URLhaus Database

You are currently viewing the URLhaus database entry for http://uss.ac.th/cgi-bin/wxwe88224015468f95gfy3z66gajm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:598787
URL: http://uss.ac.th/cgi-bin/wxwe88224015468f95gfy3z66gajm/
URL Status:Offline
Host: uss.ac.th
Date added:2020-09-22 17:13:15 UTC
Last online:2021-07-20 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-22 17:14:05 UTC to noc{at}cat[dot]net[dot]th)
Takedown time:10 months, 0 days, 21 hours, 15 minutes Bad (down since 2021-07-20 14:29:14 UTC)
Tags:doc emotet link epoch2 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-06BAL_09266086.docdoc 2ee32296f32b1507f3a355a99656fd69b0b9607ce87e66b08891fce2aaff4e2dn/a Heodo
2020-11-14BAL_09266086.docdoc 506a3e793a4560d04ed8f60ef81eac180ff05c02d976dc46c633229cee760660n/a Heodo
2020-10-30BAL_09266086.docdoc c30d0b92c6bcf0b9e11a8ad6629249fd20bc69a1a431249f887a491281cb4d22n/a Heodo
2020-10-17BAL_09266086.docdoc a5e0de9653d988a6bf2880366bfa59ade14f0e6d086963124742a93258d5798fn/a Heodo
2020-10-14BAL_09266086.docdoc a4a1ee4733ee13036dd3e03a08ca2a85c3eddf3f3de37441be3b71a7e27e2f0fn/a Heodo
2020-09-24Z_OO0937600143QP.docdoc 460d4f1fa3c90d50ae0a56c6c4c26bfcd3d3d22829baef98b7ea3e9b451974feVirustotal results 33.87%Heodo
2020-09-24S7OU12GED3HW2C1.docdoc 3321abc9c460868cfafe80f968ccea4254b02ede808bcabe4dd58055ffddb358Virustotal results 30.00%Heodo
2020-09-24DOC_VU2850245486DU.docdoc d038ad9d31d6764ec9e5ad2246c2f2a99e0c06ca8798bd54e73deecb05dab14dVirustotal results 30.65%Heodo
2020-09-24C_3TBU33YN.docdoc 896f6e1b9eb9656cfc68db252241fc7087192661175a0604505742223f0ef016Virustotal results 29.03%Heodo
2020-09-24DOC_41440560.docdoc f97b2fe462e15ffbe47937e6d6ad815595fdb180d137a7ddd92f9f41e5a6b5eaVirustotal results 27.42%Heodo
2020-09-24AF7713532863GX.docdoc fc98a386a0e52834ae5dcb93beb5aa33305f3e71cd4183a2e47c7c38d9cfeb1cVirustotal results 22.95%Heodo
2020-09-24PO_09242020EX.docdoc 3094430b3d76d53847a19a95eb5729490be7efc8f68feb4b57aeb8fd72c94ee9Virustotal results 21.15%Heodo
2020-09-24F_XT9771949553KT.docdoc c53bc4b67b9b49868bbb7d3a8323cbd2b411a41077e2b691eb9e66516dde0e4cVirustotal results 29.03%Heodo
2020-09-24PND_862822629333965547668528.docdoc 94b624741c1f94566cdff34893b864991875391da2ac00168f15691c48043367Virustotal results 25.00%Heodo
2020-09-24REP_A813XES36F2S0MM.docdoc d6f4d312b2434777abc97c10e41bb86186836a8a9a2e08b5365e301afae8d0b3Virustotal results 23.81%Heodo
2020-09-24BAL_B86B8YDNC77IL.docdoc 47c8e3e92b05f289d4c090f3405365aa37f8e0d0bfce6535dc59d999117a2fdaVirustotal results 20.97%Heodo
2020-09-24DJ1665257727WG.docdoc 969fa2b3b1738ba0cfebb842c241a5ac4558eda516437f5237a3257cc0140091n/aHeodo
2020-09-24PO_09242020EX.docdoc b0c9e63cd039da312aea84e7c632e4faab8fa1bf3b6d8382f6fd898635c39941Virustotal results 22.58%Heodo
2020-09-24L_WG1324743308OK.docdoc 69ff6eb0a71090b17e21b2829b6108b2eebf8bd12b92fe587ce103a4c5cc0f3dVirustotal results 21.31%Heodo
2020-09-24XACMYXGCR5O.docdoc fe0a0b77df06046dffc8059552a1484dfa263360d127d452805142945aa4e5a8Virustotal results 20.97%Heodo
2020-09-24D0NW2Z8.docdoc 7439811010be6eb023390a28eff9b2acf598883daf1cb66bf4c6e78bb8f13998Virustotal results 44.26%Heodo
2020-09-24FILE_1RWVQ5ZSLMY.docdoc 60443647991cdcd0fb310b965e853672e8c5c83a64629a83d7ee568b23e44296Virustotal results 45.16%Heodo
2020-09-24UP4726240149LA.docdoc 581091d124784af196ac242540f360f1ef2ab6e5e346ec9125a467b47e5e1f4fVirustotal results 37.10%Heodo
2020-09-2487129649.docdoc 4e227495a216d86b2e51164a32e9ec057c53cc5e829107af1aeb4ee9764bbdccVirustotal results 36.07%Heodo
2020-09-24PO_09242020EX.docdoc 6a85b35a3efb06108074ff5c1c41b6673f1888f5f4766aad5214383d324fd416Virustotal results 34.43%Heodo
2020-09-24INV_46004098.docdoc 109faa9ffefc2e21ff1a72efcf3e665b4be5820282f07f8fa54c14bc9f243803Virustotal results 34.43%Heodo
2020-09-24INV_50832476.docdoc 7aed739ebb48064d94fa17f51816a7d3f4414ec8d578a6bde0830e844055e971n/aHeodo
2020-09-24H_A9Z0A2CDWL9E1N7A.docdoc 3b95077a69ba1ee1226face3a5f83a78950357b93815180ebb6b6772cf8212e8Virustotal results 37.70%Heodo
2020-09-24QVG_090120_XEW_092420.docdoc b427adb1ae5fd4b290ab65b93ea392c40c42f186b732f90768099681494d10caVirustotal results 35.48%Heodo
2020-09-24INV_LYF_090120_ZNQ_092420.docdoc fba080b64f42891f1ddec30a5a83c9881e8b8dc2e577226eb1575654caddc56fVirustotal results 35.48%Heodo
2020-09-24INV_YDA_090120_PQU_092420.docdoc a5be49695d9d336e787b37a7a4955307a263c426f7cae3cecdd69d2bfe026585Virustotal results 32.26%Heodo
2020-09-24DOC_PO_09242020EX.docdoc a71d3dae8594c0336d66e366a3911fe4f349966e73fcb6c5fc9ed3077c8fcb6cVirustotal results 34.43%Heodo
2020-09-24PO_09242020EX.docdoc a26964e2d826f555642d9dac0e19c5bf685767b5a0cb12d9a83e6d332251b17dn/aHeodo
2020-09-24BAL_CBH_090120_MHQ_092420.docdoc 6e7ae3df631cfa3174a4e9e061f71a3453806fe930adca05896343d9e6f07ea4Virustotal results 29.03%Heodo
2020-09-24BAL_82904871727.docdoc a6bdea3758ccb519e3736628a467290a74b47562f8a489e89346642276c9f177n/aHeodo
2020-09-24PO_09242020EX.docdoc a279b3d82c086e59725b814eb8f6ddde5387efb28b19f197dcb6a82e239f9906Virustotal results 30.65%Heodo
2020-09-24KW8495542792VJ.docdoc a9654b509a80552021269008e33074d85ee269b8a579a23ef93bcc5aba20227cVirustotal results 29.03%Heodo
2020-09-23DOC_NSOWSK0KTOR.docdoc a5cefc7eb57545e36ce9f959ac252dd0901cbac2b6d83bae4a92daaef93f383an/aHeodo
2020-09-23PO_09242020EX.docdoc 8c5a7c3909eb8fa754ea6c689f2063f553e1400cc12b30266c8f59479453ef0eVirustotal results 29.03%Heodo
2020-09-23ZDFDXG135.docdoc 76435bca763f869f80daabd795435e20bd52e2cff25a5594ccc20c8be946a2e8Virustotal results 37.10%Heodo
2020-09-23PJD_090120_LBP_092420.docdoc 15d9c4a8449193c0406c1005887328daa93d847ea063f9097f0eee39bc404df0Virustotal results 37.10%Heodo
2020-09-23PO_09242020EX.docdoc c9de56d138a927505138fdf267dafe6d598cdd4338db121b7d7b5f9a982a3a49Virustotal results 41.94%Heodo
2020-09-23EK8643354653AH.docdoc 0bab9cd9401d43739be303f2f040aa4559bdcfce229754a8c6f2758d3046b54cVirustotal results 35.48%Heodo
2020-09-23V_PO_09232020EX.docdoc 17f28ba9ec3406178924435252e81db9e219bc21ccc0520d3c699ce0878dd738Virustotal results 33.87%Heodo
2020-09-23D_7QTNOCMD.docdoc 5d5e964840d2d7f401bae3568724b259b02c4485c211ccc7ec23c0273d11edd1Virustotal results 35.48% Heodo
2020-09-23REP_8652182924966225.docdoc 5b534bf80108820c4b2ce654b225ca8cf8fc10176fb2d3b51b3fcdb0fc5c6200n/aHeodo
2020-09-23INV_SOR_090120_CWF_092320.docdoc 3d0062b20db4e52a4f9612964699a06f8920aa931e2126424d8190273b7eb948Virustotal results 35.48%Heodo
2020-09-23DOC_PO_09232020EX.docdoc 84d892d9a7fb0b13d3688390c0e4c1eda7945a7531348d664924f48b38e67cdfVirustotal results 33.87%Heodo
2020-09-23BAL_76133164505969.docdoc 275e74c921d4676893e049215cd0a40ade4ca28564af84272af361f86f62283aVirustotal results 33.87%Heodo
2020-09-23REP_PO_09232020EX.docdoc dc22889242c4ec3f0a5cbe5050df8ee1ccc8231c28a144700b02bbaea1e2a1d2Virustotal results 38.71%Heodo
2020-09-23XE_31343713.docdoc b09074b0d262c73c66430e4e968ebee0cb946881c69d7b7fd8bc9130a1731482Virustotal results 35.48%Heodo
2020-09-23INV_5984838740.docdoc 87147834cbde11b3f37c516844cf8d9ba78e603010280ee9eef5e29c92b10425Virustotal results 37.10%Heodo
2020-09-23I_713671636024467049855758.docdoc 189c119c3845bfa395e55f7693e1e1690fd7eeb31e427128db7cba27719cac66n/aHeodo
2020-09-23BAL_PQ1629168436MM.docdoc feb0d1ca74f0ed4ae64f6c17873194dd6429d16f0b925b8354051f7d7bb04b45n/aHeodo
2020-09-23BAL_AAHDJURM1.docdoc bb8142568de9017ef615f6eb92b63a11795c3d48f30b36957efb191f225ee49bVirustotal results 36.07%Heodo
2020-09-23U_4DW3346MTVP3W5P.docdoc 952b656649c633a039c06ac4138ac005b789c82749170299de7fbb2a45f22a10Virustotal results 37.10%Heodo
2020-09-23PO_09232020EX.docdoc 4b3610dcd68cafba15d271e09c1199364c572ed710c35e9593da52cfef460b51Virustotal results 22.03%Heodo
2020-09-23BAL_U72L5Z0Z4BAZNL06.docdoc 50eb03b40f1b8d5d8289dd43d19ea6c8a45814a6ac1448b21ae3e1660b1c3c67Virustotal results 34.43%Heodo
2020-09-23PDU_090120_NSY_092320.docdoc 8e12da0d14bfcd77133c21065f6b32fd171fdf8ca5f94b6c2aa11d1c0d3f30dfVirustotal results 22.03%Heodo
2020-09-23W_5383925962.docdoc 27913bedf548875b064d7c6316b3afad4aaaaa8998e4d9640f179a7a11da73c5Virustotal results 33.87%Heodo
2020-09-23YETO_PO_09232020EX.docdoc a367f82673d105dca478418602c9f38633a5347fc2b0f565e828cb4b52e89424Virustotal results 22.58%Heodo
2020-09-23REP_IM7280072442AC.docdoc d83b4457e963cb82b3322d4ac94c492e4ee3c024573964d25ded75239d9623ebVirustotal results 22.95%Heodo
2020-09-23DOC_48835108.docdoc 20ef957f84144a3fad2d3e3b68b6159c70b7fc25c13fc2185d1686235fe49676n/aHeodo
2020-09-23SXYEGRN1K42LYN.docdoc 7928a27bbbae2f5305d56e27ed5ffc6858558e3829273fdc33307cf76f55eb93n/aHeodo
2020-09-23GN7429703733HQ.docdoc a877dd61b25805e938555868388a8543768fb01e9c45ae6072c261f61264d466Virustotal results 34.43%Heodo
2020-09-23REP_87558517.docdoc 21c40bfbb721e32e33612b797ea16cf7927dd9df4d355a8ad1509ef924b30428Virustotal results 35.48%Heodo
2020-09-23FILE_75621000459427.docdoc 50c9d530111fe31904255db5abdbabd939542a19af71c656dcdfd44c9fe2b4b0Virustotal results 36.07%Heodo
2020-09-23BAL_PO_09232020EX.docdoc 15b6e8645e321e35774c5f7b9e295ba0e3d31d3f116e7a67724e6e0e5f8f3ed8Virustotal results 36.07%Heodo
2020-09-23E_75204355.docdoc 4e02784f17b866165db458c9ae3f13edf8dae02967921cfec16074018e8cd2e7Virustotal results 35.00%Heodo
2020-09-23REP_PO_09232020EX.docdoc 90bb75f0c88bcf2a5196f73f5bfa35fe230b05ebd75d6b6f61a1440c763aebb7Virustotal results 36.07%Heodo
2020-09-23BQYFFS3.docdoc 5f0d373b1aefd0bf4a4b8942b87a71025cb90011a5633caf9258d975e90edfc3Virustotal results 34.48%Heodo
2020-09-2356573314.docdoc 23228721f30ca78a87d92bafd441f784d43b35778a46e3fb21fcca990fdc778dVirustotal results 35.48%Heodo
2020-09-2362968581700.docdoc e701a67030bc767a30c999f4bc07249218be0f846de4294b4ca96b3a64ea169dn/aHeodo
2020-09-23LRX_090120_NVZ_092320.docdoc 3ccb6e15d1d669f80a3b40e294920eda308017848943e5539c5493a5e39cad03n/aZLoader
2020-09-23HJRV_TO5645711987UL.docdoc 2f949a337c2746a62b0f22fdbd222a7783251f0b81a7332e4724a59da312369bn/aHeodo
2020-09-23PO_09232020EX.docdoc 5cb9f67f8d803e2b5cbdfa3f2be7bb32a7cde2670256be9d0c998626a49ce7f2n/aHeodo
2020-09-23REP_EM1664275138TS.docdoc 93fb00cace65d90b02ab79f949887b3eaa5b0a0bca1e4a9d7c20576f8ad18deeVirustotal results 33.87%Heodo
2020-09-23INV_MEP4J2Q2.docdoc 29b732cb0e36fa5a789f66f7d4cb5ff8905ce6ac1b8e18e29d056b439e177cc3Virustotal results 30.65%Heodo
2020-09-23V_95720902.docdoc e757a53e573f1584dd56ed851acc303473be8922e8f879bd1dd8f9b8dbec4eadVirustotal results 31.15%Heodo
2020-09-23BAL_PO_09232020EX.docdoc 23bc63af094f80c54cfecb85f86f0b2f1975ae55f29d9d66ea61d6612c36a567Virustotal results 37.10%Heodo
2020-09-23BAL_ISF_090120_ZHG_092320.docdoc 53dde3ba3a9c47b693f01a8904d5d1c223cb25c08f0488ff97b08e05dbbc7be6Virustotal results 30.65%Heodo
2020-09-23BAL_FTR_090120_UPI_092320.docdoc 10fe3df8f6540696c8eaf649bc752e30d5533b0203869ec0839cf045227620baVirustotal results 32.79%Heodo
2020-09-23M_759802481136634608312.docdoc b9230204a6b5bb648c78437d34a9350a40aa179243813ecef19402cd1f319b96Virustotal results 27.42%Heodo
2020-09-23A_948219705178271363212101.docdoc a306f78cac809e60ccf84e607470e4c43f0de4efe4dcd2f0e470786a5f672a35Virustotal results 29.03%Heodo
2020-09-23E0EV7DCJ.docdoc 1c64de03ffee1b612358e9f45424fa90efb35ee3f384839c5d48f8932bdb23a9Virustotal results 31.15%Heodo
2020-09-23ZR7937778248VT.docdoc fa7f4b3fa89ce1e3cf1f45674f36346e729aced2de513c5a058f935c65b3cffcVirustotal results 27.87%Heodo
2020-09-22MPV_52035291535615.docdoc af31068680a432b4d1d2164488f6353795fbb745479373bbafc6a60e9cf25169Virustotal results 30.65%Heodo
2020-09-22P_AR8617687876XW.docdoc 158dba6d537edd9c1fb56cc2c1307f00634cf5188667321946c2247e02eb6c40Virustotal results 29.03%Heodo
2020-09-22PO_09232020EX.docdoc 66aa75aca1e5a0fae3797f424ff58868d5a813eeef2d2c287a893e91b60769f8n/aHeodo
2020-09-224463738526.docdoc 7fc71d784c714360d684b4c25382fe807f04a3cbd861352f3c19fa0fd789e59dVirustotal results 27.42%Heodo
2020-09-22REP_PO_09232020EX.docdoc 096e7d0d8016a7efe13a6bcfe45e2b78d115eb681a6f855b639a9ca3c8db22c4Virustotal results 30.65%Heodo
2020-09-22U_KSX_090120_QFJ_092320.docdoc f81dc1dd571c29424756de4b14efa593fdea619f32694846535c4820c9acf375n/aHeodo
2020-09-2213000867.docdoc 07e10c57641a11b12fa27dd4b62a01b1f1db583eb0f33e25154c1e495d45066en/aHeodo
2020-09-22DOC_60267110.docdoc 8f8f1029e9909427e27aa6d225db5eb6d8767560af23836c44a0abff203eae4bVirustotal results 27.87%Heodo
2020-09-2256816906.docdoc 052552b8940e682ef01c6161f4b074cbcb5dcf412f62b64eafda4e3b304368ccVirustotal results 27.87%Heodo
2020-09-22DOC_63438470.docdoc dab27520c5577f059d11bd78d22f8d5cf492cdc0150781ba9b28b5fbacc5c185Virustotal results 27.42%Heodo
2020-09-22OQLJWR07HP8B.docdoc 04648ce7223361494ad5620c674be88a869710007f672d05721b77af59be70fdVirustotal results 27.87% Heodo
2020-09-22BAL_86277690.docdoc 820f15f2465a43b8c59cb29bb3d528d3312a6ffef820420bb9c3730d2bd98fb6n/aHeodo
2020-09-22YT_TF2219600467KR.docdoc c288a47cc4303a39755120a6450d469a858b7bb662f27fddf022bb2fad4553efVirustotal results 27.42%Heodo
2020-09-22PO_09222020EX.docdoc 02503f6546f32015f98eb839efb8b3d86d56b8ab5de5a30b5d6e99b4bd41802dVirustotal results 32.26%Heodo
2020-09-22REP_307051941923222645.docdoc 87f58543c86151e96b31f59d447ae70c1bc19c0eaec22d93d1291679cae0ea67Virustotal results 32.20%Heodo
2020-09-22REP_VPJ_090120_RGC_092220.docdoc 98ed7b170bb0ed8347e7011169d58c72eb48bb85e312974151833265446a9acdn/aHeodo
2020-09-22V_QY8KF3M4C.docdoc 6c12352efd4f3c01d75a62ff92dc923f367b1a81dcb6b7ccb436c8a27f1f3be2n/aHeodo
2020-09-22BAL_49906019358183798582473.docdoc 280a1aaaebe209d8b8f7a652fd2f9f9efbbb3a6731328ee3d5da4caff1bfb02aVirustotal results 23.33%Heodo