URLhaus Database

You are currently viewing the URLhaus database entry for https://dolg.website/thunder./available_kb69_g7oc/T9cjG1kk_uSGada6zV_0310503367_C4gy4a/9636146734766_iwqOkefiND/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429994
URL: https://dolg.website/thunder./available_kb69_g7oc/T9cjG1kk_uSGada6zV_0310503367_C4gy4a/9636146734766_iwqOkefiND/
URL Status:Offline
Host: dolg.website
Date added:2020-08-12 07:03:35 UTC
Last online:2020-08-12 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-12 07:04:02 UTC to abuse{at}rt[dot]ru)
Takedown time:12 hours, 33 minutes Good (down since 2020-08-12 19:37:30 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12inf.docdoc 0a2fb529473b1340196d1f0e98caa568208f26a280f1bc09523963eead8b88d0Virustotal results 48.28%Heodo
2020-08-12REP_2020_08_12_9085980.docdoc c194497bd53deae5037d7ffd04e93de9ae4a080daa6a37959aa42207f197a31aVirustotal results 45.00%Heodo
2020-08-12FILE FUV01040.docdoc e060a3ea1c14105f1702e8b612d1095bd704a9757c2107e3aacc4ce542cf2af4Virustotal results 46.30%Heodo
2020-08-12MES 0502.docdoc 87b90453b1edf9bf7ee26ba76b7a73b73be127dd13678ada570fda173417ff98Virustotal results 40.00%Heodo
2020-08-12MES_2020_08_12_90769.docdoc 19a0b43438b15957a52c653d27778c90008ae27821fe97db817356de978f063fVirustotal results 37.93%Heodo
2020-08-12Arc-2020_08_12-HK149967.docdoc 6b6d945cfba7f58812d7c716d37f887c9d81c2edb7c04cc524c5a0284e128289Virustotal results 31.67%Heodo
2020-08-12Doc.docdoc a42edb781d488bcb95cf8395c95f235ad425f492e7d3e004f83ffba92c4264eaVirustotal results 29.51%Heodo
2020-08-12file 20200812 3312744.docdoc 5ea80c59d4629ef6a11ef42c5a585fc6c263cd78ce8876440df9193182199ef6n/aHeodo
2020-08-12dat-20200812-96475.docdoc ab27914f156acd19f0881239e640672cdeb34584233e8b0c5c1e5207c1135e4bVirustotal results 28.81%Heodo
2020-08-12file-20200812-SI734.docdoc 4a57ee0f815573230706a5077ac0b74ee8e1b28a2961f94fe17bf39b26773cf6Virustotal results 28.33%Heodo
2020-08-12DAT-8062564.docdoc ebe2942f03be48db9a6fadc6c49ddf806aef0ec3b5aec0331a93f51ab66532d7Virustotal results 28.33%Heodo
2020-08-12DAT PQL6636.docdoc efa5cb5f3abe0686ab17b286e16a3fb6769b7f8f95524e063433a47738b9e5a5Virustotal results 27.59%Heodo
2020-08-12ARC 2020_08_12 LP005977.docdoc ec492f642a8aa6fa2d723853f3406c42a3604e895011181c3589e5794cfd4375Virustotal results 28.33%Heodo
2020-08-12Arc_QWG668.docdoc 60a6efb013c2184d94c35a3c67310f17cb1cb01d3bc7e081323540c3a44c7bdcVirustotal results 27.87%Heodo
2020-08-12dat_20200812_685.docdoc cf5c6559dfa14321a13a819d36e2bd4d75a84f866b63a4880da5d2eb28b4df87Virustotal results 28.81%Heodo
2020-08-12arc_QEP717.docdoc 50ef5d0b0b7a0a0854a2bcf084cf61dca7c50050f555e23a4d4bf3e23a37a96eVirustotal results 28.81%Heodo
2020-08-12LIST-20200812-A363.docdoc 148d419381f7fe5907fee5bc4d2fcdb00a856e711419ba4be9dc26f5aa1279c1Virustotal results 29.31%Heodo
2020-08-12DAT-2020_08_12-2343859.docdoc c5cf72d67d389db548717373f054466733e27034856015726230320261c7186fVirustotal results 28.81%Heodo
2020-08-12List-EL16274.docdoc bb408e523c77e1a3face26900e50985691a5ac535d97b7d460a2ed79ed616d17Virustotal results 28.33%Heodo
2020-08-12Inf-20200812-HBE134684.docdoc 5774542ab8ceb2c4ec22dd97536f12e33c4cec07ec3572155186653f69778256n/aHeodo
2020-08-12Dat_2020_08_12_FD698603.docdoc c8813cd5156c368544000da8b137c912d76cc011e859cd114824f2e4bb709458Virustotal results 50.82%Heodo