URLhaus Database

You are currently viewing the URLhaus database entry for http://www.textnook.com/fonts/personal-disk/rP0wXv2n-7c3RVmaeSSfXi-portal/geD4LBt2d-hKu5qilHa7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435927
URL: http://www.textnook.com/fonts/personal-disk/rP0wXv2n-7c3RVmaeSSfXi-portal/geD4LBt2d-hKu5qilHa7/
URL Status:Offline
Host: www.textnook.com
Date added:2020-08-18 17:32:04 UTC
Last online:2020-08-25 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002874212 created on 2020-08-18 17:34:05 UTC)
Takedown time:6 days, 21 hours, 25 minutes Bad (down since 2020-08-25 14:59:50 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-20DAT_20200820.docdoc 788a6214e334b44cf8c8bba7364d3bb9d99f6e05b9826dcb25152b5c48b8932eVirustotal results 25.00%Heodo
2020-08-20Inf-20200820-EIH86904.docdoc f5be70e882f02bf751e015d8c9556ea178965de2e4970ecba123aabd8a83e636Virustotal results 22.03%Heodo
2020-08-20INF-2020_08_20-1585.docdoc 352c1ef29ac574fdf89bfcdbbb5f78b4cca4553a8945ab3cd57a1bcd9909da27Virustotal results 21.67%Heodo
2020-08-20dat S86605.docdoc ff2219bf2a6e79b513db9d0cf17c1ba49ab9b6b9b64ccc86662e2a8090a54b13Virustotal results 41.67%Heodo
2020-08-19Mes-2020_08_20.docdoc 3209a90ec70f3c389ad600fad212afe06d4d60c9ebf4535af52b590f95c642d5Virustotal results 27.12%Heodo
2020-08-19DAT-20200819-80637.docdoc a914138cab6d64aaf2c57366a13ebfe0ad1cb2f1821402a26a4c03e8ac8d2781Virustotal results 27.12%Heodo
2020-08-19REP_20200819_027.docdoc 7c2fd9efa308be75d919032ea14df78aa0f9020fec7077fd3c4f80ae17285a76Virustotal results 20.34%Heodo
2020-08-19File 20200819 PR132.docdoc 96145efbcc291c15996cc347115acf0458e734937681b16fc1a262f739b27518Virustotal results 18.33%Heodo
2020-08-19Dat HV17139.docdoc 99fac49e296895c2ca6a405eaf09152400df0b7f4793df9f84e618d127657aa2Virustotal results 18.33%Heodo
2020-08-19doc_2020_08_19_BXZ8012.docdoc 06f924f51874c7df81f49a607dddc6e977b700d5ce712232c7e962d77150bb01Virustotal results 18.33%Heodo
2020-08-19DAT NA357.docdoc 06a4431e2a5467fd8f9c297a6a25e670ee44231c92dd38d8f998a3a93115f0c9Virustotal results 18.33%Heodo
2020-08-19Arc CA90216.docdoc e539186195154e173115f68e790dac9a32909a8c4344a387ce25fba6fbf55d27Virustotal results 18.33%Heodo
2020-08-19Rep_ARL945.docdoc e6cfec7c5e5016b798a2d0838321003cab29be4fd7d6311ccb69c0be740618c7Virustotal results 18.33%Heodo
2020-08-19FILE-20200819-H1447.docdoc 3399e67ca5bc2ba980f608d742babbf889c3a0486bd791934b8f779022b262edn/aHeodo
2020-08-19FILE_G83298.docdoc 82b2463c462ac62073f95ada6f8aa70c265d0d7ca216a36322994f2d464bda58Virustotal results 20.00%Heodo
2020-08-19list_20200819_TK272.docdoc 6409ea14c150741b3551828dcbbc20e14505bdad2f9a8eee4f450a80878f6519Virustotal results 18.33%Heodo
2020-08-19Arc_20200819_2787646.docdoc 2dea73b6391db01c0900ef660c75b0841dcb9fd8fd91c892a5faee2e9701606eVirustotal results 48.28%Heodo
2020-08-19Rep_2020_08_19_M132739.docdoc a09fb497ce5738081489fafa343ed354128eba16cc5f8f6bfbb26ff79e19ceebVirustotal results 47.46%Heodo
2020-08-19dat_162578.docdoc 1c98753feb43790bf0b2979ae0d73c4760638ab1d9c5d6b6336ce2241ba31aa4Virustotal results 45.76%Heodo
2020-08-19dat-LK989005.docdoc 305d205cdb3c030f05543db463c783753137d91a3d8c2721189a94fb36e4f7c6Virustotal results 47.46%Heodo
2020-08-19Arc_UZB727616.docdoc 7065577cfc7f1d2a71a9044c23838d7703f1a1e02b2c222ab507407a778aae24Virustotal results 47.46%Heodo
2020-08-19Arc_2020_08_19.docdoc f6feee3a8137cb0cab6667842f06e07f96e54fc2f15ebe079dc30b4060d52452Virustotal results 46.67%Heodo
2020-08-19inf-2020_08_19-TE94079.docdoc af3f70492545cd6391ad67cedb9347c9e78980d2462b1b1a6b656113d246e010Virustotal results 46.67%Heodo
2020-08-19Inf 20200819 P0827.docdoc 8ecfd0e0dbd4257b0b0f97f99517f9d1d825e32d7862b1ceb1b6bfdc67b205a0Virustotal results 45.76%Heodo
2020-08-19inf 20200819.docdoc 9f95680d93e52258b33600da99d066d953f0aa373f991d850e83ae0e050fdb4eVirustotal results 45.76%Heodo
2020-08-19ARC 2020_08_19 0950.docdoc 7916fa0619bd4a976c48a8b068040591dd8f78f9eb5b2bd3abafc019ec1f0dadn/aHeodo
2020-08-19DAT-VIR644947.docdoc 5a63ce9de6a721eaabedc5a95a579a3eee404a94034db171f646e24517fed367Virustotal results 47.54%Heodo
2020-08-19doc_20200819.docdoc 682cb4ff880f1a6a000f5a227f8dba42abd73d836308162dc519644d9dae94efVirustotal results 45.76%Heodo
2020-08-19mes-HMK39129.docdoc 45a1dbdb6b372ed28b9806469cbe031baa76035067cb69b5e936960e53988a80Virustotal results 44.83%Heodo
2020-08-19File_2020_08_19_GWN3163.docdoc 7833c0d39d11142241550af1fa9cb743026dc00c841f79a52d695fd8e9bfdd43Virustotal results 46.67%Heodo
2020-08-19DAT-2020_08_19.docdoc eb36ddd9edb9f64c1d10743135f87875826990fee2cde8abfcc653b1045c9061Virustotal results 46.67%Heodo
2020-08-19ARC_20200819_HC438.docdoc b4109096624dd29f07d9e5c328637c66396a4c0ba53760b48905a4d81e829027n/aHeodo
2020-08-18Rep_20200819_01336.docdoc eba02aeb5ab35694f34f8048ad03accea87abc6915db54d0905d905a155901ffn/aHeodo
2020-08-18dat_2020_08_19_XOF679.docdoc 85d051184c78737bf858c74a6fe5cbf9d30ed82b3ace8cad4b7555c5132cb11en/aHeodo
2020-08-18Arc-2020_08_19-248.docdoc f7f2b55cdbf9f24f6e1850b32aa87b859717f840d46caff776674a973d28d51cVirustotal results 43.33%Heodo
2020-08-18Dat_LIT9141.docdoc 91abaab1b3daa4a4dfe3d6c8adf5c5c8f0ec0551c271417fffd61444cbf47346Virustotal results 44.26%Heodo
2020-08-18Mes-KO912.docdoc 68184e955d9a5e852a40b7c215d5654f9172d35c4e7a50e24b0080bb14c6ce0aVirustotal results 43.33%Heodo
2020-08-18rep_20200818_PMQ645.docdoc 17300227be521550f2f2047dc5be4dcad326b59b87378c8a1372dbc867fb29c8n/aHeodo
2020-08-18Inf_2020_08_18_TWA229765.docdoc 2df5b20d8f749d1edb14c16c6c1c1ce78165354f3d038a23ac8d4d99188391bfVirustotal results 44.26%Heodo
2020-08-18LIST AWD49194.docdoc c998c60111b424a9eee08cff17b0f146045209d21d312a0b6b0ca71095697c8fn/aHeodo
2020-08-18Doc_1538.docdoc de7d72e073b61d24137abfd27fe66238449d71dc609887dcb78cca6b90ffe2b6Virustotal results 43.33%Heodo
2020-08-18arc-20200818-IE431595.docdoc 52386a3f4ed721abc491a22e4d08ba4497e8392249b04e5fbcdcff39502cb314n/aHeodo
2020-08-18Arc-2020_08_18-AS714356.docdoc 6259d1ed66e6b71f212718ec498a456d163ad694e8a059bb80e06aecccec4696Virustotal results 38.33%Heodo
2020-08-18Mes_KQ093780.docdoc 44833b6e9ebcdb76ab589effbf62a6054d524d128d7bff56f7ce303d511c9d3cn/aHeodo