URLhaus Database

You are currently viewing the URLhaus database entry for https://nyeinchansu.net/wp-content/OCT/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:493111
URL: https://nyeinchansu.net/wp-content/OCT/
URL Status:Offline
Host: nyeinchansu.net
Date added:2020-09-14 09:18:04 UTC
Last online:2020-09-22 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 09:20:13 UTC to abuse{at}amazonaws[dot]com)
Takedown time:7 days, 19 hours, 45 minutes Bad (down since 2020-09-22 05:06:05 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-185XDPGJX5IA.docdoc 92851cb764419d8ba397bd68f8a097ac8cd0faeeac231c1348fc7ab7172aee64Virustotal results 68.33%Heodo
2020-09-14DOC_746853818601096363729041.docdoc 33fdd2105c6792ea0096f87c5be02c0a4077e059d550eae962c72be773a41bacVirustotal results 26.67%Heodo
2020-09-14INV_2IZDGG23.docdoc b1a7d9e8d86b77651baaee9636836bd1c11bbd2566d0b8fab5de85c7c56e8083n/aHeodo
2020-09-14INV_PO_09142020EX.docdoc 80d8e37e856ada6bc31bdd15d3ef46e47cf2163c6394c78aba7ee026b55a6b2bVirustotal results 22.95%Heodo
2020-09-14REP_KQJ_090120_LQW_091420.docdoc 2e215528092b344b0a24685e8a198c966686cc291bb40928657a8418d60e6dc2Virustotal results 22.41%Heodo
2020-09-14BAL_AMZ_090120_TNQ_091420.docdoc 4828ea08e57d65a9b30f86f4064c885c040ea13314bbcd0c5275ef0dd7e9a46fVirustotal results 20.34%Heodo
2020-09-1492338442.docdoc 2fac310b78d265e0776b6f981fc06a11ed3921b74c16fa8d0209ac712636eafdVirustotal results 24.14%Heodo
2020-09-14REP_374640253672798433332266.docdoc b2da3622cd82e573c60eb2623e5d96e08956c72cb2fd0c53a126e732b376a0efVirustotal results 20.00%Heodo