URLhaus Database

You are currently viewing the URLhaus database entry for http://tm-74.ru/recent_searches/swift/d499ccg1z8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415313
URL: http://tm-74.ru/recent_searches/swift/d499ccg1z8/
URL Status:Offline
Host: tm-74.ru
Date added:2020-07-20 15:45:06 UTC
Last online:2020-07-21 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-20 15:46:03 UTC to abuse{at}nic[dot]ru)
Takedown time:13 hours, 41 minutes Good (down since 2020-07-21 05:27:43 UTC)
Tags:doc emotet link epoch2 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21DVQR_IX1121329371DE.docdoc 41239e9448583b6a09ec8574d34295b254dec60348e219d0a1355467c3ab37a4n/a Heodo
2020-07-21E_PO_07212020EX.docdoc 9e8362c34f689302d747bee833e604d4d7e10c7d519b401e9c9fe257bc241197Virustotal results 32.20% Heodo
2020-07-2117755014.docdoc 4889dc2e25eb4a39c1afed23f47c68f25441da2a8a16860479a9af42e6588696Virustotal results 31.67% 
2020-07-2140690136.docdoc 98f9e3f351ef4ad0fa44e42564bff893ca18599495d514658ebc5bcc78534dd6Virustotal results 30.65% Heodo
2020-07-21BAL_46325975.docdoc 31753fd36a9782bc8df01e639556c0f7a72a7eecc326382a981a6c69edc8d318Virustotal results 31.67% 
2020-07-21FCT_070120_MWV_072120.docdoc 6d7c0327ef758d90e34d8e64f95ea11431fc630f904b95f33141ced30a743dc1Virustotal results 31.15% 
2020-07-21M31QMWL.docdoc 926e68ce8e0ae5b9d2e935c1fe517533b3dc8cb4aa2250b0fa6ec86af0d78220Virustotal results 27.42% 
2020-07-21BAL_7CA1710ZYTRTH.docdoc 7e1aeb2be52594be4df58400922f10eb753ee56699771180bd21fed441171c2fVirustotal results 27.87% 
2020-07-21KTLM_DXQ_070120_DPU_072120.docdoc e341cca78e446c93ee00c387cee3517341c104ac0587512879a602ff58871c64Virustotal results 27.87% Heodo
2020-07-21PO_07212020EX.docdoc a7f4f8b9dddb70414bfdbbffd5c446c88b517c104a441be19151c8a711133686Virustotal results 27.42% 
2020-07-21BAL_JO4077866474JZ.docdoc 245167729dfc9f109b8a14fce10210be27ea62b8a004aa92d284cbc54f87ce72n/a 
2020-07-20FILE_08393272.docdoc cff09d732ea9fe1f128dc29bff9f5d5d8ff78ea22eadb52fa4b5b8d7c056928bVirustotal results 27.42% 
2020-07-20U_PO_07212020EX.docdoc 5ef34d47ef171a2b5cab01782a4a45d9a12f01d70dde381936b6975ca93dfad7Virustotal results 29.03% Heodo
2020-07-20REP_92937256.docdoc f532fcd4387475d48960a5f0863e003f7eba0281354728bf832162a0ca5673fbn/a Heodo
2020-07-20FILE_93351705971501330904316.docdoc 2a7edcd4009ca88459bd2ec64af866f700abb7acb68cc5b13a40315c51976df7Virustotal results 28.33% 
2020-07-20INV_09334979.docdoc 80b27b3a7242ea8cdfbcc0d266c4fe489cc0b035fb614b755e2546c80cdfbed5n/a Heodo
2020-07-20722324418111326108141.docdoc db25e5d9d7e9141385c443268866698c14432d243af5aee0906b93bf713ff820Virustotal results 29.03% Heodo
2020-07-20PO_07212020EX.docdoc f073a991092d0dc2ca2d7308e64b58992ce0cb00fe5da928b65b58530c10e7a9n/a Heodo
2020-07-20DOC_AJR_070120_ZRM_072120.docdoc a6ce3b9c522d36ac4e91cf8e2cf1581bc9d7e6548f1e66ff998e11662f6894cbn/aHeodo
2020-07-20FILE_TRO_070120_IOR_072120.docdoc 148aa06dceabdc99c7588bd48277867f3d0528fcf04463562707fd66f953045dVirustotal results 27.42% ZLoader
2020-07-20DOC_GFP_070120_BDQ_072120.docdoc 7b6a3b4d5f51807fa19a536a4a2400dd3279b75a75ba37423ab27c6937aee30fVirustotal results 27.87% Heodo
2020-07-20G_09804479331339871.docdoc cfb6588d9181a97aa1f93b2b9f8af82134836e916938a80a217cd03fe4294811n/a Heodo
2020-07-20DOC_JMB_070120_JSL_072120.docdoc 401dadd7c1211dae181b8767949d274790aa4fb72e78a3d57ae92ac2cf925da8Virustotal results 27.87% 
2020-07-20REP_HJ4MZ8KDV.docdoc 33c897cc3c1d11687231644af13032e24358c594f4b484a7040a3eeecfae7145Virustotal results 27.87% 
2020-07-20T_EGL_070120_GCL_072020.docdoc 70fd23e6a829661f7fe775e5b73c20b09a4dbeb5b97648d0851dde0591a3b304Virustotal results 27.87% Heodo
2020-07-20GQ2701919742GE.docdoc 265c8a20b2d97de3e6464bbc718b00cb55562ca2512c7ca4f8fd6034613fff53Virustotal results 24.19% 
2020-07-20JDHI_PO_07202020EX.docdoc 8811f4498f1b1d8729556a61a5683ce20c4270a64ee5ad0223185110adac5f2cn/a Heodo
2020-07-20OJZZ_PO_07202020EX.docdoc 8895dd40aa0da4cf1f3087db7cb003067025c7baba71478699d849d2f419d172Virustotal results 27.12% 
2020-07-20F_PO_07202020EX.docdoc 69167697c3c077b3ca6449ae55750d1712c20bc33196537fdbbe05e463aab195Virustotal results 27.42% 
2020-07-20INV_69352027.docdoc 1e146c18d65265b27e23f9ee84a8f1d20c046aa76c30ed386710a10cb0da2960Virustotal results 27.87% 
2020-07-203884101871071675059676.docdoc 9ea223e9251e17c155c00e320f9f1008c6872573da7a16d524213225ebec9addVirustotal results 25.81% Heodo
2020-07-20YCZ_86O8V79.docdoc 4d4dde2b4708fc336d7f1450e624c14cb25a836d5081855b17a1166a8b1b2521Virustotal results 26.67% Heodo
2020-07-20DOC_TYGCMZVBY303AMEP.docdoc d2357823bd33f106343cf781864392d133112d09386148aeec801d016dde2d47n/a 
2020-07-20Q_KW5375900717IK.docdoc 1a328aa48b0ba77e6965043cc7dc2d97edd5ac325b193b1f102a50a492444948Virustotal results 26.23% 
2020-07-2079225924.docdoc de77fe86034d9281adb201f8d4d906343d622467a133d5ef3d0e8cfe50dd4061Virustotal results 25.81% Heodo
2020-07-20D_UDU_070120_LKH_072020.docdoc 0fee9dff045cb53ab19cad51113a8af4f6b38c19b46c50150f606626fd1a42c9Virustotal results 25.81% Heodo
2020-07-20INV_KL1335160401KW.docdoc f49f50e867c62fbba39a590c6fd467d0a6ae957409da5832c798cf31558296c3Virustotal results 24.59% Heodo
2020-07-20VJV_619506376398946.docdoc 15fe975d4b69b43d4f2a72a301e2eb1beb12fb709d0cf36259e10950b30d0fa6Virustotal results 25.00% 
2020-07-20FILE_MF1409261982QT.docdoc 932c549927ea5c0ce827253fcb26978c1361cfbee3495d9dde5130ba190dd3b5Virustotal results 24.59% 
2020-07-20INV_XIA_070120_UZO_072020.docdoc 9916b4a492b19650f59d73747d3b28cd2e996ea9e6ea86675534a17b52c01bb9n/a 
2020-07-20DOC_87883234.docdoc 4a21c5de84bc7e0195418379d245278ca4e9e7d90fbba9300d0355a2f2cc6d6bVirustotal results 24.59% Heodo