URLhaus Database

You are currently viewing the URLhaus database entry for http://alliedhealthmoh.gov.my/AHPiS/balance/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:437882
URL: http://alliedhealthmoh.gov.my/AHPiS/balance/
URL Status:Offline
Host: alliedhealthmoh.gov.my
Date added:2020-08-21 04:08:10 UTC
Last online:2020-08-21 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-21 04:10:03 UTC to noc-abuse{at}mschosting[dot]com)
Takedown time:18 hours, 32 minutes Good (down since 2020-08-21 22:42:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21INV_TZY_080120_LMW_082220.docdoc 200499c68dcc60878ae71de919f5c504609c692cabee5d1c61193cff8ae83cbeVirustotal results 32.76%Heodo
2020-08-21FILE_H0M47P5I27EDE1NB.docdoc f916381df1861ea591a02695d5c3c47c0f322c985d141897e6b8da198a94c718Virustotal results 32.76%Heodo
2020-08-21DOC_MNEHREQRQR.docdoc 8907a6bfe58eb538c48ed691e79d7df49c9371412cb30a157f323e7bae524b19Virustotal results 25.86%Heodo
2020-08-21FLAR_6ZOPWVIH7CTVN.docdoc a8d9be27c76a90124652ea8d92479f9651ed136612532d9f34b4c0b8bb78fc25Virustotal results 20.34%Heodo
2020-08-21FILE_088298192952117296.docdoc 28f2d62905428be69bb94405cef4459871fb4d34be7d8e1cd99be4088802ce60n/aHeodo
2020-08-21FILE_NZ6810208728LF.docdoc dc32f2320e3eea2867f2d17d7b197d17d280e5c08d14b6d978c34c1c2338e4fdVirustotal results 30.91%Heodo
2020-08-21Y_6818064894510396143460533.docdoc 7112a5a9264a099d9056f3d980c95fead062c56ea04362528c505bcc6ddd2b1dn/aHeodo