URLhaus Database

You are currently viewing the URLhaus database entry for http://hshub.org/ThemeXP/DOC/azrh91/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429867
URL: http://hshub.org/ThemeXP/DOC/azrh91/
URL Status:Offline
Host: hshub.org
Date added:2020-08-12 04:53:03 UTC
Last online:2020-08-12 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-12 04:54:02 UTC to abuse{at}ifastnet[dot]com)
Takedown time:9 hours, 11 minutes Good (down since 2020-08-12 14:05:07 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12G_PO_08122020EX.docdoc 801b894083a28702abb0010b0d8c0fdbdb840c5ca75143f0b3651ffcd9f4733cVirustotal results 30.00%Heodo
2020-08-12IZXMN1C.docdoc 2a604113da3d540e958f07fceaefe7c0bf0b84863093e22b91a9bacea6c0fd55Virustotal results 29.31%Heodo
2020-08-12INV_LBF_080120_BNM_081220.docdoc 8133ad23a95674ac43c254256076e1571b6ac10c7fa712df1a0a3fc9054f2093Virustotal results 27.87%Heodo
2020-08-123ZC8NLVA29ZAEHH7.docdoc e9b11c739e5d0a771cb4efdc41e3d084460fa975e42a309294ab185eb2836728n/aHeodo
2020-08-12REP_PO_08122020EX.docdoc 23be0779d59df875485b237b812b0b7d7c4d53c41dd57cc961cfa570bf09eef4n/aHeodo
2020-08-12OK0544634786DO.docdoc 7eba5b17df94761ce65d93039d81735e0a1525f6b3244704a023df60dd04c17en/aHeodo
2020-08-12NEGG_QJY_080120_BCQ_081220.docdoc 2ba2b88e28df1b52b5b8e3b8f75ccdf1e3d71308206e85196e50331e57bb8bedn/aHeodo
2020-08-12DG_XU5573961377UF.docdoc 4ef955f6b07c4350dd8d78c92540f57080711947d38c572fddaf1322ee3e4bc9n/aHeodo
2020-08-12XN4607004464CQ.docdoc b00309dc3091f93c13fa36bd5d5fb4f1d080f70ab1eabe94d84eb8423dc3d5dbn/aHeodo
2020-08-12BAL_33060339.docdoc a56d5701d53cd34f450eb0a957c6f5c0716a835bc9c9070e315e22f71889b72bn/aHeodo
2020-08-12MX_586360185.docdoc 214f91b9b3ab2ea28b14536241901516f9141df4e12fd3b2ce52088fef0a3734Virustotal results 28.81%Heodo
2020-08-12BAL_PO_08122020EX.docdoc fe14ae5d76ac1ccafc67f474efe315000dadae344444a44c9200e04e94ebbdadVirustotal results 28.81%Heodo
2020-08-12REP_PO_08122020EX.docdoc 025046a10693eb1c9dca8e64fa2dc55f1ba16ff9c6650493205e2c3af827e1dcVirustotal results 52.46%Heodo
2020-08-12INV_GVD7522GPT1SEY26.docdoc 9492fa4f34cceef83ff1e6f77bc428777aba7ae617b195a3e6a06d84e5889b1eVirustotal results 54.24%Heodo
2020-08-12BAL_TOLIMS6MY6J.docdoc 45597077ea44b6912767ecc3863c6a7eb9a1acb80e69d92deb7f49b5cf9f476bVirustotal results 50.85%Heodo
2020-08-12PO_08122020EX.docdoc bf23bdfcb1ba099bac9552136a669b228f4fffaa65dd00d243331be54d5ff517n/aHeodo
2020-08-12FILE_7518739399275965090874.docdoc 035f407beebfa56f402f686f6bf72e0217cf4d4b06106b1dcb3877e1167fdfd7n/aHeodo
2020-08-12INV_22319165.docdoc ce53e6cd77782b03e293e30492ead316081d7c39f4fba50893244b8ecb0c5e12n/aHeodo