URLhaus Database

You are currently viewing the URLhaus database entry for http://duck.org/NATURALDOGTRAININGNC.COM/personal-BWlV-CHmXcuN/interior-vxqZdLu-pgGuu44C/txg67j6pqlv4ss-6t73810914yzx7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435713
URL: http://duck.org/NATURALDOGTRAININGNC.COM/personal-BWlV-CHmXcuN/interior-vxqZdLu-pgGuu44C/txg67j6pqlv4ss-6t73810914yzx7/
URL Status:Offline
Host: duck.org
Date added:2020-08-18 14:15:23 UTC
Last online:2020-08-19 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-18 14:16:06 UTC to abuse{at}servercentral[dot]com)
Takedown time:12 hours, 29 minutes Good (down since 2020-08-19 02:45:32 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19dat 20200819 9985.docdoc 7833c0d39d11142241550af1fa9cb743026dc00c841f79a52d695fd8e9bfdd43Virustotal results 46.67%Heodo
2020-08-19dat 20200819 5039945.docdoc eb36ddd9edb9f64c1d10743135f87875826990fee2cde8abfcc653b1045c9061Virustotal results 46.67%Heodo
2020-08-19MES_260.docdoc 5df568ab274842e91a3f5717af61fdbe6827249fc71e135fdc493f5177ccac7aVirustotal results 46.67%Heodo
2020-08-18Dat 2020_08_19 185441.docdoc eba02aeb5ab35694f34f8048ad03accea87abc6915db54d0905d905a155901ffn/aHeodo
2020-08-18File 2020_08_19 5203.docdoc 276103362e47f26f80bc04fff0f98df32d19fb0693919ac618f3c6f3c8350aabVirustotal results 45.00%Heodo
2020-08-18arc-20200819.docdoc f382710578f3df562db77ea613a75d9485ab315f7f8b7e5aa86e8120a0f0bf6dVirustotal results 43.33%Heodo
2020-08-18Rep-20200819.docdoc 5fe3b8e6945f1fd2e0c85c1b8cf1c0969965447dcb9d72deb04c28e05c9116b4Virustotal results 44.07%Heodo
2020-08-18List-20200819.docdoc 1a586ed406130c0ed7d070f24ccb79ee1b6f0b4a3f47373cfa6285ed1ee322b9Virustotal results 43.33%Heodo
2020-08-18LIST_20200818_TFY5321.docdoc 17300227be521550f2f2047dc5be4dcad326b59b87378c8a1372dbc867fb29c8n/aHeodo
2020-08-18Arc 20200818.docdoc 2df5b20d8f749d1edb14c16c6c1c1ce78165354f3d038a23ac8d4d99188391bfVirustotal results 44.26%Heodo
2020-08-18INF-9508591.docdoc 8eff0446f444542435bf1ea66d34ac5b2339a87d7702ba744f403dc5ec5d4795Virustotal results 44.07%Heodo
2020-08-18file 2020_08_18 027.docdoc 2665e27cc12b9a111b35b73a7afd85da8a5d1877d6270f6d8ea48edd2acc0718Virustotal results 42.62%Heodo
2020-08-18List_2020_08_18_U728352.docdoc 52386a3f4ed721abc491a22e4d08ba4497e8392249b04e5fbcdcff39502cb314n/aHeodo
2020-08-18rep 20200818 1793662.docdoc 28810939674484b940c1b242c2defba24f6fa84ca59b37ed3196792e22adc284Virustotal results 40.00%Heodo
2020-08-18FILE T93074.docdoc 818f55b9e395ed0a08beebd22e8e4404e570fe3f7b113c2b53cf13a36a8d1930Virustotal results 38.33%Heodo
2020-08-18Dat_2020_08_18_8779.docdoc 309fd26e7a9795873854e8c0c118cfa907651d218c46dc9dbf27b347e402f332Virustotal results 39.66%Heodo
2020-08-18Inf.docdoc 4447568080893f02a97ee86ec9e776b6d5b4f7ea644870e130a19f3df9b16667Virustotal results 36.67%Heodo
2020-08-18File-2020_08_18-761.docdoc 220f661d5186fcdd525b47c5a909197b80b076950ab2a2f94b6799328cbd1f19Virustotal results 35.59%Heodo
2020-08-18Rep_20200818_3937479.docdoc c2ddfddccb101d4e986562ca370e4c29e0ec7f510f7a657f32d61ae37a173c8dVirustotal results 31.15%Heodo
2020-08-18REP J882352.docdoc 96c73835686797a5dbc5dbd37ef4a7291b69f848d7ca403c9ab404f4f7f650e7Virustotal results 28.33%Heodo
2020-08-18list_GFW472224.docdoc 900062f8aeceaf3e82d45dac919862627ce1ef5646e173c9194626c2bb7e698cn/aHeodo