URLhaus Database

You are currently viewing the URLhaus database entry for http://rtgpanama.com/eviltwin_sym/attachments/qiyukxs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:619141
URL: http://rtgpanama.com/eviltwin_sym/attachments/qiyukxs/
URL Status:Offline
Host: rtgpanama.com
Date added:2020-09-28 21:44:05 UTC
Last online:2020-10-08 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-28 21:46:10 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:10 days, 1 hours, 36 minutes Bad (down since 2020-10-08 23:22:21 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30PO_09302020EX.docdoc 7d2c8d827a62c501876d11119d9989eae86dc953f1f0ced0c65a9567cb616fbbVirustotal results 22.22%Heodo
2020-09-30M_VZZ_090120_YMB_093020.docdoc fc6f0ac3e38b970866e30342911b1f72bc2a028a33a093badc8c5694321d5808n/aHeodo
2020-09-30INV_WGZ_090120_IRW_093020.docdoc 24e3ba16d86892e3c786b97123151b7a2294602a61bafd3c546475d0597a2a37Virustotal results 45.90%Heodo
2020-09-30NT3691467595LC.docdoc a9b4569007c2822d7d717a8ea3a4e3a496c52a3f2011519ca3c4dd5e42011465Virustotal results 46.67%Heodo
2020-09-30REP_SRT_090120_DVD_093020.docdoc 09920ec2c5029cdb6177cee45414e34e9307a6f40548df1ba80385c44cfcc613Virustotal results 43.55%Heodo
2020-09-3030956250672697441241.docdoc a1cbbf8abb7c17079dd727968cf72dadead6f70a04ffc9f51b29860c9a8d4801Virustotal results 44.44%Heodo
2020-09-30XVZ_090120_HYI_093020.docdoc 3d322e72fd831b7624674c0a9ed650c75bf0cf2d05e5c2dcf7746ee4187260b3Virustotal results 45.16%Heodo
2020-09-30A_PO_09302020EX.docdoc 5b04551305572c828c0ac8143249ef7e94223b0fbf7d12b43f77c4e3da8bda45Virustotal results 40.32%Heodo
2020-09-30QWA_PO_09302020EX.docdoc 42c1f3bb9e1fae138c02e1447a93ea34c9c4859fca0078bdd3ea01145c4ed12bVirustotal results 37.10%Heodo
2020-09-30LZR_7JPT81AYR0TGAOT.docdoc 1854226276e84dabaf5ceaefe8e33cd56360b60752eef6ff1a0e8e1657931e53Virustotal results 37.10%Heodo
2020-09-3086951399.docdoc 797ac0be9b6e1c912dab41fdf6c487642e027c1a24c2a6510ee3a1a326ef7bb0n/aHeodo
2020-09-30DOC_88115693.docdoc aabd54aa244d3a19daa025d685a63495581f02a35c44e11bdb76ea7bbf7360baVirustotal results 32.26%Heodo
2020-09-30INV_520761627050192861902.docdoc 8649c9f23563646d5b0033bb729307388ddb4396da639cbf0385c08ec0a01cffVirustotal results 32.26%Heodo
2020-09-30J_TLN_090120_YUN_093020.docdoc d56585c6e4a0ede125061be754c5a0c9b45728232d4c61937ffbc047df3aae30n/aHeodo
2020-09-30DOC_AJ6539521612GX.docdoc ff1650382e69268384234b18f44e36d54c6f3dbadfd3a0ef497e97729639a6b3Virustotal results 32.26%Heodo
2020-09-30INV_61944915.docdoc 75f032ed1b4c5d9738c4ebee1d878f1fe5307cba5c43dc44ce2443a640e7fb2fVirustotal results 31.15%Heodo
2020-09-30F_TTS_090120_VGY_093020.docdoc 587adcb5768ec9aa8b3be79e9ea740bc5052b9d0f09d4b2854fac3ff667edd4cVirustotal results 32.26%Heodo
2020-09-29G_ZJR_090120_EKY_093020.docdoc d6baf92252e2e3e673077f1cea8fc4bf0e240f4383dffc91c53d88857ba5fdf7Virustotal results 31.15%Heodo
2020-09-29BAL_PO_09302020EX.docdoc 5a9f82efe64ed654c3bc8be5822ab7e6cc987624f9b90222d1ecac779b7d2347n/aHeodo
2020-09-29BAL_1282232345510604912554.docdoc fbdacf9e30368d59414b52f459d935964b7833d6d8467bf0eb4ccfa97f71e4d6Virustotal results 29.03%Heodo
2020-09-2944873464.docdoc a863d09af176344fa94c7820a54398bd505f2ee93f7f66a6f05d3e60b71479ecVirustotal results 27.42%Heodo
2020-09-29H_326946591167465660266631.docdoc 91d4d101c3e8a665106bb48847dbee3791e2a9a04c0adb2f363ae7767e463337Virustotal results 29.03% Heodo
2020-09-29DOC_BB0048144340FX.docdoc 76d3bae4ebe683a5d3ff0d90971119c287a3acbab073e28b979ad7eaa60e37bfVirustotal results 27.87%Heodo
2020-09-29INV_TU1958906739QC.docdoc a6f13db40e3ed06a80aa775c78382c22282019f54c1f646ad0cfd78ffa13bfc8n/a Heodo
2020-09-28DOC_PO_09292020EX.docdoc 17d5a70293fb25971975ca6e3db5b2c8ab64a4ce026604b60278b18d01c0224cVirustotal results 31.15%Heodo
2020-09-2837667564.docdoc fb750c257e518602c4a6384f5e206558a523d360ef67037ec095446dc04034fen/aHeodo
2020-09-28DOC_79767548.docdoc 929d7e6048f9e35070989f784268013a55e08fca900478f5303eb8255879e5c5Virustotal results 29.03%Heodo