URLhaus Database

You are currently viewing the URLhaus database entry for http://dental.xiaoxiao.media/css/https:/1BVGtiTWDy6Wj6SD7lA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:517363
URL: http://dental.xiaoxiao.media/css/https:/1BVGtiTWDy6Wj6SD7lA/
URL Status:Offline
Host: dental.xiaoxiao.media
Date added:2020-09-15 16:50:09 UTC
Last online:2020-09-16 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-15 16:52:25 UTC to abuse{at}asmallorange[dot]com,eig-abuse{at}endurance[dot]com)
Takedown time:21 hours, 14 minutes Good (down since 2020-09-16 14:06:39 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16UNTITLED_20200916_DWA303.docdoc 6588df39b1cfd797af1644aedff24c2f62e80a5c800b8e8187becb4d8881c73dVirustotal results 25.00%Heodo
2020-09-16YNT11943 H25767.docdoc d55706b5d7fe77da18e3169b8a910ff0baf6a3143fa8761d5b00053e42d5c9f4Virustotal results 23.73%Heodo
2020-09-16inf_3661152.docdoc c4d44340a8baa31b2d02c6c9b4596ce0500bc64e34c61a4b1e87aa2a0cfcd174Virustotal results 20.34%Heodo
2020-09-16Dat_2020_09_16_PG6358.docdoc 15c2f883f0cd59d6bce32fd36dc5edf23ce78b273a79fe3021f7beecb3ae3ae9Virustotal results 19.30%Heodo
2020-09-16REP.docdoc fb8ad7a942d6259844caaefcc87f660c6116f86fef0e477fd4047d3eb797c8f7Virustotal results 20.34%Heodo
2020-09-16rep.docdoc e97caedcbf6d27a37ca4d06b4d5e232715567364c3192a782c4cd46f7df3e222Virustotal results 25.86%Heodo
2020-09-16Arc-7448.docdoc 4142cb49199a7efe52b944caff9ab5b07d61438a9fc89a413199b2f801aec9d8Virustotal results 26.32%Heodo
2020-09-16REP 2020_09_16 RJ717.docdoc 0bf1382d9493a03c8b56f2befa1ada29ce2ac87dbde3a1c02a0742a95e630a5cVirustotal results 26.32%Heodo
2020-09-16doc 20200916 PH555.docdoc 219b5d039e4a109011e021799762a7dddecbc2c5e6f75294daac8bb6454790a5n/aHeodo
2020-09-16Rep_2020_09_16_JIM45808.docdoc fab310e91d04203eb4a5911d81b2d387893e1913d380f5bd01a0d7d28bfbecbfVirustotal results 25.00%Heodo
2020-09-16arc_20200916_AS5071.docdoc 082b657e6fc18dd578b33ff31b260c6951ccebcb4cd71e19852a609ca723a27bVirustotal results 22.03%Heodo
2020-09-16Inf JZ894701.docdoc 1ac42c93a5c7ed2032a573c91d229836148d58174b546d68fad1283466142b01Virustotal results 20.00%Heodo
2020-09-16file-M7915.docdoc ab14206412f23c7ab737cd9e0f579bd80da5ddadc677b096af8d66409df579c5Virustotal results 20.34%Heodo
2020-09-16Untitled F013684.docdoc 12c96f80fe4fb65075234dbad10058e7efbe9f07774d8ca20219f5b5fd0b7c00n/aHeodo
2020-09-16List 2020_09_16 4906.docdoc 41a035835264e22d0533d34539e7ae0db8573b8b7bb013a5ad3fddfc6965884cVirustotal results 20.00%Heodo
2020-09-16LIST_CJD1834.docdoc d64753842bf0d8413fab16e2b4f48fa311d7eb3f1ce485fd003052016e3c6b8fVirustotal results 20.00%Heodo
2020-09-16Mes 2020_09_16 KI72931.docdoc 986bd93ac718512981dfa5118d7f043ae53e5a98960036804641a1c4b72610f9Virustotal results 20.69%Heodo
2020-09-16REP-20200916-GJ10557.docdoc 14b8acf04483277af0342148ad78291ceb2393d22002c123a588e6b76c9c9d3dVirustotal results 20.34%Heodo
2020-09-16mes 20200916.docdoc 4bf59afb77b6c07c47039cb97d4498853fcb96aee97d91ea04e96ad6df7d5420Virustotal results 20.34%Heodo
2020-09-16LIST-20200916-SH292.docdoc c18d26648d361c7c52164f6987ea197d93a43d055247acad10999b8d896ff8e1Virustotal results 20.34%Heodo
2020-09-16DAT 2020_09_16 288173.docdoc 0bb2936e529012cf02cb1f7609fa7287b49bd3a5130689aa0fbea224394e208bVirustotal results 20.34%Heodo
2020-09-16MES 2020_09_16 39903.docdoc 16f861770a0fce369ed5f6a5082844ecf21c3acd315452f28a8d75bda5aef6d0n/aHeodo
2020-09-16arc_20200916_3726.docdoc a19fa376f35c2f22c67112d0a5049196c92d820b41c96354ea3fa52453d71d82n/aHeodo
2020-09-16list.docdoc f9c13b57f880b152c53ed1c339858cf915b1347c194df39962fe2e0052e69576Virustotal results 33.90%Heodo
2020-09-16WW497 20200916 26987.docdoc ef071674b1f2a1834422f4985e7adc827df001a12baf597c43e4214ca4690951n/aHeodo
2020-09-16list_2020_09_16_JG457496.docdoc 55a20277ae9c195942274d3621049acafaff844bff9155821b6e8e55b5b288dcVirustotal results 33.33%Heodo
2020-09-16KCR876_20200916_HI305322.docdoc 793c4468a9e884d73484aa56d9bdde013d34801ae1e8120652713811130e560fVirustotal results 32.20%Heodo
2020-09-16Dat_20200916_105.docdoc c6bfcee4b167f9ecbe3abe5a37819ca6c055d9fcce418496da67ef7114fd2223Virustotal results 33.33%Heodo
2020-09-16inf 2020_09_16.docdoc 12b8124161c9ce3fd1f5501e19baadb499863b1c6411d7ea64204be683f7706fVirustotal results 33.90%Heodo
2020-09-16REP-U4324.docdoc 6ce61eccd50917328baca8baa337e8be84724ca3af434db260146552b5b901b7Virustotal results 33.90%Heodo
2020-09-16DAT GYN3242.docdoc aa4293594894b71bc6802e0f48b7de166601c9fcc291b5cac35f9c817183880cVirustotal results 33.90%Heodo
2020-09-16REP-2020_09_16-787.docdoc bcdd7a0529aeb14830e86ce4a8c9fae27fe86f5d23026e4533b53a90469164ebn/aHeodo
2020-09-16REP 919.docdoc 95719928e4208c74d4319fe5c08f000b129494d294a3f58308b2f7ac74127df6Virustotal results 33.90%Heodo
2020-09-16REP-2020_09_16-26850.docdoc 8a3279538720914f40bcbb0e8350344e0cc20ae2189a177335c7e210034ff97bVirustotal results 33.90%Heodo
2020-09-16file 20200916 J439.docdoc bdf8c73501dcf03a946c8ed4e2e6510cc815f6b36f1a9d91639cfad9dd5102b0n/aHeodo
2020-09-16rep-20200916-U416462.docdoc 1292dd86f8e8fe11fcbf78ef24f8e0001be9a651a0704a2d31fa4fdcbe6dfed2Virustotal results 33.90%Heodo
2020-09-16dat_011.docdoc 3efbf2f756756ebf7bd7511292448954e6d7cdda20849048e5a6ffd67ea27874Virustotal results 34.48%Heodo
2020-09-16Arc 247.docdoc 3e9f742cbd4f500a90f5307eac39dbaa71ac16f3991a12c4c0dee78bb777b09bVirustotal results 33.90%Heodo
2020-09-16INF-TU5955.docdoc 30aa71563af259beb93121c8f1def42d2729a460e68e250f102f01ce5b712f3cVirustotal results 33.33%Heodo
2020-09-16doc_20200916.docdoc 9d5aaf57f58d435632b896bf1d4b37a2c63288b939d15d5ad25ab532e22149a8Virustotal results 33.90%Heodo
2020-09-16ARC-20200916-LI448275.docdoc c7de97826d8a63a4bde0edf98a5e1049c3a8cceeb1bd0b848f89ba95584f7f18Virustotal results 32.20%Heodo
2020-09-16Arc-20200916-H709.docdoc 82ac6817a3e36a939990363702ea2f1314bd610d6374575a5b7afefde85c7065Virustotal results 32.76%Heodo
2020-09-16rep 20200916 KIL83063.docdoc 3e88858278038bca70d809d2baa4ea4072da2a976880d113c8edfdc49fda4590Virustotal results 32.20%Heodo
2020-09-16mes_2020_09_16_6683.docdoc 19373a5983bf61ef115b229e00b461a097c97187dbbbb075ac90f4240cad9224n/aHeodo
2020-09-16doc_2020_09_16_O087609.docdoc 5106eec527c2c3f1926725309fde44601cac2f45e601129ee392e6023e415d34Virustotal results 32.76%Heodo
2020-09-16Dat-9501824.docdoc dcb0d0b6eb04aeeb4ed91ac7100ad41a9014285cc6be83351f9af84207386d7cn/aHeodo
2020-09-1601130_2020_09_16.docdoc 9e421a68ace7a8e2fd8e963f6b58f1bbbeeaaa5ceff8b01390316312e6f52cffn/aHeodo
2020-09-15REP_20200916_EHI8940.docdoc 801147f2dc7b49cbc2907525e54d3bcd41a7ba4be9d648de5e2222d068e63d9fVirustotal results 32.20%Heodo
2020-09-15File 2020_09_16.docdoc bb6d6a8ee182afb71df2f0e50dbe64c6f2bcb636231b693f8d34aad389480be8Virustotal results 32.20%Heodo
2020-09-15doc_6718.docdoc 36cc514722804312a8769b90cd872196aca9060ba19f2122af1ef9230e9e7850Virustotal results 32.20%Heodo
2020-09-1592302YW 20200916 LN7140.docdoc d0fba2b098ff90a78440a38e84734c679208cd2f44396b653f818b1e6618c829Virustotal results 31.03%Heodo
2020-09-15Rep-20200916-G928482.docdoc 998617f6b6d8cb3b0f374f55aa9543cf8a3aa3f07239977fa532f9b0b2b04f5bVirustotal results 30.51%Heodo
2020-09-157260N-20200916-AKX7134.docdoc 79072ee92448d21af7333e10da35c4ad37c862ddadd4d11e9744f5ac2f41fa2eVirustotal results 27.12%Heodo
2020-09-15File_20200916_17877.docdoc 3a7d290d64c985186f4275fe8db0b5808e8d3dfcaa556a98851d23680f56089fVirustotal results 27.12%Heodo
2020-09-15LIST 321.docdoc 59de1190716bb70c977e59d24c6527fd5a765e7abded702239495d195191eae3Virustotal results 25.42%Heodo
2020-09-15dat-20200916-HP41116.docdoc 65bd9b7635da8ba95af31b116f327fd8c45d9a9866e83c5522bc56e2f0b4ae1an/a Heodo
2020-09-15Rep_20200916.docdoc 513e73f25aa660194472fea171d305803b69736650adbf18d2d8da89d40c0503n/aHeodo
2020-09-15Doc PH955.docdoc af24b69fe5f997b8c930405122e5bf3f0290858619776823bcf2efde68a3076eVirustotal results 26.67%Heodo
2020-09-15Doc-2020_09_15-072.docdoc 8a4d95a53d4c08749787abffaeed2faf9012068b6177db2f70f862b12e4d4c1fn/aHeodo
2020-09-15doc.docdoc f68943cea5e50cdea78b4055ca022d66f86dbcedc97596d19e0b8343386a3b53Virustotal results 27.12%Heodo
2020-09-15inf 20200915 D719.docdoc 6fc8aff5fa51bde4628bb595cf592e2cc9a1af94a665d035342688615ebabf4dVirustotal results 33.93%Heodo
2020-09-15Arc-EIM896.docdoc b3c577af2ab4bf3c53845c69c9b8d9c1497e28f89374e420387c757120c26a58n/aHeodo
2020-09-15UNTITLED-2020_09_15-S628199.docdoc 66487f2d9afca77b164715bc94a2ae81a36270cf6e9d74f5a262ed0e58a08c54Virustotal results 32.20%Heodo
2020-09-15List_KQC02502.docdoc dbab1d04f6be43ab157f7d77850e5ce737f83222c7e3c2fe5f468c27abc8e67bVirustotal results 33.33%Heodo
2020-09-15Inf 20200915 4421.docdoc 5c8b1254a5bd8b057c07b44b9235e0d3ace748a6164e164221a31eef0e15d90fVirustotal results 31.03%Heodo
2020-09-154166CAM.docdoc 320663f88f174291aee31b679bae3c878ca4911c5611d5ad68d578dd63c2b29bVirustotal results 31.58%Heodo
2020-09-15Q35564-2020_09_15-FXT448.docdoc 8ac9de1e93432f153993e54bb2fe7d0589f6cf783584ab41af2a72e00bc3699cVirustotal results 32.20%Heodo
2020-09-15ARC-RRS0765.docdoc e189cd464de4d23476b0bfd39712751116326cffc78e154130fb3ffee9f3b4f9Virustotal results 32.20%Heodo
2020-09-15Rep 2020_09_15.docdoc e43e937fa678205bbdf1e998fd637dbd7bfe7517cb70647c60a17e82a53ba832n/aHeodo
2020-09-15Attachments-PQ15030.docdoc 0d4873d7e0566fc69a357547e627d1955f6ed3c90d7b3f1aa7b417c9320dbdd1Virustotal results 30.00%Heodo
2020-09-15Doc_FU4114.docdoc a82abec78a99db12bd1ea98379dc884b80ac3dfb33c11aebc76e1336a8540f0an/aHeodo
2020-09-15Untitled_456.docdoc 25022fdedad55927f5a438cc3e58e0442c0343393954f18dcf8b8b35cc062aa3Virustotal results 31.03%Heodo
2020-09-15INF_20200915.docdoc 8f938913a1061dab6a00062bcb70b49c35e323f5a6cf836d1ca77c8d1eb2dab7Virustotal results 30.00%Heodo