2018-07-31Tracking_5547141236302.docdoc fd11a6af20cc684657689dc3aac7d402a418f67359e3e5492e2e902bd7074fc0Virustotal results 27.87% Heodo
2018-07-30DHL_number_3216277160109.docdoc 377f624d71f25a926d2b63785058f51e2d16645fb3375bff54deea3c1a94913fVirustotal results 26.23% Heodo
2018-07-30DHL_0002395243415.docdoc f77a84a3652cb6ced1cdcc8352594052d0ab054f733f980bb53a950251f13120Virustotal results 28.33% Heodo
2018-07-30DHL_Express_02067758732.docdoc f30b6fb4be68bb4cd4d91eed578096a33dfb17a78dd8eaea918ee8240feb1329Virustotal results 28.81% Heodo
2018-07-30DHL_Express_74905727060.docdoc ab8adfa6b999272350f990af6761828a69e88dedf5e9896168786dca66e3e385Virustotal results 27.59% Heodo
2018-07-30DHL_0854868.docdoc be5851ea122dd7b4d7a59ef8097cc32b73e37acf5d73bec1e3e376bacd1003b0Virustotal results 26.67% Heodo