URLhaus Database

You are currently viewing the URLhaus database entry for http://nuglox.com/wp-admin/multifunctional-section/q0s4cbbkdmr-8st8wz-869034-Cioi8tEV/07884100175-YVjhsW7f7iocKk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:416205
URL: http://nuglox.com/wp-admin/multifunctional-section/q0s4cbbkdmr-8st8wz-869034-Cioi8tEV/07884100175-YVjhsW7f7iocKk/
URL Status:Offline
Host: nuglox.com
Date added:2020-07-21 18:55:51 UTC
Last online:2020-07-24 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-21 18:56:05 UTC to abuse{at}a2hosting[dot]com)
Takedown time:2 days, 8 hours, 12 minutes Poor (down since 2020-07-24 03:08:13 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-23list_V263706.docmdoc 9a3ea141f8d72bc76545f030fe43d91476ce753bd525ed872269184599692c81Virustotal results 42.62%Heodo
2020-07-22Rep 20200723 FDH027979.docmdoc b936ca1824141941696f21188294398f23a5bf8f6dc5211f7a89d68996eb1496Virustotal results 39.34% 
2020-07-22REP-YOZ74126.docmdoc 85c9b8464b14bbfbc90c01fe540a9ba134191dd42668aebfb5c09e35b1887dc0Virustotal results 39.34% 
2020-07-22dat 2020_07_23 KX090477.docdoc 8fba8be080f896187be7d544013e3a3b8f26704a23d447ae88a76bbcc11c917bVirustotal results 37.70% 
2020-07-22mes-OB6912.rtfdoc 093cc1977c0adf342635037335e8d76802041ca0b406c065ee63bb3c4b0d30aaVirustotal results 37.70% Heodo
2020-07-22Doc JD70361.rtfdoc 06ea16c8f47256c5551752bd00c34d5cb30e9b5ea7daa3434e35ca178ca75c2bVirustotal results 37.70% 
2020-07-22mes_2020_07_22_286720.rtfdoc 5adde0f4c764095e874bfe5c58bc665bfa26b074fa84231ec735009f84a1313eVirustotal results 37.10% Heodo
2020-07-22DAT-2020_07_22-3547.docdoc 61ac92f083c25879585954c7ade43b7b17fefbfadc38a09fa9793f769f33f9f4Virustotal results 36.07% Heodo
2020-07-22Rep-682.docdoc 3cdc4b152007b8583277c7ae4ad9e2df4b455d70ea68db4e16537a0354c97362Virustotal results 38.33% Heodo
2020-07-22Dat 20200722 OU5921.rtfdoc 00f9030cbfb095139a4e8f6fc9e282149fb32fa202c75dd95063951b237bdcb3Virustotal results 38.98% 
2020-07-22List-20200722.rtfdoc f20360cd3061597269d3c295d95bab2703ac3dec8db564d56299e29db66601f8Virustotal results 35.00% Heodo
2020-07-22Rep_BC432057.docdoc 3a41b5672541c103127d7150bbc0b39ac13eede1d3851fc7c63484a3700f659fVirustotal results 27.87% Heodo
2020-07-22ARC 931.docmdoc 9d678fbeffe8eb971ce79fed03f575d8712e98b080969dd2aac8e4ede327b43cVirustotal results 27.59% 
2020-07-22Doc_AZL613129.docdoc cb016de85f101cb949d1cfb72baa282d05031bb8374f148a16af68b20dc2da45Virustotal results 27.12% 
2020-07-22doc-2020_07_22-01748.docdoc bda45a277d1d57050ac2f680f22b728a35eb2aa5d67471ea2b55817d66a982c8Virustotal results 26.67% 
2020-07-22FILE 20200722 GP538388.rtfdoc 3df05f387f43858fdc3530301f6dc27b9ac2a89560059a40ee635b6a1f25497fVirustotal results 26.67% 
2020-07-22inf_20200722_J40823.rtfdoc 457abf24cbef9694782bedcaeaecba529fb45b9839e4ef469f7fba267758ccdeVirustotal results 27.87% Heodo
2020-07-22mes-Z605.docmdoc d3d731e1c5ed00a3123112f5f1b4d029a74b742ddf0b5a2639209b85f2930b18n/aHeodo
2020-07-22INF_20200722_B875647.rtfdoc 21443c68d64ecddd740c7966067a4bed9de79aa081c06b9ad97fe8d8d0e0716bVirustotal results 25.00% Heodo
2020-07-22MES_74394.rtfdoc 3ddd3251b6460b9b8fc544ad79d56857861363651da3d1b0c4054d54777366e7Virustotal results 25.00% Heodo
2020-07-22List-2020_07_22.rtfdoc 656f9f7c087bc9a3d272d1aea2c369dcfa89d33e5fe59b61e4a57d7b181904d2n/a Heodo
2020-07-22ARC-20200722.rtfdoc 64bd75d17119d13674e5414b25e5d2cc4fd8f76b0af8721fcaa0fba000570daeVirustotal results 25.00% Heodo
2020-07-22MES-20200722-TC1837.rtfdoc a018bebb6f4d713eff5d16c6b80d20df72bab7d5e055c287018f1f842f952e1eVirustotal results 25.00% Heodo
2020-07-22dat 20200722 AQ064.docdoc 737f7e0557c9203033464070e06e23e7675c8325abd0083d1ebbdaca3f7eac2eVirustotal results 37.29% 
2020-07-22dat-20200722-NLH959.rtfdoc 8aec85cd8e1f0f312d2a3442272e4634ea845690457c6a516b51378c868a1c34Virustotal results 34.43% Heodo
2020-07-22list-2318537.rtfdoc 20f29a9a1184a44a6ce629ca9668c86c1e6cbd4479a1bc1c3df082d17a1762dbVirustotal results 33.33% Heodo
2020-07-21REP 2020_07_22 5359385.rtfdoc b88eeea6841abee77c07e6b5243d98213c6997de1033e14ddec0cf10b9b11c35Virustotal results 26.23% Heodo
2020-07-21List 2020_07_22 322885.rtfdoc db88b385b97b7038cd233960f7f99ce350a72a3eecf6bbbcb227645f111d4e7cn/a Heodo
2020-07-21inf_YP466.rtfdoc ca4ae10db92df8cf44bacee70e7560ae411a37d1559687ad47687282ca447526Virustotal results 25.81% 
2020-07-21Arc_2020_07_22_193.docmdoc 96f45a5c51839644dbf8e9f7ffaa226944422285dd997fc0ff8c23a883b18410n/a 
2020-07-21INF_20200722_LSM5071.docdoc 8aa3e958943656f026b02437d4c84ed9268018560390b8ab0d9807c7b23c8b41n/a 
2020-07-21doc_2020_07_21_4765.docmdoc 150a88b5563c954af14fe5765edc790b73360e570b2a163a7930c0253e10d9e2Virustotal results 23.33% 
2020-07-21dat-239.docdoc a498a07bd860a86bd937ea230aea64bdbc55c3040d90c13e57a2670608c1af3fVirustotal results 31.15% 
2020-07-21dat-239.docdoc a498a07bd860a86bd937ea230aea64bdbc55c3040d90c13e57a2670608c1af3fVirustotal results 31.15% 
2020-07-21dat_2020_07_21_5605.docmdoc 31f2efffc02e6ee0f8a7339acbb1eb5aa9faa94b66709417b22f4c2fbc77e7d2n/a Heodo
2020-07-21list-20200721-LDF8789.docmdoc 9e5640f95155193ba256e171fa3c82d7ee336931c3b88e12f1678197ba4d3081Virustotal results 31.15% 
2020-07-21ARC-3071960.docdoc 050da6467ba07b4ad283cb19242ba04f2ad1abf3220c2eae335a348c061b49afn/a Heodo