URLhaus Database

You are currently viewing the URLhaus database entry for https://kotova.fi/cgi-bin/https:/FILE/hS1Gt8udKeRV5wF6np3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452485
URL: https://kotova.fi/cgi-bin/https:/FILE/hS1Gt8udKeRV5wF6np3/
URL Status:Offline
Host: kotova.fi
Date added:2020-09-03 14:24:03 UTC
Last online:2020-09-03 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 14:26:07 UTC to info{at}hostingpalvelu[dot]fi)
Takedown time:5 hours, 12 minutes Good (down since 2020-09-03 19:39:03 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03doc 20200903 774299.docdoc 87c33ae0a712785fde7c483d86dbb964ab1db6cb7a0050ea07e5da240dba44b7n/aHeodo
2020-09-03Attachment_SL5039.docdoc af81984de14d081c2a5d015a4266dd625fd7eb4153810cb71c2ba3e9dbf382ddVirustotal results 23.73%Heodo
2020-09-03LIST 95190.docdoc 87dc054eccdd1cd6182d372f5fad56aae34971c4a0ab10e92fd242ee82e9c785n/aHeodo
2020-09-03list_2020_09_03_7949200.docdoc 75e21b06b155b76eeb61cf02a1e3d2ed091b180853d2c6dba9aa7f4afa014aa8n/aHeodo
2020-09-03UNTITLED-27123.docdoc 1e8ea370168c58d9ea8d88b67552e2397a879ea142fbb091ab2e258d51db9f69Virustotal results 21.67%Heodo
2020-09-03Inf_YL3230.docdoc 86bcb8fe918dc1b3fdc5a6ff0902527872723b002108c86f14be504b2a9c295eVirustotal results 25.00%Heodo
2020-09-03MES 2020_09_03 Q67691.docdoc 039593442d9e6207131ebcf1a580c3e5bec865876db4457c1f8caa6947159cbdVirustotal results 25.00%Heodo
2020-09-03mes-CC773.docdoc 4af88a43df9708bbfe4b6e374b0a1d494ebe3e3e148bc26031e2274b74d33bd5Virustotal results 25.00%Heodo
2020-09-03rep-2684828.docdoc 95a7e791afc63ee2afec1fb8ed9283881d2afc17110419804e6dad34cf0914ddVirustotal results 25.42%Heodo
2020-09-03rep_ONY342790.docdoc b507bcea8c1df6e8829b92fe0a23e5dca964764b5f973292f03c120d676c8ed3Virustotal results 25.00%Heodo
2020-09-03Arc-2020_09_03-38300.docdoc 4a2ee0cb09dab923da14ab985f65d156e600b82e42b0bb53bf982243bed9400eVirustotal results 23.73%Heodo
2020-09-03mes-PX818.docdoc f7344f9193316539b2e534058faa5c6aeabe035179fec5b8d7fabc8884612087Virustotal results 23.33%Heodo
2020-09-03dat YR4164.docdoc a3cb0dab145b2e5b5000b6b134acdb73594fb0bec769212dc3b848b5eb16d284n/aHeodo
2020-09-03Rep_20200903_121.docdoc 8da638f633a35eb320331bc3842f55e54256cd7f625997eff55eb120af446fc1Virustotal results 21.67%Heodo
2020-09-035413YEB-20200903-NE443049.docdoc c3361afb20133f50828375dc15cdef13a90d58b0e1eb86bbc091449394d67ff7Virustotal results 22.03%Heodo
2020-09-03inf 3937529.docdoc 8f3005dd01b057a916e725d8df5f16214633ecc82993787765bec64e206ccd97Virustotal results 20.00%Heodo
2020-09-03Untitled-20200903-711765.docdoc b004c93450c25e5f003507331416340551486461fbc571bd854f62dfb21e1a46n/aHeodo