URLhaus Database

You are currently viewing the URLhaus database entry for http://astigmati.uz/wp-content/https://docs/7qs6sWOF9rvDvEYRM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:504735
URL: http://astigmati.uz/wp-content/https://docs/7qs6sWOF9rvDvEYRM/
URL Status:Offline
Host: astigmati.uz
Date added:2020-09-14 23:36:06 UTC
Last online:2020-09-15 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-14 23:38:51 UTC to greg{at}uzsci[dot]net)
Takedown time:10 hours, 35 minutes Good (down since 2020-09-15 10:14:10 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-15Inf 774748.docdoc ca8d28ed383c1c8fd9ec5f80a3b8554ece5bc52ffad7b7fc3b29d8e1ba5b2188Virustotal results 23.73%Heodo
2020-09-15LIST-20200915.docdoc 445a016e7a9eddbc4e0ae84d64a5ed7c7785b21bdd3503c19cf4d67d75662157Virustotal results 23.73%Heodo
2020-09-15rep 20200915 580764.docdoc f1889cf61020e82a3a09189d111623e320c0de288cf6358a8b78faf84c221f6cVirustotal results 24.56%Heodo
2020-09-15rep_2020_09_15_T994.docdoc 807391e7d966a61e58ac7b3362dc046433dea4bf6ce1b4be4f6e401816cb4d30n/aHeodo
2020-09-15AH7453_20200915.docdoc b4cc02dfcf8d78c1ae755a87957b62e9bf8caaac7d5b7f9c821243c16156b1a1n/aHeodo
2020-09-15Attachment-66302.docdoc c20847352ed2103a0c6667c5e686307b2e4cedc91f9b4dbd9d7a1839056a7de7Virustotal results 24.56%Heodo
2020-09-15Attachment_0324.docdoc f97694da71b6d09abe7dce7e990340e1328b1e9647d6052cc2154065460f9d39Virustotal results 24.14%Heodo
2020-09-15UNTITLED.docdoc b81cfd4a25215c8ea1fce928fe34abac6aec507996d06e94517a407c2f830573Virustotal results 23.73%Heodo
2020-09-15LS134-20200915-2781.docdoc efb761d064a0532695fb1e9591211f23a27e1e4058c510d6330f2ef5ad26bce2Virustotal results 22.41%Heodo
2020-09-15Arc E5609.docdoc 7463b8f26d81d26802635deb9e38b2d1f5edbdc4788affcd52d757a740b19b07Virustotal results 23.73%Heodo
2020-09-15ARC-2020_09_15-JVT141448.docdoc e93305d9e0353b2bee392690b34ff857e6888e3e7fba9e45955620ed30de57adVirustotal results 23.73%Heodo
2020-09-15REP 2020_09_15 LKF1281.docdoc 3efa7fdc4ca6834bb9660796ff8e44d4920b31e3cba358915cfc879f08cadbecn/aHeodo
2020-09-15FILE_20200915_MD08710.docdoc ba9d077883e665aec704bcfe5aa0e2dad671f16f6e5c1b4b87c20682530e1a0fVirustotal results 47.46%Heodo
2020-09-15Doc-2020_09_15.docdoc 52a16eb4d0a5916ce64afde8ebd6f617d816671ca29c92b3076ccb8199e01f0fVirustotal results 48.28%Heodo
2020-09-15J286_2020_09_15_118.docdoc e0aad52f9de4512023a6d55564583a80a0c187c213055d7ae3f5c47da8d5d7ddVirustotal results 50.00%Heodo
2020-09-15dat-2020_09_15.docdoc 70fd42a9c8f4e756e7045642e89490e8917b44e18a081e82a9a6be42a1cd29a2Virustotal results 49.15%Heodo
2020-09-15File-951.docdoc 31eed9ea0b73f0824c7e449cf3246f8e914614057c5619e5c4efbdfb1e99b40dVirustotal results 44.83%Heodo
2020-09-15LIST_20200915_4492.docdoc bab404a66237f3796ffc9047bdac95d69e90bc166e8c2838affdd13e0efae9e7n/aHeodo
2020-09-15Attachment_2020_09_15_716696.docdoc e203577dadb325bd364b0a6609b5aa2b4df457ba261810b3e5416950dff54c8fVirustotal results 45.76%Heodo
2020-09-15Arc_2020_09_15_355890.docdoc d4c9555b63b03bb49ef48c18edd3d1e1dc33617c56a00505f470823f6de5c394n/aHeodo
2020-09-15file YN99497.docdoc eccb065e1c60436dabac0b306c646b72a2fea2f01323b85d717724c08feaada3n/aHeodo
2020-09-15DAT_20200915_41436.docdoc 0de486e758ab3a42b8cf8fac0544cd138cac337db3c2688bf2e714089db683adn/aHeodo
2020-09-15File_T202410.docdoc f17e30fcbb606a053ce0672cdff6f8b3402fb01346e7753abfd3add6f6fdfca4Virustotal results 42.37%Heodo
2020-09-15Attachment-5909160.docdoc 1edb5c54fee229f7a710437d7356d55d4343437e46e849802c75ae6101162c47Virustotal results 42.37%Heodo
2020-09-15037_2020_09_15_55644.docdoc 5fae5bb30e9800ec137ead15679e59e39b70069c5a495f35874953f74cbd4c6cVirustotal results 42.37%Heodo
2020-09-15Mes-2020_09_15-6720.docdoc 3d3ce21eb20a5c3ea022e9f6e9fd3a339ed2c4cb22c26bbc83e88d0cf7ab6ceeVirustotal results 40.68%Heodo
2020-09-15395LZE_20200915_N90736.docdoc af77b6d2c8b4ac5dd458b68e927c7ff84ed97c517498254d74eec800e9699b1aVirustotal results 40.35%Heodo
2020-09-15INF-480033.docdoc 9ce006bb0e752354b2374803060115dedb3f8239567d4bfa6a2a027a74bd9b9bn/aHeodo
2020-09-1500511-20200915-788.docdoc cf8d757135f246e73646a6a72adfde896d3ed51271e7056596076d834e960968n/aHeodo
2020-09-15Doc-20200915.docdoc 7f270bf002e459e860698dbefae6fed9ece80b03830e5fc6bb156d2c5cd8f65fVirustotal results 39.66%Heodo
2020-09-15Attachment-20200915-5364.docdoc 0fd1ea9df6c248cc1ef6ac65fc534db5ffb946cd912f8199503dd93fecbda5c0Virustotal results 39.66%Heodo
2020-09-15Doc_20200915.docdoc c247ddf966fd2c2df2ffec2956e4798990741e8b0f7d121639bdd06fa98053deVirustotal results 38.98%Heodo
2020-09-14rep 8989881.docdoc 3797086d291ee004f0fca9dab3efca616b89626f0f0f01ea2db082c63d67d68dVirustotal results 40.35%Heodo
2020-09-14list_2020_09_15_PN9311.docdoc a37f74acd4e0dae148467f7004339fc3ddd54e34eb6bb7c3dca20a13edd09b41Virustotal results 38.60%Heodo