URLhaus Database

You are currently viewing the URLhaus database entry for http://naveenassociates.co.in/kljb5/attachments/f6374987261048772romcjvbfbr375/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:608588
URL: http://naveenassociates.co.in/kljb5/attachments/f6374987261048772romcjvbfbr375/
URL Status:Offline
Host: naveenassociates.co.in
Date added:2020-09-24 03:12:18 UTC
Last online:2020-10-05 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002960042 created on 2020-09-24 03:14:06 UTC)
Takedown time:11 days, 11 hours, 15 minutes Bad (down since 2020-10-05 14:29:40 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-26R_GH8322082443KR.docdoc 70b7896224df87d94e16a934abba5919f7d6a7cfbd7960a9f1c6f75d05dac546n/a 
2020-09-25REP_74974651.docdoc 8a73bdca97395b9f659104c200734008fe685faff6734fc31ce0cd575090f1b2Virustotal results 57.38%Heodo
2020-09-24RW6615289766FA.docdoc 8ffd33471d8e180b9ff498aaa84ef11bf50e846252c62e42e416fe68c1698d06Virustotal results 25.81%Heodo
2020-09-24PO_09242020EX.docdoc b8c075d4057bdd225bd2328001ef2cc8efb5e79192d6c2fe8279677927714ec8n/aHeodo
2020-09-24BAL_PO_09242020EX.docdoc 29f8908fad78f532f3e53d23cd10d6289376b52c559e2398ab3a2ceb671ba1cbn/aHeodo
2020-09-241869241141700231186045.docdoc 32bbcef052b442f62a2fbb0c5dad498dcb779148f31f2e51d4f7a38245024f8eVirustotal results 20.97%Heodo
2020-09-24QJI_54872093468928366373.docdoc 60b9c51a988490875a152231c3217de228b7406a1378ab07263aea7f02ecd3ccn/aHeodo
2020-09-24IMT_25231199.docdoc 460d4f1fa3c90d50ae0a56c6c4c26bfcd3d3d22829baef98b7ea3e9b451974feVirustotal results 33.87%Heodo
2020-09-24REP_22603488.docdoc 896f6e1b9eb9656cfc68db252241fc7087192661175a0604505742223f0ef016n/aHeodo
2020-09-24FILE_PO_09242020EX.docdoc 8b209e2d294b8c5b50bd83d9fd9184268ce21313f7d5876d74c7e10f48ac946eVirustotal results 20.97%Heodo
2020-09-24REP_PO_09242020EX.docdoc e2dffd7e2a3663a738dac21fd590dec2cce14df9ccf7aebcc5944258a827bc04n/aHeodo
2020-09-24BAL_46239414090703382485.docdoc d522d2f16aa3e16dc127e4340ff8bfd23ab4de894995c8dbb75b31bd4b4d73cbVirustotal results 38.71%Heodo
2020-09-24BAL_46679234.docdoc a92504d33c04f21f1e8bfc2322f66cf3d45f486ed7ebbf78f3ee270fb0d3e3a2Virustotal results 39.34%Heodo
2020-09-24YX7756057769DK.docdoc 4e227495a216d86b2e51164a32e9ec057c53cc5e829107af1aeb4ee9764bbdccVirustotal results 35.48%Heodo
2020-09-24REP_DIZ_090120_ZND_092420.docdoc 353903d7b90942b9e45059e7a1ea56eea91c412f5cf0864982870f55f9e61e98n/aHeodo
2020-09-24BAL_VAI_090120_WBV_092420.docdoc 2ec5659b0eadb3f644298e5c297be25451dff898c0551365d0d757a4e5975556Virustotal results 37.10%Heodo
2020-09-24084020157161219169.docdoc 7aed739ebb48064d94fa17f51816a7d3f4414ec8d578a6bde0830e844055e971n/aHeodo
2020-09-24FILE_PO_09242020EX.docdoc 89221a444d804e1d28751ac3f2cab050f02f3029ed849cea01f98def15afb0e5n/aHeodo