URLhaus Database

You are currently viewing the URLhaus database entry for https://alpr.linkgate.ml/nvo2qqq/OCT/ixpnfela/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432619
URL: https://alpr.linkgate.ml/nvo2qqq/OCT/ixpnfela/
URL Status:Offline
Host: alpr.linkgate.ml
Date added:2020-08-13 22:52:03 UTC
Last online:2020-08-19 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-13 22:54:02 UTC to abuse{at}a2hosting[dot]com)
Takedown time:5 days, 18 hours, 36 minutes Bad (down since 2020-08-19 17:30:30 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15INV_OFO_080120_QEF_081520.docdoc 55f8854dbcaa2832aa10f768c129ab27544b5b153c7e4ea008f7ae9444681eecVirustotal results 47.46%Heodo
2020-08-15S_68914892.docdoc cbcab8fe8de37aa8149b376e9debdd37d4d56c928e607a6b3f3ecda3a741dce7Virustotal results 40.68%Heodo
2020-08-1407348871.docdoc 264dc22a6bf14f16c4cc3d66fac070d1a3758fa9cd97e761f7d239fe3b23654bVirustotal results 22.03%Heodo
2020-08-14ZQUR_91217293.docdoc 04de242641cf8fe86bc455b923b2cef373975666c56022b3b905cf452fca64d8Virustotal results 37.29%Heodo
2020-08-14DOC_70245453.docdoc faf84d497b5e84b1bd618c248355cf615ad54d45cd29b96c570a3a9c9b8d105bVirustotal results 35.00%Heodo
2020-08-13INV_105225247434.docdoc ae61420aebc07da884917752dcdac62809ccd7a3eb2ed470a3b6c810e7635adfn/aHeodo
2020-08-13INV_ZAU_080120_KSI_081420.docdoc 33cb0c5b82e157a05e07fd93c39a559493e996fae82d0a65335e761541f9b105Virustotal results 36.67% Heodo