URLhaus Database

You are currently viewing the URLhaus database entry for http://askcafe.net/mobil/EfIZKaM2bc_FU179k4hd_module/guarded_4410519_yAQ1tVqFu/fwsSSiO9V_1pI3Isisdj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:426985
URL: http://askcafe.net/mobil/EfIZKaM2bc_FU179k4hd_module/guarded_4410519_yAQ1tVqFu/fwsSSiO9V_1pI3Isisdj/
URL Status:Offline
Host: askcafe.net
Date added:2020-08-07 05:55:16 UTC
Last online:2020-08-07 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-07 05:56:02 UTC to info{at}birbir[dot]com[dot]tr)
Takedown time:11 hours, 31 minutes Good (down since 2020-08-07 17:27:06 UTC)
Tags:doc emotet link epoch1 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-07ARC_20200807_FST43360.docdoc 9bb646dd5265b86eba5c799d25dec0df4d675cc6e841b5487f22f53532ec4c74n/a QuakBot
2020-08-07Doc 20200807 5199324.docdoc 612b33cca81c88e812436d48c987273b54a73bdc04a908102beac2aaf50b5825n/a Heodo
2020-08-07FILE 033544.docdoc 640141473cc0509ab14b2fd02d2c2e2f4527592a141634e484152904299732b1n/a Heodo
2020-08-07Mes-20200807-4062.docdoc 3faa5383383ac0ea0fb3b0b200cc128ce70ea0f3b00966d7c5fade338763eae2Virustotal results 25.81% Heodo
2020-08-07Dat-20200807-0833.docdoc e557c9d2cc0e3f2aa2355b58c657834d11c61fe22903ea0800713dc9e09632c0Virustotal results 26.23% Heodo
2020-08-07file MWS168157.docdoc b4bfa9abdc1af9d31045f6c98499ccfa5e332945a2b269c064bc108023673a2en/a Heodo
2020-08-07inf_1313.docdoc a288dd3026142c4fb729f070fdb05a968a11a0cb77d24bdcc066866ac51eb936Virustotal results 26.23% Heodo
2020-08-07inf_20200807_W9628.docdoc 5758ab9165be010ed997a923a16d1d5651b13ede3b6ec4c96faa236f8591759fVirustotal results 25.81% Heodo
2020-08-07inf_2020_08_07_CY451.docdoc 11a879a7d8dec97462c1c9185051ef6a793dfa91fa064697aebc8e58839b888en/a Heodo
2020-08-07dat 20200807 L68568.docdoc b584a5aebf9d1ad385649f724d7889be3f925dbb7a40ecce452d88f63462e44cn/a Heodo
2020-08-07INF-20200807-L5087.docdoc af8ca0fa1d9fa19974e76b3491741aec5421ff068ac5b8fcb364b9fa30edb3ccn/a Heodo
2020-08-07File-758227.docdoc d8b1512c883ce8a757dc12b9a48423d6f6854ab429004ae2435ed470a397dcf5Virustotal results 25.00% Heodo
2020-08-07Arc_20200807_3941.docdoc d55a2e0971027bd30b6722f6827d6344f1126b7f7ba6c04a91179b881ca6e98aVirustotal results 25.00% Heodo
2020-08-07arc_20200807_021.docdoc 90f8bbf6dee1ad7d38d610ea379dd8fd80444592cadac1f1497cad9b6d4e5caaVirustotal results 44.26% Heodo
2020-08-07INF_2020_08_07_GGR751.docdoc 4d66b8fafcf69f590dc74a3383fa08576a6de54ef030b8d47bced68e03f63065Virustotal results 29.51% Heodo
2020-08-07File NS331373.docdoc d21fb5ef05cc6d7375ad67529c3b74d7111dff2fd9a11ce6944a25e4dc2463c0Virustotal results 27.87% Heodo
2020-08-07Inf-2020_08_07-32784.docdoc a6cf38618a58d0076e02ca5aa15020a6971e1367e0b8c00168775a31f8b92618Virustotal results 37.10%Heodo