URLhaus Database

You are currently viewing the URLhaus database entry for http://ktpdx.net/buddybackups/Overview/1vsvfjd2dta1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:446126
URL: http://ktpdx.net/buddybackups/Overview/1vsvfjd2dta1/
URL Status:Offline
Host: ktpdx.net
Date added:2020-08-28 16:39:34 UTC
Last online:2020-08-28 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-28 16:40:02 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:2 hours, 44 minutes Good (down since 2020-08-28 19:24:20 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-28A_PO_08282020EX.docdoc 45c6cbf3a848206d33f3a4d92ca9ac6f3511b39227d46e433887c00384ed6f56Virustotal results 28.07%Heodo
2020-08-28H22WTJ0L8TASNI.docdoc f5b03a311135b32ed372590430479a35b0e7c1538ffe7e95f60baf40732f350dn/aHeodo
2020-08-28OLE_124178741.docdoc 6fb504f2fd1966b7eb00f0a9cdcbd5fc4cedbc4bc50d5d77702e61460e5230d4n/aHeodo
2020-08-28XAR_080120_YIF_082820.docdoc 425659a7db67434fb846e86eb949e0ae4af1288284cfe1633ebd1229f20a9c55n/aHeodo
2020-08-2808401378423758020861983.docdoc 894b67e8fdc469d458ec7f0970172a3671d53635c004c3ba4c3f85a650c55ea1Virustotal results 27.59%Heodo