URLhaus Database

You are currently viewing the URLhaus database entry for http://icacc.com/fcgi-bin/multifunctional-khbuqe6ekcp0klpp-697hanmef/security-area/48402530470-L376N7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422082
URL: http://icacc.com/fcgi-bin/multifunctional-khbuqe6ekcp0klpp-697hanmef/security-area/48402530470-L376N7/
URL Status:Offline
Host: icacc.com
Date added:2020-07-30 16:39:03 UTC
Last online:2020-07-30 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002838222 created on 2020-07-30 16:40:07 UTC)
Takedown time:6 hours, 32 minutes Good (down since 2020-07-30 23:12:09 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30DAT_6969.docdoc 66bae2882ec3f80f3b6ff5a7311cb36710ecf7747298a52e13d7a84e55ed6e92Virustotal results 50.00% Heodo
2020-07-30List 2020_07_31 8989532.docdoc 4122a94cf3814bd9e32328263e6b981316558b31ce38df659a1853a02274dc00Virustotal results 50.85% Heodo
2020-07-30Doc 2020_07_31 YZY5589.docdoc 9c59614355467ee88c9dd9cde34e35c9b7344c82eb6b01c36ede1aa41923740eVirustotal results 49.18% Heodo
2020-07-30list-2020_07_30-8255.docdoc de22f3d159bf17825aa2c83805068b8ebe5d690f6981d2e8102613087fd3b6deVirustotal results 47.54% Heodo
2020-07-30File 20200730 958215.docdoc 05e3220da16bb1bc81bf38848242552d4c34c03ef5de4e3f912429f2cec649d8Virustotal results 48.33% Heodo
2020-07-30doc-23177.docdoc 48d8cbfc263814a895f4c3a14f14ea016f0ee51ae329063b61a0a2e4a541ad82n/a Heodo
2020-07-30arc-20200730-BW4444.docdoc 94edc6ca93bf52aa32d4a4c5ff3382b0a1e1b39e3b234ff48354551d37aecbafVirustotal results 47.54% Heodo
2020-07-30rep 20200730 372.docdoc dbdabc0245226588757dd5317307e3e4d7307b6948dc4c467a1dbff0231e7e0bn/a Heodo
2020-07-30LIST 2020_07_30 T934442.docdoc 46815e894a9b6f7e7ad9bcb948b69d2b4847dbfd865ad522641c8d73fac7cbafVirustotal results 49.15% Heodo
2020-07-30dat_20200730.docdoc 4c8c34a44a9443ad04f4515f360a20869d42f7d631fbb637dbfcf146a029a181Virustotal results 48.33% Heodo
2020-07-30List_APS3892.docdoc 9aa5ef4cd779c27d0db8683412281e9b128846b846c5cacbc8caada39b2b9394n/a Heodo
2020-07-30File 2020_07_30 LSP491.docdoc c7cf836f720de4f6ca197815eb09d5588d630f613b082ead21ca6fcbdf124f3fn/a Heodo
2020-07-30file.docdoc 6511b1fde2ef072f82a4de1fe9124c05afea6eee427bb3f6e204d6d8f583bf8bVirustotal results 46.67% Heodo
2020-07-30MES-XX14541.docdoc 0a8e833c673b9d7d6d4c36937bbca05aa4cd7e77db8cbb1c521ab624c87a2511n/a Heodo