URLhaus Database

You are currently viewing the URLhaus database entry for http://microsite.buniyad.co.in/qhh8/979/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:619498
URL: http://microsite.buniyad.co.in/qhh8/979/
URL Status:Offline
Host: microsite.buniyad.co.in
Date added:2020-09-28 23:06:21 UTC
Last online:2020-09-29 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002971327 created on 2020-09-28 23:08:05 UTC)
Takedown time:6 hours, 22 minutes Good (down since 2020-09-29 05:30:37 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-29V_O3PXEWK1W9JRE.docdoc aec0879b78a9a099436d59b73582462c6149429a5b11474954ba0fa0b75d7c64n/aHeodo
2020-09-29ALP_S240FI6.docdoc 18b180a651a5c1f82e1e37fa36fc92e6c0e2516bf788cf33ab3f6f6681be6cc8n/aHeodo
2020-09-29D_02NVC19K.docdoc 1af9c4541fd3967f4d9820ee633cde8bee8d73612d046cba0456debdf28313aen/aHeodo
2020-09-29INV_36934117.docdoc 4b7fd3aa52853241aaa5c8d95e005ace57390afc9406bdf9da287bd7c6ccd123n/aHeodo
2020-09-29NDA_090120_ZZR_092920.docdoc 70ea160fde803539083eb208609b17b5910f502f8bb0a3e36e053ece5b214df2Virustotal results 41.94%Heodo
2020-09-29REP_KQZR33P0.docdoc ccc18b91da784754f83482778c7bfc1de931b4416de9957b6e7b61b25d8d43caVirustotal results 40.32%Heodo
2020-09-29TO8642350759NO.docdoc 22a6a4e3f1f8a228220e5ee2c90a0eca756a901e6907d3f58ea65edcf5ed01abVirustotal results 40.98%Heodo
2020-09-29SSR_090120_WZX_092920.docdoc 5a8be1cc109ff476e4b7ffbd87db95b671cd66eb4482bef8ed076629fc0c0152Virustotal results 39.34%Heodo
2020-09-29INV_QQK_090120_CRN_092920.docdoc acbe625125210f292986e1a32b358fc608504c11aee463f05e4ea2b4ecac55acVirustotal results 37.10%Heodo
2020-09-29BAL_PO_09292020EX.docdoc 354f42e3a360351ce3a12b152b9b619b2dda611a1bd404d2e54a8e0f2249f988Virustotal results 38.33%Heodo
2020-09-29DW_CJ1DYZ63UDH.docdoc 098fb7d718037b90543175fc964c4fde918746825292005bdca3f6bf33a29360Virustotal results 37.70%Heodo
2020-09-2935286781.docdoc 7cf6bfee34514fc64699f528b75e89bd79fa6f40567cd474844dd861ad118998Virustotal results 37.70%Heodo
2020-09-2990138753.docdoc 62d1a0ddc98b6e9f6f22539f196550672415057298dbe058673fd5fc8bab7bbaVirustotal results 37.10%Heodo
2020-09-29G_PO_09292020EX.docdoc 13b98d2f0d07581934fcff17efd69c9924d5cc1d0bb874c28eaaeb497cba7bb4Virustotal results 33.93%Heodo
2020-09-29INV_PO_09292020EX.docdoc f84be91eaa46a92cbd5d01beea7f41b3b0422079aeb425f74b2322266934c301n/aHeodo
2020-09-29DOC_57950278094.docdoc ec3551f3adec4732bf943e62d97b659d244f9944f90537dcaa93c7f8c76d56fdVirustotal results 37.10%Heodo
2020-09-29FILE_7KWRRCEEPPJ36L.docdoc f32f8b9e20a672922119f98f132c9fa7f52718da751a756707a788cc8f64d4f3Virustotal results 35.48%Heodo
2020-09-28DOC_PO_09292020EX.docdoc 1fdcd8e253588b618783075095bff83fed0abcfb359a355750122d417f337993Virustotal results 32.26%Heodo
2020-09-28INV_SH2159491028GO.docdoc 062b6c361a8a16a16a0a473b92473450686b604fb275c6a38d95dc46477444faVirustotal results 32.26%Heodo
2020-09-28DOC_SXGPJRX4P9.docdoc 5511a4406f3aac11acd3a67d5b5a567088a88e946caf868616b1de1bc329b09fVirustotal results 32.26%Heodo
2020-09-28DOC_YNH_090120_UXY_092920.docdoc ca07979b399d505a206ec7c3db9d742e72efee8adcfa6e2c517a553d3102e2adn/aHeodo