URLhaus Database

You are currently viewing the URLhaus database entry for http://namunet.co.kr/100wp-admin/attachments/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:430442
URL: http://namunet.co.kr/100wp-admin/attachments/
URL Status:Offline
Host: namunet.co.kr
Date added:2020-08-12 13:49:11 UTC
Last online:2020-08-13 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-12 13:50:04 UTC to irt{at}nic[dot]or[dot]kr)
Takedown time:10 hours, 51 minutes Good (down since 2020-08-13 00:41:21 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12BAL_DM3827524007DW.docdoc a9af06ae735677ec282b4a66f7bc85a343dc7c71491658673fed6150e05ef3c5Virustotal results 50.85%Heodo
2020-08-12L_UV5804852457TG.docdoc e9bbc3d987e57144a6554ea1c30a527af2db5a40b2c12e9fa6b28a79ea2afb3aVirustotal results 49.15%Heodo
2020-08-12INV_FIH_080120_VLY_081320.docdoc 77b30bd340e5190b08a7d94df99aa81a4aed0b89711a543fa9f87bb83fe3a72fVirustotal results 50.00%Heodo
2020-08-12REP_32332737847417351227.docdoc 29c5831f071871eed50e5f9e8c02779dedc26d8d1b5485a57cef2f7dae79c9f0Virustotal results 50.00%Heodo
2020-08-12D_14218708.docdoc 5ec93d8ade8ce137e0a4718134228f587451d59aeaa2e27d24713ccc4866e8edn/aHeodo
2020-08-12REP_18937683.docdoc e5114df7f77a23171adfda3224ca608f5705e48a524a4a9fbac8cb8fc3166e7bn/aHeodo
2020-08-1258308507.docdoc c75a7753aba5fdf5703e46cfe6e6a53ceb7df3394f932fc521343b25ab0b2388n/aHeodo
2020-08-12677068561201632364.docdoc f2ccd3c493881b68693c2d24addb0a1ec854e6020efdff1cbccf785a1ad099bfVirustotal results 48.33%Heodo
2020-08-12N_HVW_080120_ZEO_081220.docdoc 4b94ba4ad2c65349c09e18ba049dd76f5b61a5491812b3ea60961945d1866446Virustotal results 48.33%Heodo
2020-08-12DOC_OEY_080120_JQD_081220.docdoc 01817dd6570dc258829c88ceab491052f8376cc5071286d89c5ef07b621f96ddn/aHeodo
2020-08-12JJ0410520510YR.docdoc 97feccf3c91f6d0275ecafdf2bb2d3a869dbd30f1ed7e87db533ac6a63678fb5n/aHeodo
2020-08-12AA5160047585ZQ.docdoc 272b2ee94e735c0b96219372ae505aa8689e9790ff6390568311fe3eb01a9f2fn/aHeodo
2020-08-12REP_RF5091559338XU.docdoc 1b43dacaa3825888c4583607901a5fad687f60840690fa8dfb7b5ab72e28c27an/aHeodo
2020-08-12FILE_RHSLU26.docdoc 25263694227734da43c741c2d09b0f0aceb8cb2d9488378a2ea765c6c19be594n/aHeodo
2020-08-12BAL_PO_08122020EX.docdoc 4020a8982e70b51b150cd40a837ea5dfceb35f0a6c9f9858b3fae5e00404ae62n/aHeodo
2020-08-12C_2340924911389833985328653.docdoc 5039852e09153172ff5ef82c3e169e6a8c73a0b9f50c3ccdfac9773c3918bc09Virustotal results 28.81%Heodo
2020-08-12229304005324989.docdoc ac38a17c79443f9efb6c3c9ec810744944877100bf33dbdc16487cf13181db55n/aHeodo