URLhaus Database

You are currently viewing the URLhaus database entry for http://kottonhood.com/adminpanel/common-resource/open-cloud/dh14z5kgbiy3-s2x809537t5v00/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431495
URL: http://kottonhood.com/adminpanel/common-resource/open-cloud/dh14z5kgbiy3-s2x809537t5v00/
URL Status:Offline
Host: kottonhood.com
Date added:2020-08-13 03:31:36 UTC
Last online:2020-08-13 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-13 03:32:02 UTC to abuse{at}publicdomainregistry[dot]com)
Takedown time:15 hours, 22 minutes Good (down since 2020-08-13 18:54:20 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13dat_2020_08_13_671997.docdoc 46927454721c5e3fd90b2fee4870ce3ed1164f837680278f19478136a5480023Virustotal results 33.33%Heodo
2020-08-13Inf.docdoc 658b81e912c908e06150b1351a244262cf277f4c99003a8f7599354d478a4657Virustotal results 33.33%Heodo
2020-08-13rep-WZY770748.docdoc d43376a9677bdd25b14f07f6018d3b77196925c879b8709f2d83fb5c4b0d25e4Virustotal results 35.00%Heodo
2020-08-13MES-2020_08_13-JRY34710.docdoc f9c8ab13c75b9b4f583962eddd9376163fe85a8e12736648689168bca6f49511Virustotal results 30.00%Heodo
2020-08-13Dat 20200813 21706.docdoc fdf01790e32780da83434ba20976bbb51b54fadee6bb76b399dac783936926a2n/aHeodo
2020-08-13Dat 20200813 39789.docdoc 793ee0c1c89b9276d2efac9fbd6234a0ea5f1a007f65dbac2cc78323aa754793Virustotal results 30.00%Heodo
2020-08-13FILE 2020_08_13 J60040.docdoc 5a3a976d0bcfa77a2062c3cb8209c49850ed86d7af095efae956cce532ad9535Virustotal results 28.33%Heodo
2020-08-13Arc 20200813 727.docdoc a29171156f8613e2fb07ecaddce758a942371a5df390af684dd26d9eb8c58629n/aHeodo
2020-08-13INF_2020_08_13_BW1657.docdoc 0ea9f851fe1ad8e20a6006bc87e6dbf46665d52e6fbb5924c36962fa8bd30ef2Virustotal results 26.67%Heodo
2020-08-13DAT 2020_08_13 BA934294.docdoc a9e97cd44d571b602a1a710895d7a187c895248302aa3f6d52eef243709d9b13Virustotal results 30.51%Heodo
2020-08-13Rep 962993.docdoc 17fcb8fe842886a12009f2e21a1c76e37266f19254335e5a41386063c232d0cdVirustotal results 30.51%Heodo
2020-08-13REP_721.docdoc d111f7e51281671a4be10bc8809880ae95ecd11d99abd63fc1ad6f85395ee191Virustotal results 30.00%Heodo
2020-08-13inf 2020_08_13 UX05103.docdoc ed9b538ccde9fa35497f0d75bc42390e77699f3ec515a3ef5b226c091dcc8c1bVirustotal results 29.51%Heodo
2020-08-13inf_2020_08_13.docdoc a394f307a1b2d631b8a4be1518f22884983b1ab8d5bd5e922c492a92026752d5n/aHeodo
2020-08-13MES-L865611.docdoc 7c1ec9b4be7e6c0c420ed6c2788fe96b85289280dc2a9631f084f6223d03a440Virustotal results 30.00%Heodo
2020-08-13File-QRC9421.docdoc aedfbb4721ad66a54bdcee74a01bec2eff0a704e45d508a6625bc9a574266b09Virustotal results 28.33%Heodo
2020-08-13file_2020_08_13_HVZ517527.docdoc e6dc6e50ffc9a797059e2694751f99b03d4952479b2b4d8afb40b5b1b809cba4Virustotal results 26.67%Heodo
2020-08-13Mes-2020_08_13-678776.docdoc 8e34aac321039ce22c7bbb89b61257a397013e7b62607102bea64b2fb1f61960Virustotal results 26.67%Heodo
2020-08-13Dat_20200813_6267755.docdoc 76bb490090bed7074824b7b620db247726602318c7acfb9e1c16861b79bfdf3dVirustotal results 28.33%Heodo
2020-08-13Mes UN1396.docdoc a547b1929ab490afde0868812aa109aad11e71f8df07ca4325c556fe506072a5Virustotal results 26.67%Heodo
2020-08-13REP-20200813-6566709.docdoc 21c04e61b8204b3b63d3420fcf570b5d7d063338639fac037a6748df5386e1a8Virustotal results 27.12%Heodo
2020-08-13list-65741.docdoc 5c70b1d9be2e62d3cb581708789ffcafdc47ae8733f09039db0c3c7bfe9041d9Virustotal results 51.67%Heodo
2020-08-13FILE_2020_08_13_GXM448951.docdoc 57fcedf7b710607daf3ff9d1d3f81b02e5597d6a760e10c3af3805702f2e2ec5Virustotal results 51.67%Heodo
2020-08-13Rep_2020_08_13.docdoc 059d90ba2fdda046ef59121b28ea19e6e7d5b9560b0ce0dab9234e0b0c93e56bVirustotal results 53.33%Heodo
2020-08-13Arc_X702095.docdoc d88d0131f8422f4ca25451d4c1f3642d6bcab4aa071bbf0cfed86e54a6e62976Virustotal results 53.33%Heodo
2020-08-13inf-20200813-1849.docdoc d16cd96a6382c743e97444d51967f3d83c72ca0618c6d92facad07211712c9beVirustotal results 51.67%Heodo
2020-08-13dat KY9501.docdoc 34b90b804ac07f37b48a7437f520d80dd3efe9bc79c96c722240c63d9e457164Virustotal results 52.54%Heodo
2020-08-13List.docdoc 95b4b56cd387e84d98464776533fc9c64ba2102ce84cf990e49dc6cbc17dd8d3Virustotal results 52.54%Heodo