URLhaus Database

You are currently viewing the URLhaus database entry for http://tksb.net/serenna/open-zone/h3jvaIWJT-cT5geY4dZ-portal/7e6sq-6uxwu6ty581x/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429441
URL: http://tksb.net/serenna/open-zone/h3jvaIWJT-cT5geY4dZ-portal/7e6sq-6uxwu6ty581x/
URL Status:Offline
Host: tksb.net
Date added:2020-08-11 14:39:09 UTC
Last online:2021-04-26 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-11 14:40:05 UTC to abuse{at}aptum[dot]com)
Takedown time:8 months, 18 days, 2 hours, 28 minutes Bad (down since 2021-04-26 17:08:21 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-27ARC 6573.docdoc 451bca8e554bd014a470e34371b661882e6e304e90c5e5a370332ff189ac92c1Virustotal results 73.21%Heodo
2020-08-11dat 20200811 0526678.docdoc e589ae383d2dda4770ca6a4cd98ae21ad8e8230567a0c3c2dd5fe33395d90cefn/aHeodo
2020-08-11mes_20200811.docdoc 1da87bf7cde42012d6ef60a19e839e43b5cf12ca5942cd31c40cc0ac0e31da49Virustotal results 40.68%Heodo
2020-08-11inf K6986.docdoc 41a14ae8992338c85b383362556c69ed34ef79be6782f91011a521681efea640Virustotal results 40.00%Heodo
2020-08-11INF_2020_08_11_H735.docdoc 43dfe63eff9212397ee2b7be571cd22d59ee8e88b32968034a655193a6ff6b71Virustotal results 36.67%Heodo
2020-08-11file_2020_08_11_YF45312.docdoc 276be88a16b686ba3176e2b41f7695209629edfd16517fb9c8eb7b3ebbf905caVirustotal results 31.15%Heodo
2020-08-11Dat-D91479.docdoc e116b128fdaf41295ce37895adc734d500040cd8b6d027ad266a73d31a7f7ff3Virustotal results 31.67%Heodo
2020-08-11Arc 98632.docdoc 443267f63d955561b6da7e86366dcbd233c605fb7eb3b92e5863f7482738e692Virustotal results 32.20%Heodo
2020-08-11LIST RDB957.docdoc 356e3d6505e5c614fd7fe96e3e20c392e04e5b6e552a28f069dd37250d00508eVirustotal results 30.00%Heodo
2020-08-11ARC-2020_08_11.docdoc c279b2621cc960bc14d86aa7b7a8ed1d61346e3e582e77072b43a1631871f3f1n/aHeodo
2020-08-11MES_852.docdoc c66bf4466026b71489377b455aefbb0d9daf2b7877cc86f06aab43e023384eecVirustotal results 30.00%Heodo