URLhaus Database

You are currently viewing the URLhaus database entry for https://vastraindia.com/dry/attachments/98WIyjmwdrTHJ1Ax/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:608550
URL: https://vastraindia.com/dry/attachments/98WIyjmwdrTHJ1Ax/
URL Status:Offline
Host: vastraindia.com
Date added:2020-09-24 03:08:34 UTC
Last online:2020-09-26 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 03:10:15 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:2 days, 7 hours, 21 minutes Poor (down since 2020-09-26 10:32:00 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-25Inf-2020_09_25-D874.docdoc d3e012af393d0c3110d710e9e5847ea22d96f727c9ac4f6aae00aca450a6a555n/aHeodo
2020-09-25mes-70139.docdoc e55b497502188dc8b8da281b3a2e03550c1ff2299b5d45e61f51502706652bcbn/aHeodo
2020-09-25Doc_2020_09_25_802741.docdoc 018067bf198382877c4b21006840178202d28ca1cef4c8faae500a82dc6672f8Virustotal results 38.33%Heodo
2020-09-25rep_2020_09_25.docdoc fe890849b50a3266c007ef8b917afc54bed8de8c8630f33cea2fb0d9d6bbccaen/aHeodo
2020-09-24FILE_20200924_8783218.docdoc be612472636783a90675b4f5675d0acc07782b484cac36e5fb8e19ce861b8c38Virustotal results 29.03%Heodo
2020-09-24MES.docdoc ce6c5b403794988f1f8b87e204c73e7de295624d14d9b2e7b2115ece7aae362cVirustotal results 27.87%Heodo
2020-09-24Mes_2020_09_24_AEQ7595.docdoc ef16ca7f98838032f77c4ce37274671438e7f500526a91c22a2ca6c1e2bcff62Virustotal results 27.42%Heodo
2020-09-24Mes-20200924-I72480.docdoc 1fba84d3bf95f4bcd6dea7cb0e278712f39c4adae6b83a63f00252c1e7e82c34Virustotal results 24.19%Heodo
2020-09-24List 1152.docdoc 57c819aa8037219a797527d244de0184e442b0f39eb6dd73b17661ab7f97969cVirustotal results 24.19%Heodo
2020-09-2439698_20200924_B140.docdoc a7119297d5e0a5d3b6ab6bfdecc15029d2243b433db330c981e01246f23d5556Virustotal results 24.19%Heodo
2020-09-24DAT 20200924 575883.docdoc ee8bbbd66f875dadd1be1e600b7ea785439dfae118c9ae269a9beb0bc11c1b8fn/aHeodo
2020-09-24REP 20200924 4749.docdoc d5496150a225e2950b4d68c44020e8bf9b30d640ffbf2d72046c3adbd2584818n/aHeodo
2020-09-24Doc_ZJW122546.docdoc d45880473c5098805fac94221c1a8d160d65028a7ec34bd85ec8e56782c57fffVirustotal results 24.19%Heodo
2020-09-2430292057 20200924 202.docdoc a183faf9989affc0f28663b6ae74e921382cf5c04ccee9f318ce777048caa813Virustotal results 22.58%Heodo
2020-09-24Mes-2020_09_24-CV9525.docdoc 441ad457e4ddfaca677155904b89ca29985e8a97d7b9477c7629d7e3acbcbd43n/aHeodo
2020-09-24REP-2020_09_24-584142.docdoc 4a7b9059ed2f25757d6e26bfa82478a8ad0185e0667ccd1a3f34409081c8892dVirustotal results 35.48%Heodo
2020-09-24arc-2020_09_24-ONJ9436.docdoc 55388c604861ff723371329b1a3915d35ec93ef0376b4455a179cf48e14c0799n/aHeodo
2020-09-24DAT-20200924-48020.docdoc a480137b781966afdb9faf717461bdfa384061fd21da898b447d924801063c60n/aHeodo
2020-09-24INF_2020_09_24.docdoc bd244207a04b13c2f19aa2ae6cfcb18baae07a101e2d455f3dc45224e7540b80Virustotal results 32.79%Heodo
2020-09-24rep_2020_09_24_225776.docdoc 3196b8694fd5439fbabe402c87ca63a1d71fc67c7ee0d3a23fc0b3db6201924dn/aHeodo
2020-09-24Attachment_20200924.docdoc edeac6b6b86c18650d2a2f8b7d9737c558892f5dd76da6be7b771e5e010bb244n/aHeodo
2020-09-24INF-386947.docdoc 62e2755b440593966cab9014c2af893a1ad4d8d576a6d2569db57d9fcbbd9abaVirustotal results 20.00%Heodo
2020-09-24inf X840.docdoc 528d22e4147caf0834320353578b1d3fb47fe97bd180e7d2bf9f764980d14bacVirustotal results 42.62%Heodo
2020-09-24file 2020_09_24 A50912.docdoc 448c58d4e526ffd04116fb0f31bd9971ce9f51c993c4368e3ef8a54c93a2c70cVirustotal results 44.26%Heodo
2020-09-2400434199 XQL172.docdoc 24e031fb985e7f9a012366503ac58c163c138850f5707b5029a5793b27857ba5n/aHeodo
2020-09-24Attachments-2020_09_24-31444.docdoc a496cccdddad5164a08cbffe45117788e25e55db35dbdb3f92db0d967ff0e452Virustotal results 27.42%Heodo