URLhaus Database

You are currently viewing the URLhaus database entry for https://ictsmkn2cibar.org/cgi-bin/http://Reporting/68WJYVAyzjfP0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453356
URL: https://ictsmkn2cibar.org/cgi-bin/http://Reporting/68WJYVAyzjfP0/
URL Status:Offline
Host: ictsmkn2cibar.org
Date added:2020-09-04 14:49:35 UTC
Last online:2020-09-24 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 14:50:04 UTC to abuse{at}hspnet[dot]net)
Takedown time:19 days, 22 hours, 54 minutes Bad (down since 2020-09-24 13:44:06 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-05MES FI708.docdoc 4c3f9a91ab8bd67a7de8b61f6d5e49c34a0c3ded123f63205f02d17ff570c204Virustotal results 30.00%Heodo
2020-09-05dat-651334.docdoc 8abd1fd956a522b05535b6b9ddb53a6c4353e20235979a9ed05679ac4f2a95can/aHeodo
2020-09-05file 2020_09_05 318.docdoc 13e33248efb3839e1e0e830942f519158cbd7090dd25afa842b4228cb5ada615Virustotal results 30.00%Heodo
2020-09-05UNTITLED-YSS4418.docdoc ddd8c361d3ca02b5ca803895bb6f365200b244f91cbde23f27b6af134ebedf5aVirustotal results 30.00%Heodo
2020-09-05arc_20200905_JU368.docdoc 36db57afc7d4faa57d7bbd559db7ca4ae2bd483caacaa9fba1a3cc6839b240a3n/aHeodo
2020-09-05doc_8287344.docdoc e89ae83996380754135f2a758f5a9506a7a44eb610c70b28f909b2f0b73ce548Virustotal results 30.51%Heodo
2020-09-05359O 20200905 363.docdoc 4160aae4b7d4ee73a7137bbd2d8c5cad6f215282af86bec49526c1b15db1c50eVirustotal results 31.03%Heodo
2020-09-05mes_2020_09_05_NKS30574.docdoc 54fac54bf401937afa1a48e9545b32e46ac8be7c543918e4a841177baf879ea3Virustotal results 30.51%Heodo
2020-09-05Rep_2020_09_05_5494.docdoc c1658fd6974ace7a621b0e46c9d3f1bbb8ad7d3ddeb3032082937f3133c1c063Virustotal results 30.00%Heodo
2020-09-05LIST-20200905.docdoc ca1ecf3a84713ebe3b95b15bb7e7d4fe779daa81b1a2879feb79423222472ec8Virustotal results 29.51%Heodo
2020-09-05Inf 2020_09_05 73252.docdoc f71c39920ac9463b4be57b2c9ef5a795184d8adab4c0a8761d0d491ae6b5a140Virustotal results 30.00%Heodo
2020-09-05arc 20200905 EK934.docdoc 51da971ad054a7cc8d3a929c87eba819eed539387ca660dad760e7bcf2477562Virustotal results 28.33%Heodo
2020-09-05LIST 443.docdoc a6861aa553541ef958ad8dbfff87e748c920813dd0b745d69787b2818357158aVirustotal results 30.00%Heodo
2020-09-05DAT_2020_09_05.docdoc 5b82741c8587a1a90e3ce044387a541c69a916330391030a4daa50aa1db6a445Virustotal results 28.81%Heodo
2020-09-05DAT_2020_09_05_1634.docdoc b647104789174776abced7dc5a7abaa47fa349c4b21749ca3b6634e4f039da4dVirustotal results 28.33%Heodo
2020-09-05Arc_81844.docdoc b1d37441a65187f53492dcd30fe0d3fafb9de343694c7ac79d3ce5434cec9350Virustotal results 28.33%Heodo
2020-09-056066_2020_09_05_S7405.docdoc 173c9cfe44cb721e3d1edede6afda3a107dd78b74c1adb41c19fae5ae6a382d7Virustotal results 28.33%Heodo
2020-09-05REP-20200905-20638.docdoc 7b33fe4f09c06251aba09bbc5407ae8fd899bae0a40d3e7d55f3806a8b6a74a6Virustotal results 29.31%Heodo
2020-09-05DAT QBH260.docdoc ee2869e612b62baacd8f12266c98e851549e6789343a4020cc424755ae55326aVirustotal results 28.81%Heodo
2020-09-058273W_JEF42215.docdoc dcb081f33d098bd8befd0776a185a13823b7a4f29087f39cfb3b1cc9693722f9Virustotal results 26.67%Heodo
2020-09-05UNTITLED_T0050.docdoc 2ddd8ba7251afbeee6c41576c377265c1a2a9f5370cd66683c24db0c89a0062dVirustotal results 26.67%Heodo
2020-09-05Attachments 2020_09_05 5462.docdoc c66ac5fc632592fd547d29b2ea0d58d6fd421effca802489611fb9a43a656a45Virustotal results 24.59%Heodo
2020-09-05Rep_7513.docdoc 0917f0cbca78c19301ba65aa799b29dcf90ee3666fc9f8b83f00c5ea34a0eba6Virustotal results 26.67%Heodo
2020-09-05list-20200905-725449.docdoc 6914af81ae643d0106a7cb16454991e2b4d29053551e92e659456ad592120f57Virustotal results 26.23%Heodo
2020-09-05list_4060.docdoc f3c01505f223d53a856b4cbb5201b5cbad5706145be5e214e266f4570491a8ccVirustotal results 26.67%Heodo
2020-09-05Arc C88508.docdoc 2572ca226200ecc1019e9813f939d7484962a7f90ecc62921f7efb01e5bdefeaVirustotal results 25.42%Heodo
2020-09-0536420195-SA5969.docdoc d933cd9a8fdaa58bf021074d4dcbca7f3fed26971db346a66f8b2435afb70b50Virustotal results 21.67%Heodo
2020-09-05XPT790_2020_09_05_0886.docdoc f0e8099995f3ce14cd75fb397efda8a5ef10d2360783b3321d55be49eb5a7888Virustotal results 22.03%Heodo
2020-09-05File-20200905-RAW7323.docdoc de7201ce2995436691a764734f9d6dc4395dba5066dc1c6c469fb2684daa58cbn/aHeodo
2020-09-05DAT 2020_09_05 5756308.docdoc 2d5d1fe8c77135420414a5cef6384683cfbf59f04e7e9b03c909c2f4c3ec54e9Virustotal results 21.67%Heodo
2020-09-05doc-20200905-374026.docdoc 3c51d26e98137dad5c907c872c1af3b0faea7094df4acb08d71d8873e8800a9dVirustotal results 21.31%Heodo
2020-09-05ARC 20200905 JAH791.docdoc a0c340e5b8f401a13ec7ea03f405623ed8532d1bdfc9f708d34ad94a2c14ac47Virustotal results 22.03%Heodo
2020-09-05MES 2020_09_05 EEE449.docdoc e5b5640cb999ccd3a5fa07ef28ecdb37ea16dbe142bd3cec619837a9c0c3baddn/aHeodo
2020-09-05MES-099.docdoc 4c30d9c7120c06908f0bfdea08c45fbef17a72793a4688a2aa236899c0aa8d2bVirustotal results 22.03%Heodo
2020-09-05DAT_1472738.docdoc ac03cec1ea7e2d4ba254b3225a617ff11bb93247cfd84340907d0533522327e4Virustotal results 21.67%Heodo
2020-09-04mes-20200905-3103.docdoc 4501204cd406a353ac88516bb9f133148c882ea030d84403dc54bd0297f68b6fVirustotal results 22.03%Heodo
2020-09-04INF.docdoc be5a076cc07b81d54fda54ef3c56f2d60ee214c3d1fe46de3dc59a1df619dc29Virustotal results 21.67%Heodo
2020-09-04DAT 20200905.docdoc a68967c55063a216717a336462d01e74b4dbf73c0e3ad3b56bfe2c4ab10f3b38Virustotal results 23.73%Heodo
2020-09-04Arc_20200905_60666.docdoc 137b5a0cda220100df4caefac31efe6cc85c4bd72580fe2ce1987887901d3ed7Virustotal results 22.03%Heodo
2020-09-04E638 20200905.docdoc 0f264ea12ac1b1f96e80c683d7aabce629b15ded57f43e29a4faa7cbf057d673Virustotal results 22.03%Heodo
2020-09-04File_2020_09_05_184.docdoc 5c812ff66278cf61e89871fd5d02ba1e06092920cbface28f9710fd77ca413b2Virustotal results 20.69%Heodo
2020-09-04Arc_2020_09_05_DT808.docdoc 44f213e9ff99dece96ea33d94a4e46bb3e508480002c5e255d46ca711b44a9e3Virustotal results 20.00%Heodo
2020-09-04doc-2020_09_05-818449.docdoc e3986d10ba408aefe9c0f44c298dafcd5501ea916fc093cbff42c479194a9309Virustotal results 20.00%Heodo
2020-09-04List_2020_09_05_277.docdoc 17387deff7e3725fb0ae1aacebcb5e9be101e9ad64a337ce858202ef07458f1cVirustotal results 20.00%Heodo
2020-09-04Inf-20200905-674.docdoc 4833c57c4ff48c2720247aa3bc9c8d62222f9fe3d095924030c344bfa8673847Virustotal results 20.69%Heodo
2020-09-04list_2020_09_05_6170.docdoc b177d6304e1239837128c14fc3423ded464e3877b918bdf27db3d2f40375c398Virustotal results 20.00%Heodo
2020-09-04Dat P16781.docdoc 9f003b20287110dbbea8826454c0666aee189fbf57cb907e8cf072dfe3829b18Virustotal results 20.69%Heodo
2020-09-04Attachment_2020_09_04_5632.docdoc 924f9439383931103e48f1a8618e3b5b0dc6e56ba52261116659d5dd2bbc3050n/aHeodo
2020-09-04ARC-2020_09_04-X898.docdoc 9c0798c3e8889889ef70b039545920afb91f1508144606704a1889286192bbf9Virustotal results 20.34%Heodo
2020-09-04Dat 2020_09_04 573.docdoc 623ee20c1b2e5a53a0bbf6eb21f4b87cb0e6392e023f1e08267abc08c26e5bbfVirustotal results 20.34%Heodo
2020-09-04doc 2020_09_04 59319.docdoc 44d3865f9ac7efa31a3e9882aa38bad74bdd7e66627f48cf5f915a664ad329cfn/aHeodo
2020-09-04Inf-QKA85296.docdoc 627615216c18d1e8f7e1fd2774e09f54950e8068ccf5712cf072d21fc266763fn/aHeodo
2020-09-04File_2020_09_04.docdoc 50b2236aa5eb66410121fae6fbee2696da6878e6e22da851a522caa037b65c25n/aHeodo
2020-09-04Dat_20200904.docdoc 112b31f94d0408209223b109553273ff732fcd2f05b532c53d7ef7e4658bec80Virustotal results 35.59%Heodo
2020-09-04REP_2020_09_04_428.docdoc c567ea1fcaf384bfd2ad39165ea9b07fc04bfcbd325f7b3ecbe8c7329e65611cVirustotal results 35.59%Heodo
2020-09-04Rep-M275.docdoc 6811ea887aa1fb0b0947ae4c101b1bccd01e6be62529652d9a9c70a8879485feVirustotal results 34.43%Heodo
2020-09-04dat_2020_09_04_FOZ0297.docdoc 8460a5fa5f04096785b86ecb12c7eb2118f8d5032be10ecd0bd9b49e728afaccVirustotal results 35.00%Heodo
2020-09-04ARC 2020_09_04.docdoc 6d0e0c6c270e763b2d4e0f6e14fd373b7ca0688c6b0d27a4589f39d40c756d3fVirustotal results 35.00%Heodo
2020-09-04LIST 2020_09_04 C6879.docdoc 113c8c78cdad0ed438501117f87ca9b0d52b672ddd8b015284541ded516827e6Virustotal results 35.00%Heodo
2020-09-04Attachments-421281.docdoc cc4f7c86201d0618e4cc76f2030913800e738cb4a46496daa65e8f3507b3e12dn/aHeodo
2020-09-04FILE-20200904-OQ34998.docdoc 5da16c9f1af8807ac20e6adce0424c7e8fb78d5a4187584a3587876c2affb1e7n/aHeodo
2020-09-04Rep 2020_09_04 67252.docdoc 530c8a300c489e40c554fb9c0be1d28633675699b2a84b520ff020fcebcf964dVirustotal results 35.59%Heodo
2020-09-04ARC 2020_09_04 385.docdoc 10fa2f7a4aa981b8f214a0875399cbb3052961541bc988e45faa9ffa346689c3Virustotal results 35.00%Heodo
2020-09-04Rep_2020_09_04_080.docdoc fbaa65a02cf8c771c0cf3656084a8b4168750f336ef53130fc96a219ce9dc121Virustotal results 35.00%Heodo
2020-09-04717EC_2020_09_04_H03578.docdoc 9fcaf4513c97d7fc9141d719481fcd7479ef7213701221d18a3755a7035e4d3bn/aHeodo
2020-09-04mes_20200904_007.docdoc 00a7e0634054721fe9f4467f8843d3558c3694215da05f6027c8444786c55d21Virustotal results 35.00%Heodo
2020-09-04UNTITLED JI377451.docdoc 60417a3fac59e91bb0031c7e6fc97a808021296c159f11631bc3ac3e34ec5603n/aHeodo
2020-09-04FILE.docdoc 20f0a0ba4cd0dac615e918dd489d36a9dbe9da8eccd28074379ccb9297f44202Virustotal results 30.00%Heodo
2020-09-0400962O 2020_09_04.docdoc 9c82f57cbccf6ba04020fd7828aff371796a2f69e908f5ecf8c25d921a13abf6n/aHeodo
2020-09-04Attachment_20200904_35817.docdoc edbc22e742e12b2af45a775673812f2c751b4f9071a83b9565d3d547fa380655Virustotal results 30.00%Heodo
2020-09-04048LJL-20200904-3938017.docdoc be6a2393d8d58557a21737649e0977851d793862f1b80f1d27a1ee2ee70b3154n/aHeodo