URLhaus Database

You are currently viewing the URLhaus database entry for http://phy.sci.lru.ac.th/th/closed_module/security_space/523310819211_OckRuv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:434624
URL: http://phy.sci.lru.ac.th/th/closed_module/security_space/523310819211_OckRuv/
URL Status:Offline
Host: phy.sci.lru.ac.th
Date added:2020-08-17 13:17:07 UTC
Last online:2020-08-18 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-17 13:18:02 UTC to helpdesk{at}apnic[dot]net)
Takedown time:14 hours, 48 minutes Good (down since 2020-08-18 04:06:42 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-18MES-2020_08_18-75385.docdoc 5b2f315f6910580a86de6995dc3bb3af0bba726b0292875fbeeb557d17759d57Virustotal results 45.00%Heodo
2020-08-18MES-20200818-2758221.docdoc 9f6acf9a0b1abf9481a13650ecdec0e7a9cb7a4c30938c2ffcca8da0934a96d2n/aHeodo
2020-08-18rep-20200818-J301221.docdoc 1a92578592df96f6bc3c58861c8719f37bd57d2386789d07d319c613fcf2f79bVirustotal results 45.00%Heodo
2020-08-18inf 20200818 E625360.docdoc 77893a46e331faf345a8134849c0182109a90c65f156f288b95f054bc8bf667dn/aHeodo
2020-08-18Mes_2020_08_18.docdoc 503c77f99b0c8271cb80a1101e69d6c9060647f7a4a8451c23aae49bd344b634n/aHeodo
2020-08-18MES_2020_08_18.docdoc 403175e425e2a4c0eedf4b7a5fee64bdcb3b6e6929a1aea63dbda7f9a84e8086Virustotal results 41.38%Heodo
2020-08-18FILE 2020_08_18 IXU270.docdoc cbae984f113307015e9a42c646507cd4fecbc37c1ce7ed2fa9d731fdfff7e00fVirustotal results 42.62%Heodo
2020-08-18list_2020_08_18_UDJ41109.docdoc 872c0c3578f24be338bcaa8a29f2b157d80a2d3d5e5ecbd33b028bced714c077Virustotal results 41.67%Heodo
2020-08-18list_2020_08_18.docdoc 0ffb643d2ef22089512c5de14e1d2f14d5632e77e9f609b1374c79fbe0a788e0n/aHeodo
2020-08-18FILE 2020_08_18 EJ81943.docdoc 4426143a003042fcf53c32a42cb6e2dfa30ff4dfdf7e2248eb6533df67ac8723Virustotal results 41.67%Heodo
2020-08-18Inf_H151.docdoc e7007d098ff3b77d307fdffbc2b566e6396298bfb9718bd207a8b377aca0b96aVirustotal results 42.62%Heodo
2020-08-18List_20200818_W007.docdoc 716cb0fed68d3999a988461ba151d314310471e1ff5e5267419ad5f378da2150n/aHeodo
2020-08-18file_20200818_JCJ525612.docdoc 8bbfe9b6aae9ae8cd42ef61b046d0c690f0637f216d5a22d4a5f7911b59469f7Virustotal results 41.67%Heodo
2020-08-18rep Y1998.docdoc e976f7e4de4c0bedc4e4bbc27752994f9110c050508b106611f035260551a8e0Virustotal results 43.10%Heodo
2020-08-17ARC 7705496.docdoc cc2b2954e615657190a6b35c6784f2280cf56ca53c09647bcd8e096a005642cfVirustotal results 41.67%Heodo
2020-08-17Dat_2020_08_18_VNB389.docdoc faffee3625908bf1e2cb82c961bd1d777beeff0f87166e3aedc6fa984834c42fVirustotal results 41.67% Heodo
2020-08-17INF 61147.docdoc 32cb1657bab6cea4734f694fefe16389dca17cad7673cc0be676c77e070ae735Virustotal results 41.67% Heodo
2020-08-17Doc_IK755.docdoc 34c3b24fcdb685c45554b1bc9ab60336cfb9233e87c3f21c61bd63723fea1338Virustotal results 40.68% Heodo
2020-08-17mes-20200818-724259.docdoc 6535313a52f000bc92afec62f22968677544878c5cf2109e862e72f7c441dda0Virustotal results 37.29% Heodo
2020-08-17LIST-8974.docdoc 818e631aced6291b95a641f2eace827a0b9f2ee202b364a3a09378bc52401e03Virustotal results 40.00%Heodo
2020-08-17Rep 2020_08_18 QR97264.docdoc b217056622d2655617081ef69ad65da589c7ca744d2d1d6b666425f5d55f4644Virustotal results 38.33% Heodo
2020-08-17REP 20200818 5728.docdoc 47b3fee25d6683706ef483aa30125377edf7bb21dd17638c81c52fa7e64966f7Virustotal results 34.48%Heodo
2020-08-17MES-C652467.docdoc b5ba2a25b6b78baed8f427232afed8841e367725d1fb05bb47b5ec863dcfcf7aVirustotal results 35.00%Heodo
2020-08-17INF-2020_08_17.docdoc 3c021a95e5f5b22f4efc9f3fc678defdb4c50196549ba03786c0aa2bfead670eVirustotal results 35.59%Heodo
2020-08-17Rep_20200817_WI4770.docdoc 348368dc3b9ba59325226c159fd0b695e4256ad96894a3f58d3b97297a87a1b0Virustotal results 33.33%Heodo
2020-08-17File 5201622.docdoc 068447c2fb052258a7ea0ba47b2fa89cd69bb3a9bc9457e394de0a70a1277da4Virustotal results 33.33%Heodo
2020-08-17doc_20200817_GZV717223.docdoc 4e222c92dce7f604bdab06a48a8b26d08c4c3ff4e455795f8024e98823f1c13eVirustotal results 32.20%Heodo
2020-08-17rep-20200817-V124.docdoc da10e987e0f17cdbf08a4c765e272d4feb929d329ba74d4fb5d1d27c36c1ed38n/aHeodo
2020-08-17list_20200817_0323422.docdoc 2bf93775cbad0953590c5e66820b5cb447eaaad0b0450e53e4bbe9fb951ef90aVirustotal results 28.81%Heodo
2020-08-17FILE.docdoc da36139efceba6bdc76e654a8ee65827216781721578417791ffd386102b8272Virustotal results 29.31%Heodo
2020-08-17Dat G627.docdoc 37fa3d3cd6ac66a6c2dac81cdbfa47a07af9cc5d6103546473c07d0dec853636Virustotal results 30.00%Heodo
2020-08-17List 20200817 PW1522.docdoc e72e7fc919831a1466ce7e52f75ba5ed79a6ae5c1782de1f1e33b1130f843609Virustotal results 28.07%Heodo
2020-08-17File-KEV939435.docdoc be3ec3f71ce797fc82f6e2c0d4544dde3c5ab20ff6df9ed778b0ba1199a980e2Virustotal results 28.33%Heodo
2020-08-17DAT_20200817_814793.docdoc 7c36e6a351ea7a57bdbec894054f6a997e79596a6bd0f68845bd3b6e9eaad37bVirustotal results 25.00%Heodo
2020-08-17Rep_20200817_A813593.docdoc 414a3261de7975d33e98be8efd2d34d23f9b0f3f51146b5d771026f5eb0a27d1Virustotal results 25.42%Heodo
2020-08-17REP 20200817 YCH8774.docdoc 8b689a2b1b329de864a728b4d212d99d754ee1ba922d6995f3eba7c8f2e5812bVirustotal results 26.67%Heodo
2020-08-17list-ZOQ2192.docdoc 285cbe4cd306ae4c3557c91c2fd38e3a562f79d21643a6295b53aae718aae367Virustotal results 26.67%Heodo
2020-08-17doc_2020_08_17_10897.docdoc e484e9b8614dff68bd63e103a395b4e03576c2f72fdcba1ff45344012e0f51b6Virustotal results 26.23%Heodo
2020-08-17doc-2020_08_17-QL763.docdoc 768b963eba0a3f6936ff6a6953909f9f70e8751a3b527b73aa0bb5def1b18305Virustotal results 23.73%Heodo
2020-08-17REP_2397.docdoc dbecd98d9fd1626b3aa562d063ba66033db39d1b8e846afe8634d738feeda550Virustotal results 23.33%Heodo
2020-08-17ARC_20200817_36126.docdoc 6345eb23231f0dc6c89087b411c649f2a3259a066c20232d8e1ccaea0e0d9792n/aHeodo
2020-08-17REP X91730.docdoc 5488ced86c0349f218ebe8ee794bcca48f54e48b1be0335d03602d5a8b99a90an/aHeodo
2020-08-17MES 20200817.docdoc 43cbe67366ebd1755f3f9742473141d00c8bab73a6dbb227ec90fad08ddb07ddVirustotal results 23.33%Heodo