URLhaus Database

You are currently viewing the URLhaus database entry for http://cddvd.kz/cgi-bin/personal_resource/09838294438_MbomSwEzHHAK_5009y0r_zuv1lmxioln4epf/0909749832_gML2uVDawnRtu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427503
URL: http://cddvd.kz/cgi-bin/personal_resource/09838294438_MbomSwEzHHAK_5009y0r_zuv1lmxioln4epf/0909749832_gML2uVDawnRtu/
URL Status:Offline
Host: cddvd.kz
Date added:2020-08-07 22:08:20 UTC
Last online:2020-08-10 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 22:10:04 UTC to abuse{at}telecom[dot]kz)
Takedown time:2 days, 22 hours, 55 minutes Poor (down since 2020-08-10 21:06:00 UTC)
Tags:doc emotet link epoch1 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08list 840451.docdoc ba50483a5407dc7d213263534638c2e4e0445d9d06f977dc496e979beda32f33Virustotal results 45.76% Heodo
2020-08-08list-77234.docdoc 31674d9d2a53c9407819aec8731838ed678f2d3317a2a4a47680fcea72536fe0Virustotal results 40.98% Heodo
2020-08-08Rep_E883226.docdoc 6d851aa91fb4cfef84903c3d1926892f45b06e662077f5fb62434768f44e5ea0Virustotal results 41.67% Heodo
2020-08-08inf_2020_08_08.docdoc a5b4fca70c16e40a7c4bad03de3c8f0448aea24ebbf989026202c94a9eeee7f8Virustotal results 40.32% Heodo
2020-08-08Arc-2020_08_08-278.docdoc cec603db22ca641e772ad1f3912383a2b3c73d6210e966c3b6ab9b4ab6695362Virustotal results 40.98% QuakBot
2020-08-08File_20200808_96997.docdoc 4be780211b5eeca427c252f629f2ed5b1e7062193463819a056e705ffa9df1baVirustotal results 41.94% Heodo
2020-08-08inf.docdoc ce5d6aa5b1cfe76e48ec485669e784f6e6fa115c5c008cd89c499726b2a74652Virustotal results 40.98% Heodo
2020-08-08arc.docdoc a2c4d99f84b10b57c46b0bd1ea0fdd817fbaec3ca977b5b71f62b8ad2896f3d7Virustotal results 40.32% QuakBot
2020-08-08doc 084898.docdoc 7eb59e041da8977c3bd1f5e50484f6026ebf4a8dd24f4e9cf391e991650f373dVirustotal results 40.98% Heodo
2020-08-08REP 2020_08_08 L320247.docdoc 7749011322a1fa88e88ac29e4663fc961f0b6ca6432e1257aefaceb28252a4c3Virustotal results 40.98% QuakBot
2020-08-08MES_2020_08_08_9330729.docdoc da431f9f7888ba7c9912a4ddd22f7d4bb12fcb99f9003d0e5b37a30ba731462eVirustotal results 42.62% QuakBot
2020-08-08FILE 20200808.docdoc 4749be0b925b0d49c831813a68772865cc0448b80e10fc43d06b81c93c5c9e34Virustotal results 44.26% Heodo
2020-08-08arc 2020_08_08 224.docdoc 2ef95fd9c222a0b299b53659e79526a1281e9d076b75aafaedb447034237ba36Virustotal results 44.07% Heodo
2020-08-08mes.docdoc 1ec0aea3e7613086f550e01f5014835b55ac12b7d35ad781c2173dd150a0eebaVirustotal results 41.94% Heodo
2020-08-08REP 20200808 19324.docdoc 8d118098701f23422ec3560934134ab170767e28ea66c8a336be4dc8ec102987Virustotal results 44.26% Heodo
2020-08-08Dat_20200808_57690.docdoc b53199af61de887966a39331aec0a4572deb4044b309a735a63ed90911032cf1Virustotal results 43.55% Heodo
2020-08-08REP-56755.docdoc e5e2f23eae1e5ced0e4dd57ce7c5c5ebb9206decd8ef46a05c454df21be49ea6Virustotal results 42.62% Heodo
2020-08-08REP-20200808-GAP57140.docdoc dbbfe251ebab8c3e19de23d3e0aca5661d1e893f34b9a123699fa7f2d3d5b8abn/a QuakBot
2020-08-08ARC 1703802.docdoc 68fa39fdeeb2482b9dbec2a1c2a7649e0a1e4b883528ef42b407a240bac4065eVirustotal results 40.98% Heodo
2020-08-08doc-20200808-1417009.docdoc 62112657085b9dc12429d5002978a67b6a792db61dca0bfd23db9d5370717ec5n/a Heodo
2020-08-08arc HL568.docdoc d840943a1f750210b98a2f26d5852b1c58ce7e454a38b38884f0b5371ec1198aVirustotal results 40.98% Heodo
2020-08-08REP_20200808_478.docdoc a671e2959966d9a945046df0dd4a878fbe99b378e108e50c8de5a2746ce7dde8n/a QuakBot
2020-08-08REP 20200808 IZ5382.docdoc 999698b5ddcc7f3b457aa5504fadf382046c692cd623f345e198e80e9823501en/a Heodo
2020-08-08rep-2020_08_08-SL1145.docdoc fcc0bbc42e2e7c52087a0a4da5dff8a2ed8efddd80d6a4805aa9fccfbfdd3910n/a QuakBot
2020-08-08Inf_7069.docdoc e9bf95d02c5b2b1e8ac21c595cce59294b8a54da32e71a619cdf2ed03448dc96Virustotal results 40.98% QuakBot
2020-08-08mes 2020_08_08 MWB3488.docdoc 501893610fc7b68385c512147e464fd30fbe631de1d21b4b7f2f89bbc7583e81Virustotal results 41.67% QuakBot
2020-08-08Doc-Z248.docdoc eece4ec540e8ae52c63b4384986f2de0003b5b51d486ee8602de1709feb06dc4n/a Heodo
2020-08-08Doc_2020_08_08_397096.docdoc 7db111b6a3b2b44ddb5ce3413643af61cc16843c9921e8fd636a7d8cfb7894d6n/a Heodo
2020-08-08FILE 2020_08_08 055.docdoc 58f0127055c008e43422699f0ad05a08557071493548f6b4c1190411c6f00200n/a QuakBot
2020-08-08inf 2020_08_08 M84585.docdoc a737ca74e110edc3bf6b03a41b8f19a2e7c5b5e3ca563480e94efc99a1be9f0aVirustotal results 40.32% Heodo
2020-08-08MES-1391137.docdoc 63c966c20ccc686dfa62a5063bff299d385ea9f159cc9a5b79dc59063fb9514fVirustotal results 42.62% QuakBot
2020-08-08file_J44825.docdoc ec11d3cebaa5d4d05ef93c8b88ab79e34d82fede8daa5a821d119d12de060ffbVirustotal results 44.26% Heodo
2020-08-08DAT-20200808-EUV0513.docdoc f3be0b911d44447b80b1337f332187ad596fbfe6a0739cdacdd2f9d759e12114Virustotal results 40.00% QuakBot
2020-08-07REP_20200808_624638.docdoc 5d2b88e4fefb1593bca1de5b27276ba0d00140416c91339fc6fd44431c8ccbd9Virustotal results 40.00% QuakBot
2020-08-07INF_2020_08_08_8976190.docdoc db694f78bb24216ca23101aab17ecfdb5cd00978da5a4bc50c8d293005e06361Virustotal results 37.70% Heodo