URLhaus Database

You are currently viewing the URLhaus database entry for http://pogltd.com/_vti_bin/Documentation/io11n0d2p/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:441993
URL: http://pogltd.com/_vti_bin/Documentation/io11n0d2p/
URL Status:Offline
Host: pogltd.com
Date added:2020-08-25 19:25:06 UTC
Last online:2020-08-27 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-25 19:26:02 UTC to abuse{at}sgc[dot]hk)
Takedown time:1 day, 10 hours, 57 minutes Poor (down since 2020-08-27 06:23:39 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-27INV_KHH_080120_MCC_082720.docdoc 4cb865b49222804a73c256ba51fca7e68ab66d4936ecb514b108827fe2fa9a01Virustotal results 30.51%Heodo
2020-08-26FILE_PO_08262020EX.docdoc 7a082d2d846a53d95bf86c4806bc6ace013ac04f1fa8750c17728f64726e47dfVirustotal results 31.58%Heodo
2020-08-26PO_08262020EX.docdoc 1c50d88604610dc28e6769e8c4d2526a24ba934e3b01108514edc13f68892451Virustotal results 27.59%Heodo
2020-08-26INV_MIPXU1LOT6L1437.docdoc 676c878bed2e541c7e1adcbb0f141462e8f98125e82ff705dcda881165585452n/aHeodo
2020-08-26BAL_OFY_080120_CJI_082620.docdoc 16ba108b19b54a215fdffb4ada0bf198814e65190ae73a686c300bdfb5eb2ab6n/aHeodo
2020-08-26FILE_91858926025176123749.docdoc 300cf0fd3de72ba9c28fc5428b8fac05aa455c7d7ffffbf3ae72db863f7fec1eVirustotal results 43.10%Heodo
2020-08-25REP_PO_08252020EX.docdoc c83c6353d36706d9ede8b73d387db5ea74ea2977900f849d802d7cf17669c266n/aHeodo
2020-08-25PJ2623429648HQ.docdoc ebf572465108b8645ca9637d9c17b4fe717d4d99f3d4dd29046a22a8f608bcebn/a Heodo
2020-08-25BAL_BCG_080120_RRN_082520.docdoc 5419b1d842aa8d13493c5ac67bfd2839472947b3345c2f6552dc69521575959fVirustotal results 41.38%Heodo