URLhaus Database

You are currently viewing the URLhaus database entry for https://an9news.com/aokhf/public/91992BOcd3w/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:548068
URL: https://an9news.com/aokhf/public/91992BOcd3w/
URL Status:Offline
Host: an9news.com
Date added:2020-09-17 20:03:08 UTC
Last online:2020-09-17 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002942437 created on 2020-09-17 20:04:06 UTC)
Takedown time:2 hours, 9 minutes Good (down since 2020-09-17 22:13:58 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-17504_4738792.docdoc 5cf1c435df44614218257702eaf9e9efd98f63cba2d6306e704ea49a0799fc39n/aHeodo
2020-09-17Arc-20200918-T73793.docdoc e36c64b96d2cd2ac0e73dfbb55750f10b5afbaa1c2ed9a7129a19faae285fcc6n/aHeodo
2020-09-17file_20200918.docdoc 00d004d041cd6d18ac2b3b26f53b642816578698bb96055a921f74a0e16aca23Virustotal results 32.76%Heodo
2020-09-17mes_20200918_302602.docdoc 1bc4a47d0fe2369993ff6f11e93075f7e441de5d443e88719a9787c43f6a277aVirustotal results 31.67%Heodo
2020-09-17Dat 20200917.docdoc 69b92a13de9bc9189abf0d3e05336bc19c4d2aed4299571a7bd3537567279461Virustotal results 32.20%Heodo
2020-09-17Dat_20200917_U509.docdoc 0df824f36e56dbf8febc5fcb22a4017bd18feb908d157a5761754b81776f74abn/aHeodo
2020-09-17UNTITLED-4906.docdoc 314fd7232ed22434e4c12d009ccb2b7649683c85a6d4fc1d3b7e556a7c94054dVirustotal results 32.20%Heodo