URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ksgresearch.org/6313647008267795/rbb1egnfcqq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453698
URL: http://www.ksgresearch.org/6313647008267795/rbb1egnfcqq/
URL Status:Offline
Host: www.ksgresearch.org
Date added:2020-09-05 02:17:35 UTC
Last online:2020-10-27 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-05 02:18:03 UTC to abuse{at}dimenoc[dot]com)
Takedown time:1 month, 22 days, 4 hours, 16 minutes Bad (down since 2020-10-27 06:34:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-15FILE_286335810890410373733.docdoc 1246f0fdcd238c8024b389e1f28783276528b12af413ffee21fe0aecbe18b55cn/a Heodo
2020-09-05696398412725138411689451.docdoc 8b23e164f16ba0caed21611db9782895ac3a6a1f5b30a16e7cff6a2f8e3c3008Virustotal results 44.07%Heodo
2020-09-05INV_50472729.docdoc 3c64a79cdd49b1710bd9042cb9988c215e0050e9ef57e604f4679c45abcafd73n/aHeodo
2020-09-05PO_09052020EX.docdoc 7888c29713425a14d1a374dfad7e3ba568408a4c756f476461f1357fe69699e6n/aHeodo
2020-09-05FILE_45061496.docdoc 52646e971288c190bffe00616c46fdb3741f1be6a5f0fe2235ca71c24435bf65n/aHeodo
2020-09-05RWY_090120_NRP_090520.docdoc 7c88f52c679aeb917f52a42b5424f5aeb90901cd44d00fe9aa0608e4f2940cb4n/aHeodo
2020-09-05INV_54802338951905740.docdoc b47773387ceae19a77df17722ac76711cd26f753da32fb7f1a43302d5523bf59n/aHeodo
2020-09-05DOC_PO_09052020EX.docdoc 9dec32ba9b743147a0bb4ae8041825a74aed44d6dba4f1ace85a6a008227cb0cVirustotal results 41.67%Heodo
2020-09-05OVL_61183590761165417514021.docdoc f2c72c50487b631344d96edddf586d9e99c4685edb37450bade175f676504f32n/aHeodo
2020-09-05FILE_AT7YLBSJ6UFX.docdoc e58920e12dd5ce571200cf0e7449728756bbb8a0b43d301ea7a625b5d7755c1eVirustotal results 35.00%Heodo
2020-09-05BAL_93982586.docdoc 7a30501200d16da77107068379331700e901268be067ce701617b4df11238b75Virustotal results 21.67%Heodo
2020-09-05DOC_JHD_090120_TVW_090520.docdoc 039c1a80de238f23e0baa36bef68172211789c397e294663fd1117bae972bc79Virustotal results 31.67%Heodo
2020-09-05DOC_1RN4QOYIMT.docdoc ebc24ae3a35b97e088396a839e1b94a2a71fc528915607e809c1d56780cdf030Virustotal results 31.67%Heodo
2020-09-05SY9232226670UZ.docdoc 8c2da9079e400f97c3679a4f138c565c32493719b8c611f772f31c9781cc90a9Virustotal results 31.67%Heodo
2020-09-05XA_OJ2100446394OC.docdoc d687cfe8a3bb92d088de0d9d1a6a61c4254635189e0a677975a5fb453724576bn/aHeodo
2020-09-05REP_PDE_090120_CCC_090520.docdoc 916a9fdb4940cd7596a9604a95e7af177de4c28e90bfa8c2c98d836e82aab78cVirustotal results 31.15%Heodo
2020-09-0542098136.docdoc 53ce3cc79fda9e0a7f82873c3b94b8dfc7d31d3eab577ee54707cb8c1ad10585Virustotal results 32.20%Heodo
2020-09-05I_Q18E2F03F1KXGY7J.docdoc 7332b5582ed72e5d0f8ddd61b24b1329f4a0e3b5083cbe586c00e49f88e04b46Virustotal results 22.03%Heodo
2020-09-05DOC_2889424911518943028545.docdoc e09612bc00202606cdfdfd5140ede548aa4d9224c339eb3e4ed0ad24dbad4f0eVirustotal results 31.67%Heodo
2020-09-05BAL_UCT_090120_HLZ_090520.docdoc 3c0391237b2adda4499615dc19541883ee3a71e7c2db9eb3b3eb02f1b15d8578n/aHeodo
2020-09-05BAL_0828712411257690445.docdoc 6289f2e9039d8290e8166b5e1251bcd8d8317a3c458b4d21b7e210f113245c7fVirustotal results 31.67%Heodo
2020-09-0591V7AZFAOXOW.docdoc d64c1bb1fbb978e265b3ee51e8e289cb4df8fe6727077731485022eb968ff3ffVirustotal results 30.51%Heodo
2020-09-05Z_GI0967360909WI.docdoc 8a1b69d8887c60c1170f376610877703b08db59b89d9f5992c95b7dd3a332a21n/aHeodo
2020-09-05J_2CCGQQYQ8HQ2K.docdoc 4c903b5a31a9f3c899eef444b340a7b8ef976419af252bec53202c9f06614150Virustotal results 25.42%Heodo
2020-09-05WJLA_PO_09052020EX.docdoc f9ef3bfe7d720474ddaeb7e816e38478952790b9b70acac27a93a3ff3603ff24n/aHeodo