URLhaus Database

You are currently viewing the URLhaus database entry for http://ikari24.com/adsl/attachments/da8hf69a/ecfg39490438345411300v44pgkvi335dchf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431399
URL: http://ikari24.com/adsl/attachments/da8hf69a/ecfg39490438345411300v44pgkvi335dchf/
URL Status:Offline
Host: ikari24.com
Date added:2020-08-13 00:52:15 UTC
Last online:2020-08-13 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-13 00:54:02 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Takedown time:8 hours, 17 minutes Good (down since 2020-08-13 09:11:18 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13PO_08132020EX.docdoc a8bba76a96bc1cc1852b0b70a3e75776d9dda9cdd9a5978c25f38dd031cd1d4bVirustotal results 27.87%Heodo
2020-08-134997517515846989256.docdoc ba510b5a0f97430a09efbd12acbb4c1be869e71e678adf5fa0b5498fb477068eVirustotal results 28.33%Heodo
2020-08-13VOW_080120_JJZ_081320.docdoc f3288815441008b2291c6b17d597d58fe606f7475c4641bacba49ad56c1b1142n/aHeodo
2020-08-13REP_PO_08132020EX.docdoc d3cbf8eb26742271a0281233827b52ab52334bef5335d0f8a27c9db613de55c7Virustotal results 53.33%Heodo
2020-08-13FILE_00674115.docdoc aa6d1d92278957eef1af09829bba94b4b37a84b56cb33e65cd070f7ada92e244Virustotal results 51.67%Heodo
2020-08-13AZKJ6H94.docdoc a5f57f7cf9288f13cd7e297715c8e108eb7cafb64d3f8241811e872196857d08n/aHeodo
2020-08-13T_NVANX0CAM.docdoc c2bb5e128810c06abd15ad3ef0bc95622c20da154ca500892972305c94feabedVirustotal results 52.54%Heodo
2020-08-13PO_08132020EX.docdoc 2ec1025c3a44b35de74853b22998ea439d6eb5f0d92d9065256692f0deadcbd9Virustotal results 51.67%Heodo
2020-08-13FILE_HN9708873267JL.docdoc d6c79b4a2f215faeb9618b79dd4f61e19017ccb05671741339b78de3753744a8n/aHeodo