URLhaus Database

You are currently viewing the URLhaus database entry for http://tbgmud.net/paul/closed_412212_OOB4oW/guarded_ND1fQpvM_hoor8wS3k8s0BV/2131123717046_ggrQHKebxKaK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436088
URL: http://tbgmud.net/paul/closed_412212_OOB4oW/guarded_ND1fQpvM_hoor8wS3k8s0BV/2131123717046_ggrQHKebxKaK/
URL Status:Offline
Host: tbgmud.net
Date added:2020-08-18 20:09:04 UTC
Last online:2020-08-19 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-18 20:10:03 UTC to abuse{at}hetzner[dot]de)
Takedown time:11 hours, 7 minutes Good (down since 2020-08-19 07:17:07 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19list_MX0947.docdoc 09d725bc4314f587c3132842fc1d924a1ec4952620d18e32796d3797b90e66b0n/aHeodo
2020-08-19arc_20200819_Z565686.docdoc 305d205cdb3c030f05543db463c783753137d91a3d8c2721189a94fb36e4f7c6Virustotal results 47.46%Heodo
2020-08-19list-DCQ405.docdoc a0096856f8887d5cdf7d5f2e6805694ac96da153aaaa326ef25ee058e6c6a683Virustotal results 46.67%Heodo
2020-08-19arc 20200819 RMX04421.docdoc f6feee3a8137cb0cab6667842f06e07f96e54fc2f15ebe079dc30b4060d52452Virustotal results 46.67%Heodo
2020-08-19list 20200819 461.docdoc e951848d42ae155a4f81c8c0ecd4f3164426f99a023d9c9bf841f130998a4668Virustotal results 46.67%Heodo
2020-08-19File_20200819_932682.docdoc 948a3065cb08ddc97ef33cce132fadb8de68441de9d0fb9cc30fad5fd39be2ccVirustotal results 45.76%Heodo
2020-08-19inf_NB329960.docdoc 60529051426888b950c39051f1ae3ffd04df199460f8f08ad2fb4ae0d65837f6Virustotal results 46.67%Heodo
2020-08-19Dat_2020_08_19.docdoc 5194005835c1f487f14f03ea67a9300ad9821c5d0922e5549321d2629448f630Virustotal results 46.67%Heodo
2020-08-19LIST 20200819 GQ61923.docdoc 5a63ce9de6a721eaabedc5a95a579a3eee404a94034db171f646e24517fed367Virustotal results 47.54%Heodo
2020-08-19Arc-2020_08_19.docdoc 682cb4ff880f1a6a000f5a227f8dba42abd73d836308162dc519644d9dae94efVirustotal results 45.76%Heodo
2020-08-19LIST 2020_08_19 66427.docdoc 40ba73d22e9dab3b78ab066b7fce42d3bc541832c4d6a8ce3c564f2290c0b308Virustotal results 45.00%Heodo
2020-08-19INF_20200819_534450.docdoc 859010e3760b56ccc5e32be50378cd07f2f34509d92b112b4ec0e6e5802fda42Virustotal results 46.67%Heodo
2020-08-19inf-UOT280293.docdoc 63c85fe46afbae39a953f205b3b3d63109f1f4e6aabe61d3d1b9deb3ac66d335Virustotal results 46.67%Heodo
2020-08-19Dat-20200819-285.docdoc b4109096624dd29f07d9e5c328637c66396a4c0ba53760b48905a4d81e829027n/aHeodo
2020-08-18list LT8536.docdoc eba02aeb5ab35694f34f8048ad03accea87abc6915db54d0905d905a155901ffVirustotal results 45.76%Heodo
2020-08-18LIST 140084.docdoc 85d051184c78737bf858c74a6fe5cbf9d30ed82b3ace8cad4b7555c5132cb11eVirustotal results 44.07%Heodo
2020-08-18list 2020_08_19 2897631.docdoc f7f2b55cdbf9f24f6e1850b32aa87b859717f840d46caff776674a973d28d51cVirustotal results 43.33%Heodo
2020-08-18File_864577.docdoc 91abaab1b3daa4a4dfe3d6c8adf5c5c8f0ec0551c271417fffd61444cbf47346Virustotal results 44.26%Heodo
2020-08-18Rep_Z8588.docdoc 68184e955d9a5e852a40b7c215d5654f9172d35c4e7a50e24b0080bb14c6ce0aVirustotal results 43.33%Heodo
2020-08-18Arc 13944.docdoc 55183240d4344ec16d2bf19836addfaafebea308d9349ef0df5d92aa7840a916Virustotal results 42.00%Heodo