URLhaus Database

You are currently viewing the URLhaus database entry for http://hamrokarnalikhabar.com/wp-includes/60220_f2wyJs_zone/external_UBIPd_SXK6LLOgzh1Y7Q/ye8qfm85li1q_77t7vty/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428132
URL: http://hamrokarnalikhabar.com/wp-includes/60220_f2wyJs_zone/external_UBIPd_SXK6LLOgzh1Y7Q/ye8qfm85li1q_77t7vty/
URL Status:Offline
Host: hamrokarnalikhabar.com
Date added:2020-08-10 08:02:11 UTC
Last online:2020-08-10 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-10 08:04:02 UTC to abuse{at}digitalocean[dot]com)
Takedown time:6 hours, 48 minutes Good (down since 2020-08-10 14:52:38 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-10List-X524.docdoc a911b368b94dc3e0fb269c4d07d39d833670469f5a55427786035059cb194a67Virustotal results 37.10% Heodo
2020-08-10doc 2020_08_10 67120.docdoc 45c4190948b0c2820d9f66648aa3c78b09071303b6dbbba413464384ce5d5f72Virustotal results 33.87%Heodo
2020-08-10dat 2020_08_10 OR148.docdoc 1ffeeaaba729ae71d1ace58dd6403d93cf036e5faf59f53b19437b2e5bb2a26aVirustotal results 28.33% Heodo
2020-08-10mes-20200810-LU193995.docdoc 8f9af89d2ebf390e92bc66c56b6fe9fc28b7852a1333ceb33e5c37e7d58971f2Virustotal results 27.12% Heodo
2020-08-10Doc-2020_08_10-VRC629.docdoc 42aa54c97fd4610db06d1243f65542ff4e4fb19f46680240989a85e26b01f565Virustotal results 25.00% Heodo
2020-08-10DAT.docdoc fea75486f779a09cc13afd43618fc5e3fb34dd21ad064fd50b17f9ba0efb21e4Virustotal results 24.19% Heodo
2020-08-10mes_554.docdoc ce0216ccf311399fb9c2ee7c86a1e7da2277236cc474868128f3bb2d6540171fVirustotal results 24.59% Heodo
2020-08-10LIST_8271538.docdoc 4d4ae1699db9838c38dee58dcd77506a4d264f9bb07868d8238c32f614162907Virustotal results 24.59% Heodo
2020-08-10arc_2020_08_10.docdoc 799851df1ba5830b6c1441b7a66be4f00b95a7f9cb434eea83672a5bfa8bc475Virustotal results 23.33% Heodo
2020-08-10Arc 04173.docdoc 4785c1a88f785775f3e1ff5d2a23655322d1beb91d61da3f9a328ca4f2443c0eVirustotal results 22.95% Heodo
2020-08-10File-550.docdoc fa4d4fd753c9e149d01fd2d3c9c4feb9c2de06940c9fbd3337d959e768eff74aVirustotal results 23.33% Heodo
2020-08-10rep-2020_08_10-YO153768.docdoc 2d9eefd9fba0c4807e2e9c22ff8588448a68b7cbdb9f868a0f177161d4b044c7Virustotal results 24.59% Heodo
2020-08-10rep-20200810.docdoc 89916122c841fe8367c6789ba4feb91c43d3d31445ea5abbcfa7c14ef3d67f4fn/a Heodo
2020-08-10arc 20200810 114.docdoc 0a3291d2715fd01250ba5d617a9526e37b1e15edd535968de9770e3ecfe0b66aVirustotal results 24.59% Heodo
2020-08-10Mes-4864246.docdoc c8ecb35f1491b312bc8f34bab1a9746238044b23b70fe26cc8f232875f484587Virustotal results 25.00% Heodo
2020-08-10Doc-20200810-IMJ0492.docdoc 1c0dc75596d8dad5280188b49ea0d4efc4dd881af73f0b79ddd95f34c57da955n/a Heodo