URLhaus Database

You are currently viewing the URLhaus database entry for http://patcraft.ninja/toolo/Scan/l6w6bsel3/2gvhgtb8333223026926924aaqdqajxy7hdj532p/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:609845
URL: http://patcraft.ninja/toolo/Scan/l6w6bsel3/2gvhgtb8333223026926924aaqdqajxy7hdj532p/
URL Status:Offline
Host: patcraft.ninja
Date added:2020-09-24 11:18:33 UTC
Last online:2020-09-26 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 11:20:06 UTC to abuse{at}digitalocean[dot]com)
Takedown time:2 days, 6 hours, 38 minutes Poor (down since 2020-09-26 17:58:50 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-25ZPL_090120_CZI_092520.docdoc 8a73bdca97395b9f659104c200734008fe685faff6734fc31ce0cd575090f1b2Virustotal results 35.48%Heodo
2020-09-25G_WW6684845005NO.docdoc c12a24dc51b89166e734d3ff2969cb866132c5865e0f5aebe7d442fd57d9e4b6n/aHeodo
2020-09-25REP_7TM0WSX6T6XYGWQ.docdoc 5527db4d50b16756417124cf891df4ce3d61c561eb2782f339973dc75c73390bn/a Heodo
2020-09-25Z_QED_090120_WTN_092520.docdoc eefd694ad7a3c1d10441452c651459410143b5ce0d56e19d39c16c1114105d09Virustotal results 30.65% Heodo
2020-09-24BAL_XR4410668988IT.docdoc 47e84b40c894119dda8c1abf4033b74ccdea7712d9ee871dde8360c87e7951baVirustotal results 20.97%Heodo
2020-09-24INV_CHX_090120_UXE_092520.docdoc 067c4167bccffac88b09ca407f2023d128d8da729e468ed4c7779cbf248653b3Virustotal results 24.19%Heodo
2020-09-242CW3EIIAAA85D9F.docdoc cdd71002bc856432c4601d28ab82f21a59cc5dfd779119a556b6e353a3a9f5efn/aHeodo
2020-09-24CX_TCN_090120_IJD_092520.docdoc c8e1fe8c16784222fdc737735ed29812a5f1721e61b75f3386fa6ea802c9b525Virustotal results 21.31%Heodo
2020-09-24BAL_2350788604427915399.docdoc 071b94219cf7f333e5e3c76753c74ec9a5d71f9d4ccf17cb631287fe3508e39fVirustotal results 32.26%Heodo
2020-09-24INV_WV2750560063RE.docdoc 35774d12164e3314ec57dde2f5948d18c0e60439fd49b21753e4e0954b3325d3n/aHeodo
2020-09-24INV_WS7549169774AW.docdoc 9dd8a90d5bcddd1b1748a24fbb8c636601ce3a3d198b95e342958492db07fd98Virustotal results 29.03%Heodo
2020-09-2462467338598.docdoc c4fc9ec7954c1bc71dc415464f2813e6151dd7c106526dfe3aa8d97ec3b8f9deVirustotal results 20.97%Heodo
2020-09-24REP_04U48JN.docdoc 96d9b3d02df7aea418bb5629677cc35f0eaee5ea68e2373e23a730378f5f5297Virustotal results 29.51%Heodo
2020-09-24BOD_090120_RKY_092520.docdoc 2a3395e9459dc5f0fc72621c2299e98b4226e6b99cf6069d89004e3d430a219dVirustotal results 29.03%Heodo
2020-09-24BAL_35292230.docdoc 02ef96f4a3c715053acf327bd61196658034d30887f0bb1a9769e4bfedfe0a41n/aHeodo
2020-09-24VG0642484605UZ.docdoc 5bbcb03cbdf0fa9eb5854ee7d5c7d3669e469fbde2dd1cfe0b6c4767dd19d138n/aHeodo
2020-09-24INV_PO_09242020EX.docdoc 68d56a79c843b1b6a5d9937b5f98c3ecd25a60ebbffb348a9e08cde6dd1a98fdn/aHeodo
2020-09-24PO_09242020EX.docdoc 85c3fbc17a0daacdb938f7ea4b8dfa14ae9a099d59de1e9fef807b569c999acbVirustotal results 19.35%Heodo
2020-09-24I_ZFB_090120_CLM_092420.docdoc 85264b8b2a7f29ff8c64c3de97d3e17a58c4aa09c6a67460d5be96117461224bn/aHeodo
2020-09-24FILE_431327038747.docdoc 0c7afbe35c98a28e15a89bfcadca720430162ad730a496d96595ecfbd3cd1683Virustotal results 19.67%Heodo
2020-09-24I_MX7482637879HA.docdoc 267834c0d23e344ce20d8814e0e5499c7f5bc32fbda08c9ebf721a3dcb2efe26n/aHeodo
2020-09-24BAL_PO_09242020EX.docdoc ce2603e03a1742baf5735e994899aecaa1075b7d6a3a811070455dc802e8df15n/aHeodo
2020-09-24INV_KPD_090120_XXI_092420.docdoc 1e8a41d3b5b66bf2151302e128b041ae3994ea9a2a0a688a098fb691a692e222n/aHeodo
2020-09-24PO_09242020EX.docdoc fe9b0b3adac87d1fe5b13863ff7ab54660757a7bc0b4996cfe241ff357c57b3dn/aHeodo
2020-09-24LOM8XNWRDB.docdoc 8b90ba12e56de7cf064ee54d147a39175bea9149cef12b45b5fcc04b43808d9cn/aHeodo
2020-09-24DOC_093983776835271030045.docdoc 460d4f1fa3c90d50ae0a56c6c4c26bfcd3d3d22829baef98b7ea3e9b451974feVirustotal results 33.87%Heodo
2020-09-24D_045313825381568635763831.docdoc 3321abc9c460868cfafe80f968ccea4254b02ede808bcabe4dd58055ffddb358n/aHeodo
2020-09-24RG0125454112JX.docdoc b8a9d5f54e75467b003cb37db317d9537fc49705aa3334531937929937b0eaaen/aHeodo
2020-09-24LP_MC9056401075JI.docdoc da886aa9c4cf9af28406c6c6b2bd1a84fdca0dd1861259185aba9da512264acfn/aHeodo
2020-09-24L_68SG5AM0KQ48W.docdoc 0513605e1d28ab01152da25d30cb6762b95b79d8183cb775c505abc6f341e4f5Virustotal results 30.65%Heodo
2020-09-24REP_75237260.docdoc 447465de32a94153d18ec88201122059c81c4d5e43fad6bdace0fc4b7b788a57Virustotal results 27.42%Heodo
2020-09-24W_NIT_090120_NRJ_092420.docdoc 5c7bfd1823b37a4f48ff0166d60e88e0be88ae562cf87c6bf393597da4fd835bn/aHeodo