URLhaus Database

You are currently viewing the URLhaus database entry for https://nundi.com/wp-content/esp/9bx092za39i/nkpehc21025282867918678tadxpzn31w2onfmgm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415841
URL: https://nundi.com/wp-content/esp/9bx092za39i/nkpehc21025282867918678tadxpzn31w2onfmgm/
URL Status:Offline
Host: nundi.com
Date added:2020-07-21 09:26:04 UTC
Last online:2020-07-23 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-21 09:28:04 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:1 day, 23 hours, 53 minutes Poor (down since 2020-07-23 09:21:48 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-23EQBK_Z5920TOGTVHPPH73.docdoc ecfcada8131c01436ccd879656898e0c54347fc88b8e4c523fcfe2faa885cea5Virustotal results 43.33%Heodo
2020-07-21FILE_FH1297274203RB.docdoc 5f79033b6a54db8f8075b5fa3c0629142bb73e654e4aabb10f5e905942a4871dVirustotal results 24.59% Heodo
2020-07-21SR_PO_07212020EX.docdoc 9fae422f1e6eaf42b4164526f13a51a3f366b573b191fb013ed934bf90d4a436Virustotal results 24.14% Heodo
2020-07-21Y_PO_07212020EX.docdoc 281280ed257511ed8f8f2b291a83ce2978bc6e6f14c52ca9ce10540c70cf0605Virustotal results 24.19% Heodo
2020-07-21BAL_PO_07212020EX.docdoc 4501457e1fae31cb83a1d2818d169525f75627a017efc573932fd412e6e2c406Virustotal results 24.59% Heodo
2020-07-21WOB_757462988119969099.docdoc b1a935c9a64f8a2191e613e696c6df7a5892c608ec14c6f72c3459c4a62f2865Virustotal results 25.42% Heodo
2020-07-21BAL_PO_07212020EX.docdoc d40a13f38676eec40c7fc38f03d55507495374f948219045d50e6ae6af725275Virustotal results 23.64% Heodo
2020-07-21TV8607284398WC.docdoc 6ea128ea049d2ebacb539514c677bb05791d9844046f47e6e1e3dc783f2942fbVirustotal results 22.95%Heodo
2020-07-21INV_PO_07212020EX.docdoc 003110462b096556a9d96dca0472feaa2dee2edaf6d8d0e179dc08a8a8f2b775Virustotal results 23.73% Heodo
2020-07-21DOC_12340208.docdoc 76135328ce70dd5755fa54408d962b10954d6bb5c47f883a7c2bdd1defbebb9cVirustotal results 22.95% Heodo
2020-07-21M_PO_07212020EX.docdoc 7205124c976d15cd097c35d5c82d63d616b710da7b82ead06faecf91fd620405n/a Heodo