URLhaus Database

You are currently viewing the URLhaus database entry for http://kmgroup.rs/welcome/common-sector/verified-warehouse/tj5-681x7t/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429771
URL: http://kmgroup.rs/welcome/common-sector/verified-warehouse/tj5-681x7t/
URL Status:Offline
Host: kmgroup.rs
Date added:2020-08-11 23:03:04 UTC
Last online:2020-08-12 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-11 23:04:02 UTC to abuse{at}sbb[dot]rs)
Takedown time:16 hours, 50 minutes Good (down since 2020-08-12 15:54:02 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12INF-2020_08_12-RBC925.docdoc a42edb781d488bcb95cf8395c95f235ad425f492e7d3e004f83ffba92c4264eaVirustotal results 29.51%Heodo
2020-08-12FILE_20200812_OQ981.docdoc 5ea80c59d4629ef6a11ef42c5a585fc6c263cd78ce8876440df9193182199ef6n/aHeodo
2020-08-12file XPQ242004.docdoc 98cdaca6fb4bec5a48ca84cbfa00b123f41849a8c0e94c9a7a0b5e2e00bc2ddeVirustotal results 28.33%Heodo
2020-08-12Doc-2020_08_12-1780.docdoc ba7e60bff1eee324d5376e7f78a7cf51aa033dcb9c8b814c71cc54cbfc1fb476n/aHeodo
2020-08-12Inf-7842.docdoc ebe2942f03be48db9a6fadc6c49ddf806aef0ec3b5aec0331a93f51ab66532d7Virustotal results 28.81%Heodo
2020-08-12File-2020_08_12-QF80313.docdoc efa5cb5f3abe0686ab17b286e16a3fb6769b7f8f95524e063433a47738b9e5a5Virustotal results 27.59%Heodo
2020-08-12Doc-2020_08_12-DYB283053.docdoc ec492f642a8aa6fa2d723853f3406c42a3604e895011181c3589e5794cfd4375Virustotal results 28.33%Heodo
2020-08-12REP_2020_08_12_749971.docdoc 60a6efb013c2184d94c35a3c67310f17cb1cb01d3bc7e081323540c3a44c7bdcVirustotal results 27.87%Heodo
2020-08-12mes 2020_08_12 IXK99968.docdoc c15363c91a8b99bc22063620a1747a678b17db67321d1b7e850d753f76f56231Virustotal results 28.81%Heodo
2020-08-12Doc-HMG867086.docdoc 50ef5d0b0b7a0a0854a2bcf084cf61dca7c50050f555e23a4d4bf3e23a37a96eVirustotal results 28.81%Heodo
2020-08-12list-2020_08_12-1239.docdoc 148d419381f7fe5907fee5bc4d2fcdb00a856e711419ba4be9dc26f5aa1279c1Virustotal results 29.31%Heodo
2020-08-12ARC VL628347.docdoc c5cf72d67d389db548717373f054466733e27034856015726230320261c7186fVirustotal results 28.81%Heodo
2020-08-12ARC HUP56548.docdoc bb408e523c77e1a3face26900e50985691a5ac535d97b7d460a2ed79ed616d17Virustotal results 28.33%Heodo
2020-08-12FILE-20200812.docdoc 1ab4853922334f81c7d8c208de1c6dc1f137a45a665fb1acf5f33666158c2ff1Virustotal results 27.59%Heodo
2020-08-12ARC_87353.docdoc 7c7837406f4a125ee3a129d23771f32eace788283c06a517f0bdfe7dc4f7036cVirustotal results 50.82%Heodo
2020-08-12rep 20200812 X2682.docdoc e44866ddc3408fab14c87c206e408852253a05de531691d4cb8e1dcd7f37cf72Virustotal results 50.88%Heodo
2020-08-12FILE 2020_08_12 VW387600.docdoc 1f2721d86674c089b606753be49e601afa652cd0daa1af0a19239ca33981af29Virustotal results 51.67%Heodo
2020-08-12List_2020_08_12_064890.docdoc 1e49a48de56f70d98bd4a9438f95292a8725b5025075cbf8f0bccd551474754bVirustotal results 49.15%Heodo
2020-08-12rep-2020_08_12-50583.docdoc bdbc30e32c0856ae4d83de0bf9fd372f69f023be391c2bafac21c73bb998a899Virustotal results 50.00%Heodo
2020-08-12Arc_2020_08_12_TO47204.docdoc 9e95cffa8cb342aefdb7f8c1a029adcd48d1304b400d07318215436dd2894341n/aHeodo
2020-08-12INF-20200812-404.docdoc e5c2116828d317efeac4ff3a7fe2092bae369fbb5265db371d919a3ffa037cefVirustotal results 52.54%Heodo
2020-08-12FILE-20200812-ICO045401.docdoc fadf9dff9ac739df4bfe67bb110d2570b3a8b56ff10d4d0a619ec013819ee896Virustotal results 50.82%Heodo
2020-08-12FILE_20200812_H93115.docdoc 106b70745b6bbcd2a3b1590f596682076f039f584ccde6df0ca12dab353fb701Virustotal results 51.72%Heodo
2020-08-12DAT-2020_08_12-58844.docdoc 6fa74bb52572c68bce1d712b488aea9184f884d85ef22b26492011dc0fbec3a8Virustotal results 52.54%Heodo
2020-08-12MES.docdoc 7d7ecd381d765e01cbb41e6b0a254b7bc60ebb1d59c3c212286dbb9054e5093dn/aHeodo
2020-08-12Arc TR7893.docdoc 239b0c4f5e150bac96fff321ed672e0772718018ae715db9d4feb0b59879fbb7Virustotal results 50.85%Heodo
2020-08-12inf.docdoc e49959014262227a3e6ca5bc2937e6afab83a251fc694000d1a3d38e7814d9dcVirustotal results 50.85%Heodo
2020-08-11Arc_20200812_06826.docdoc 3172baeac20b373f569c715b80b2d49718315f9e5f6abf7fbcc403791cc7b411Virustotal results 48.33%Heodo