URLhaus Database

You are currently viewing the URLhaus database entry for http://kushaalgroup.com/wp-content/241561-r6iO1U-zone/open-cloud/3538908848207-sKZlJIsYsp2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435719
URL: http://kushaalgroup.com/wp-content/241561-r6iO1U-zone/open-cloud/3538908848207-sKZlJIsYsp2/
URL Status:Offline
Host: kushaalgroup.com
Date added:2020-08-18 14:22:20 UTC
Last online:2020-08-24 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002873879 created on 2020-08-18 14:24:08 UTC)
Takedown time:5 days, 22 hours, 55 minutes Bad (down since 2020-08-24 13:19:58 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-20rep_20200820_87679.docdoc 48c065c3c6c626c7fca855686845bf480a74dd0902ae005eeea171dcb5237947Virustotal results 23.33%Heodo
2020-08-20LIST-2020_08_20-SNM463432.docdoc ce3ff108a607fa2314a8bcbced388fe05dd7231df86db8dbd4beb6271388f1cfVirustotal results 23.33%Heodo
2020-08-20FILE 6318.docdoc 9e62c23b5b500ce62172589cab6a3ff383923f5278baff7ddd3d3e91e6c350bbVirustotal results 22.95%Heodo
2020-08-20List_JC63810.docdoc 41e41e5f1f8b2aff80e45e953dd83940e4b3f419f749158861614405f686a5beVirustotal results 21.67%Heodo
2020-08-20doc-AJ2027.docdoc d8a8a0f1dcbf50e189a8b0433e5c62e8ff908e4b29ef93c4d0ecb9efd87402a5Virustotal results 21.67%Heodo
2020-08-20rep-20200820-X1820.docdoc c770bba68818296583e90edb1401e456254a70721f9572ed9036d9a4aabd3aa5Virustotal results 22.03%Heodo
2020-08-20inf-2020_08_20-QX2171.docdoc 2aa3ae963e12e360ed0aa0cac15bb33e19e9359e7b08e7b2f9055df72c76c34fVirustotal results 22.03%Heodo
2020-08-20arc 2020_08_20 L613626.docdoc 93d43e8efd2b7c13c0695b9ccd0026d2b289bc0a681d091d568072044de9d886Virustotal results 22.03%Heodo
2020-08-20REP.docdoc 378b412d3de776d01ec9fdec9de5c4af668d37871bd5ef9d2eeb144eb21b5d01Virustotal results 21.67%Heodo
2020-08-20LIST OB651.docdoc 385b99deb4659a9229df342c92919b54428710364712aa73f5de71245a8e4e55Virustotal results 22.03%Heodo
2020-08-20FILE 20200820 YPB68153.docdoc d2facd4ae0b3d244e4f38cb95e23764ff0f8854d9d6a7e6c8204561ac04a6f07Virustotal results 22.03%Heodo
2020-08-20inf_20200820_53832.docdoc c0f5f0a1aa4c69b6453e9e1156ce1e886eb92d0b1114a63c47ae2ab0f4923841Virustotal results 21.67%Heodo
2020-08-20mes-20200820-A9668.docdoc a6495ce0634ebce9b181f45914574e07b54400238c8a8eeeacd6516ccce7752dVirustotal results 43.10%Heodo
2020-08-20rep_433800.docdoc ff2219bf2a6e79b513db9d0cf17c1ba49ab9b6b9b64ccc86662e2a8090a54b13Virustotal results 41.67%Heodo
2020-08-20LIST 20200820 NIU21610.docdoc 89b6ed4e8a0cf8a07e457b0f616f06fc4770fd168802ee6180994858453dc3f3Virustotal results 40.00%Heodo
2020-08-20arc 2020_08_20 IP856138.docdoc e47caa21a204cff18af76ca9418e048f41e70ffea406ea5c41bbb6fc6bac357fVirustotal results 38.33%Heodo
2020-08-20Doc 20200820 58127.docdoc f28b0ecc48cbc29c0012148055d79a34ab74c7915bf0cca7ba368c935913dad2Virustotal results 40.00%Heodo
2020-08-20Doc_20200820.docdoc 187e9bdc1e2164fcf26b37b0dd2782d45ce5e77204d07e62415fab629ef1c691Virustotal results 42.37%Heodo
2020-08-20Dat_20200820_8864.docdoc 139d96003a5964f811cfd1d2a1c28130de97b7b0a548b04e7eb8dbf7331d94e3Virustotal results 40.68%Heodo
2020-08-20list-20200820-080.docdoc 6679ce1f8ad158f0d6b60d0ba53a9320239863e3250674f436ec67091b98ae80Virustotal results 38.33%Heodo
2020-08-20Mes EML18520.docdoc 5ad149456e0772a69b4139cd61954bce1285c24eb8e99a88b9570736e7ddae47Virustotal results 36.84%Heodo
2020-08-20inf 2020_08_20 6520613.docdoc 3ed76020d61aa516417f737bb0253133123f00212219db1ca4cf1ac0f1ffc95fVirustotal results 38.33%Heodo
2020-08-20REP.docdoc 93f9d6bb9716c6966fe42149253438f3efccaa82e2ead12abf9bcaa2ee75164aVirustotal results 38.98%Heodo
2020-08-20Mes_20200820_DE88379.docdoc ee9234daf1c51abb50e560523f8b3dcf72911fe6ac98f37e67a8b62f595c7e93Virustotal results 38.98%Heodo
2020-08-20Arc-2020_08_20-WAI561836.docdoc 14837e0fca7286d6b85e13b9a9f1d5498b6a30241cd7cdfc59b5adcb0547be15Virustotal results 38.33%Heodo
2020-08-20inf_2020_08_20_501.docdoc 34df63aaf08820ef807a0992d54df52142bea2fc2135e5f4012ab9f1f89aaac9Virustotal results 38.33%Heodo
2020-08-20Rep 20200820.docdoc 81bed19efa97ba8177bda3736a8ab04d1a331974d94e3ccbda0e1c85f0cde5d5Virustotal results 38.33%Heodo
2020-08-20Rep-695008.docdoc 6524abb8b7a32931b5793239b4348d8b69b6855b4cdd5ac8f73b26e854c36139Virustotal results 38.98%Heodo
2020-08-20ARC_20200820_IVP35566.docdoc 2689c419bfbe55bbfccf9898fc0f3589fe6f3f905e0ce33e5b65944e9a01e597Virustotal results 38.33%Heodo
2020-08-20inf 20200820.docdoc e5da2bc79938c38b6d1deb7265a10cef4adb6664addab2bc3739942b0a0d0d34Virustotal results 33.33%Heodo
2020-08-19Doc_3508117.docdoc 2c5b0a5c645d8ca87fd7a703e770536a91e2178a14a3b50980fc71231a5c9049Virustotal results 32.20%Heodo
2020-08-19ARC_NX36760.docdoc 0cd31f3fe195cfa0c025d27c1cf6ad200d8228b2fff802412181fece4bbf5155Virustotal results 28.81%Heodo
2020-08-19LIST_42178.docdoc 18f2491dcef8d7f0113049e146994fc5a8fc1615ff0fbbd659fa0a5d580ea72dVirustotal results 28.07%Heodo
2020-08-19LIST_20200819_49727.docdoc c940432dc1875cdb1adfbda4eb2c3a23b3a10fd0a53cf12cc32e79389120b5d8Virustotal results 26.67%Heodo
2020-08-19rep_MD811.docdoc 7b1214f3fa1a87909df1dc2aaf3d66f4ef5ebe9cc2a8040bffa44e44e28ae36bVirustotal results 26.67%Heodo
2020-08-19Mes 20200819 215483.docdoc 949d5111399eaea6135927548fb0154fd3b99217f2e5556ee5b7efb4eeb8d813Virustotal results 27.12%Heodo
2020-08-19INF 084929.docdoc 7dc844f8716dcdfe52e129c179b48139c29cb20831bd719a02b8120135a7ddebVirustotal results 26.67%Heodo
2020-08-19ARC-C9671.docdoc 7c9a4d56c192bd2e71e2098965b8affdfaf10cc6e3e5ced40ede0fd1c947d50eVirustotal results 27.12%Heodo
2020-08-19Rep 2020_08_19 VXM24873.docdoc 480761889ebb7040b138b87207419aa6634dfec3a5c8b3672392b21bfb15c46bVirustotal results 26.67%Heodo
2020-08-19MES-20200819.docdoc ad1cd733252039fe55df9241f672a3e0dc2435552a2f48e40f56477612916743Virustotal results 26.67%Heodo
2020-08-19REP_20200819_963.docdoc 5a69dbe048fbeb2da153621f4cb921772399169f8fc1b021e72ff4650f82f6a6Virustotal results 27.59%Heodo
2020-08-19List G59164.docdoc d54b881b142aa3ec2e3b816d4dc326d23176dee31c65f78ff9b9328f61aaedb9Virustotal results 27.12% Heodo
2020-08-19arc 2020_08_19 ZKJ3977.docdoc 4f49566c22cd95508f39368f73be4e9b6c9c8e504c519f2383cc00fb67d28c55Virustotal results 23.73%Heodo
2020-08-19FILE_669.docdoc bcec740185af19805b96a2a510bf2e824d2c3dd65c58866cc013ce08b8648e6dVirustotal results 22.03%Heodo
2020-08-19arc-2020_08_19.docdoc 35a575d3cc73b07a44de16fc04dbd04650ba5d4a0005028abc178ad78e1d47b4Virustotal results 21.67%Heodo
2020-08-19Rep_20200819_336.docdoc 017dedfe5d57e11c86048a8f6470f4d48573fc0bc581b8ef0a6e22c06169770aVirustotal results 20.69%Heodo
2020-08-19FILE-14952.docdoc b4980748305d9329f376c996a7887e4cb40713c823693998d4360500c510062an/aHeodo
2020-08-19LIST-20200819.docdoc f089aaa465591c3bda52688c4f998d141107fcbd15cb723c4f961386e2c8bb58Virustotal results 20.00%Heodo
2020-08-19File R932267.docdoc 02efef8ede900c86814ee2bdbd43c88bda71b970e85d0320bdb50feea29dc6baVirustotal results 18.33%Heodo
2020-08-19REP_2020_08_19_NQ19619.docdoc 440bce9e28d9e45a9b6158c91047a6bcf28d0f4cbd2dad43f041d74beda848b4Virustotal results 20.00%Heodo
2020-08-19file-2020_08_19-SHN264944.docdoc 124ae2447478f4b71404f5f07ea89abe4b985e402955ebcd02fb67b27939de31Virustotal results 19.30%Heodo
2020-08-19list_20200819_615.docdoc 47375ee765d009fcfbc20d212b828e35b6ff6c22fd0a478f90f24800cc21ef29n/aHeodo
2020-08-19doc UQH2639.docdoc ac5d6169036212c360d8f4232685f6664041d612f03126d5ae29a48dfdcf2d1dn/aHeodo
2020-08-19file-2020_08_19-VPZ295.docdoc 8c8c9a461837ed77d0dcfda29092e08452817660cf5a56a7e9547741960e43dcn/aHeodo
2020-08-19mes-GMC428.docdoc fc3d622adccc98bf7aee3ff98037920892cf9ec8e29b6a2de393217d74499b7en/aHeodo
2020-08-19DAT 20200819 2174318.docdoc e9da8132017bc36f1448def9ba8b2ea44184e68bf955c08ba75f2560ade79372Virustotal results 18.33%Heodo
2020-08-19doc 2020_08_19.docdoc 17904f8a80c29c5ed3d3048aae5f62027b918b756006c67893220e03e7a0d7c8Virustotal results 18.33%Heodo
2020-08-19ARC-2020_08_19.docdoc 4798faf76258c8ed12cd2d43a683e3c56b6fadbcbc5b6e7a797ca73e76ed49dfVirustotal results 18.18%Heodo
2020-08-19LIST 2020_08_19 AZ182555.docdoc 44116755a469545747d98ca4dad33a22c5565d571be3001cb95cb4971c532c3cVirustotal results 18.33%Heodo
2020-08-19file-20200819-FZ171.docdoc 55243fe4d8aaffb5742798883e5ebb342f4cbf5eb2b4ea32c0f3603c658ddc93Virustotal results 18.64%Heodo
2020-08-19dat_0105585.docdoc 06f924f51874c7df81f49a607dddc6e977b700d5ce712232c7e962d77150bb01Virustotal results 18.33%Heodo
2020-08-19DAT_2020_08_19_JNG331020.docdoc 06a4431e2a5467fd8f9c297a6a25e670ee44231c92dd38d8f998a3a93115f0c9Virustotal results 18.33%Heodo
2020-08-19Mes-2020_08_19-2504.docdoc 2b815dffdace46c2316ebb0febb0efa9a74420d58418169469b0ceb0356abfb5Virustotal results 18.33%Heodo
2020-08-19doc_2020_08_19_712.docdoc 741441215f02f536e57bad81a0cd2549669c22dabf11a9db8076f3e7ec6acf1bVirustotal results 18.33%Heodo
2020-08-19dat 20200819 23983.docdoc 3399e67ca5bc2ba980f608d742babbf889c3a0486bd791934b8f779022b262edn/aHeodo
2020-08-19Doc_20200819_LSO993496.docdoc 1dd9e898cf2ef400f93bb6759c7453980dc396b70c7c8748055db01b62685f2aVirustotal results 18.64%Heodo
2020-08-19ARC-20200819-ADO67959.docdoc 6409ea14c150741b3551828dcbbc20e14505bdad2f9a8eee4f450a80878f6519Virustotal results 18.33%Heodo
2020-08-19File_20200819_583254.docdoc da820b108be2808d9d5d1909a3d8683f33f902abe5ae4e5e319d6aa766aba61dVirustotal results 47.46%Heodo
2020-08-19FILE-5813114.docdoc b7bdd06a64996f7d16cffc6e46115bc8ad4810d39a77f97489406b878041fc4aVirustotal results 47.46%Heodo
2020-08-19Arc_20200819_CNW18934.docdoc 09d725bc4314f587c3132842fc1d924a1ec4952620d18e32796d3797b90e66b0n/aHeodo
2020-08-19LIST 20200819 ZPA042203.docdoc 305d205cdb3c030f05543db463c783753137d91a3d8c2721189a94fb36e4f7c6Virustotal results 47.46%Heodo
2020-08-19List-20200819-T512.docdoc a0096856f8887d5cdf7d5f2e6805694ac96da153aaaa326ef25ee058e6c6a683Virustotal results 46.67%Heodo
2020-08-19Rep_2020_08_19.docdoc f6feee3a8137cb0cab6667842f06e07f96e54fc2f15ebe079dc30b4060d52452Virustotal results 46.67%Heodo
2020-08-19Rep-2020_08_19-3457.docdoc af3f70492545cd6391ad67cedb9347c9e78980d2462b1b1a6b656113d246e010Virustotal results 46.67%Heodo
2020-08-19Doc_BV0401.docdoc 8ecfd0e0dbd4257b0b0f97f99517f9d1d825e32d7862b1ceb1b6bfdc67b205a0Virustotal results 45.76%Heodo
2020-08-19ARC-2020_08_19-297599.docdoc 9f95680d93e52258b33600da99d066d953f0aa373f991d850e83ae0e050fdb4eVirustotal results 45.76%Heodo
2020-08-19doc_2020_08_19_X683.docdoc 3b4441c0d07aa3869dd4e8928a0b764028f96262d45ffb00ef0d4275c66fce02Virustotal results 46.67%Heodo
2020-08-19Dat 2020_08_19 8799.docdoc 5a63ce9de6a721eaabedc5a95a579a3eee404a94034db171f646e24517fed367Virustotal results 46.67%Heodo
2020-08-19file 2020_08_19 AUA8468.docdoc e94bbfc806ca8e6182447d1f10e43d213e234887abec37e993057a77a51e3132Virustotal results 45.00%Heodo
2020-08-19Rep-994433.docdoc 45a1dbdb6b372ed28b9806469cbe031baa76035067cb69b5e936960e53988a80Virustotal results 44.83%Heodo
2020-08-19Mes_4022.docdoc 04f5fb6798ce3949fb5191ed7c89dfc725231489c34bf2369d98e5228a6efcdeVirustotal results 46.67%Heodo
2020-08-19mes E632.docdoc eb36ddd9edb9f64c1d10743135f87875826990fee2cde8abfcc653b1045c9061Virustotal results 46.67%Heodo
2020-08-19Inf_67820.docdoc b4109096624dd29f07d9e5c328637c66396a4c0ba53760b48905a4d81e829027n/aHeodo
2020-08-18dat-8533.docdoc 5644494f53e0f58e39e8c623b06d33e093d920e7728632366beaa74ce3ce75a2Virustotal results 43.33%Heodo
2020-08-18dat_20200819_YLX78932.docdoc 85d051184c78737bf858c74a6fe5cbf9d30ed82b3ace8cad4b7555c5132cb11en/aHeodo
2020-08-18File-2020_08_19-0912.docdoc f7f2b55cdbf9f24f6e1850b32aa87b859717f840d46caff776674a973d28d51cVirustotal results 43.33%Heodo
2020-08-18LIST-2020_08_19.docdoc 8f47cb493376d43a1a8f2ccadec7a4cade6df8e86bf5159d54781451519064c3Virustotal results 44.26%Heodo
2020-08-18Inf-20200819-4699.docdoc 942ccd6baa3b3eea249f01497d82b6835ddf27ab79c9db9561a3f473e05eceaaVirustotal results 43.33%Heodo
2020-08-18File-2020_08_18-LHC144.docdoc f4b06b5878e6216de2fd744371e3da706006cd0eaab9952e028ed23bdb5b89d6Virustotal results 43.10%Heodo
2020-08-18file-YAT937.docdoc 38a85f6b82ce5d88a70ee0bc98517b5d3d4f82516e1532a0085c7c843310e350Virustotal results 45.00%Heodo
2020-08-18Mes-2020_08_18-UY218.docdoc 1a8c5bc937330472d676469e981466649ed28cae04d2f3273b0648e96ee6609eVirustotal results 43.33%Heodo
2020-08-18MES-20200818-0829825.docdoc 2665e27cc12b9a111b35b73a7afd85da8a5d1877d6270f6d8ea48edd2acc0718Virustotal results 42.62%Heodo
2020-08-18Inf 20200818 199.docdoc 52386a3f4ed721abc491a22e4d08ba4497e8392249b04e5fbcdcff39502cb314n/aHeodo
2020-08-18Inf-EC5616.docdoc 72d943737f8d648bf65f1f9071ab2656abc7a9095e4bb53f4be92836d49aaca5n/aHeodo
2020-08-18DAT-20200818.docdoc c2c31857eddef908bb15ebce07f54e91a068ffff5b92014fd70c1d5ce8f34cd6Virustotal results 40.00%Heodo
2020-08-18Rep-2020_08_18-8348.docdoc cae4e9249f1219782d6c234dc44eab63930830f75ab90f4d533f0ddd3bacb745n/aHeodo
2020-08-18arc_K4719.docdoc cbe9a323a3f8c6f8e119d5765df5d8c8aec0899db8729b8cc5f63e877925173aVirustotal results 37.29%Heodo
2020-08-18List-DPR61959.docdoc 220f661d5186fcdd525b47c5a909197b80b076950ab2a2f94b6799328cbd1f19Virustotal results 35.59%Heodo
2020-08-18mes_2020_08_18_448.docdoc 46411363967383fde95f164b6ca16cdf6f2da8a1269ee7c150b892d445cc9f20Virustotal results 29.51%Heodo
2020-08-18arc-G35394.docdoc 96c73835686797a5dbc5dbd37ef4a7291b69f848d7ca403c9ab404f4f7f650e7Virustotal results 28.33%Heodo
2020-08-18FILE-5407996.docdoc b5fc512f17b6959fef800f246c73b92f91a86868468e1a4786c4cba27ffeb10eVirustotal results 25.42%Heodo