URLhaus Database

You are currently viewing the URLhaus database entry for http://kereselidze.com/Documentation/3ib95dook/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435256
URL: http://kereselidze.com/Documentation/3ib95dook/
URL Status:Offline
Host: kereselidze.com
Date added:2020-08-17 23:24:34 UTC
Last online:2021-02-14 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-17 23:26:02 UTC to abuse{at}magtinet[dot]ge)
Takedown time:6 months, 0 days, 11 hours, 43 minutes Bad (down since 2021-02-14 11:09:51 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-17BAL_90672376.docdoc d455be8bab47cee43ba5e71e1ecb482cddbc0c320d39874a081d23d5d27d7fa8Virustotal results 72.88%Heodo
2020-08-18BAL_23TMWMPRXPR.docdoc eec53e193ef4301a8a7e0c901b5525cc447136daa569cb0a4e589d75bed15be9n/a
2020-08-18W_NHIDPCKUZK6.docdoc 27c375a8f3878f06b0f95f14705dbf8400f42c0208bdbffc432c9fe9be231b7aVirustotal results 41.67%Heodo
2020-08-18DOC_6002695069780261160771969.docdoc 4b2c463c130aa9358e9853fd7af4e476c3f9721168623f6befc47050979d936eVirustotal results 42.37%Heodo
2020-08-18FILE_1LUUW8M7SXLEMS.docdoc 5b6530e4d580725b37bd1d03eeb44c472d0529b1422b830bebdc62bf8b6d0c83n/aHeodo
2020-08-1828953295436759.docdoc 5fd9d575a13678e66d43f02aa919121a34f26ff8ef42fd2b43a475f1e96a0188Virustotal results 40.98%Heodo
2020-08-18464673237740408.docdoc a9f2dfb969ec4a5c09edfdcf49a041eed112c8ef64c36610131b1ef17118292aVirustotal results 41.67%Heodo
2020-08-1737231804.docdoc dff1df7c560a8a24caa14cf006d941b7c3d80648923fc99f691cf668706dd683n/a Heodo
2020-08-17FILE_4A59NPQ.docdoc c0bd051153ba3fc559191e1a744dafb51332259e42fe8e436dade8cc96fae9een/aHeodo
2020-08-17REP_730770730.docdoc 6cfd3bc71ff38c615ec9c2b54e9f7b2a878e5b34918ef26526b8d2695f04ba6eVirustotal results 42.62%Heodo
2020-08-17LND_51436817.docdoc 7b77207a79af88d9ae875004fe564803f06bf6fc32432e99635e7910c43e720dn/a Heodo