URLhaus Database

You are currently viewing the URLhaus database entry for http://microsite.buniyad.co.in/qhh8/Scan/qc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:619499
URL: http://microsite.buniyad.co.in/qhh8/Scan/qc/
URL Status:Offline
Host: microsite.buniyad.co.in
Date added:2020-09-28 23:06:30 UTC
Last online:2020-09-29 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002971328 created on 2020-09-28 23:08:09 UTC)
Takedown time:6 hours, 30 minutes Good (down since 2020-09-29 05:38:11 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-29DOC_PP5353748331BA.docdoc 1087155bc18fbbc2413d2ce4a37be877bff2d9d95202b3f9a9c5ba3a9c986e74Virustotal results 43.55%Heodo
2020-09-2972071094.docdoc aec0879b78a9a099436d59b73582462c6149429a5b11474954ba0fa0b75d7c64n/aHeodo
2020-09-2976067478.docdoc e845bd78a64f545d9f7b775917897db736b2b48e13501d975816bf84e36f75c0n/aHeodo
2020-09-29DH0755735297KV.docdoc 15d3403b8d1d07b8b635e79f0fd458c3961ef5b48d60d19b6596c9c1028a2662n/aHeodo
2020-09-29FILE_CB6374880161OK.docdoc d3b204a9a314a83910394cbfc8ce9a3ee143f7dff5fb09a1f17b138bd042f27aVirustotal results 42.62%Heodo
2020-09-29DM2113453765MW.docdoc 665a83304be8126632283c77fd184c5093b67885447b2ff3832e60ca7131675bn/aHeodo
2020-09-29J9CXEZ3W.docdoc a973fb7943766b57cd43a3411ebc0e4f2526142e27a0c7e259a0fdabd30a5596n/aHeodo
2020-09-29FILE_PO_09292020EX.docdoc 5a8be1cc109ff476e4b7ffbd87db95b671cd66eb4482bef8ed076629fc0c0152Virustotal results 39.34%Heodo
2020-09-29Z_NUDSU7WS4.docdoc 3d6b85f9f65640711318439f907eb96de0373d99872765323dbf7b21696159eaVirustotal results 37.10%Heodo
2020-09-2903323431562.docdoc 8d59fd778e28d2031a7419577a57bcbbfab3de3caef805c35e4431f436328d85Virustotal results 40.32%Heodo
2020-09-29PXE_090120_HMI_092920.docdoc b74254f66908c1f19454f3a01f443968483b4835fcb9952d5ced94e754c9f312Virustotal results 38.71%Heodo
2020-09-29REP_TXR_090120_BXK_092920.docdoc 0383ecfdf99c78b9251b7857ddb9c66a992742cbf247aabb1a300ca9a1b4806aVirustotal results 37.10%Heodo
2020-09-29BAL_FAD_090120_ZMK_092920.docdoc 62d1a0ddc98b6e9f6f22539f196550672415057298dbe058673fd5fc8bab7bbaVirustotal results 37.10%Heodo
2020-09-29JEFQ_36245069.docdoc 13b98d2f0d07581934fcff17efd69c9924d5cc1d0bb874c28eaaeb497cba7bb4Virustotal results 33.93%Heodo
2020-09-29INV_99046308.docdoc ec3551f3adec4732bf943e62d97b659d244f9944f90537dcaa93c7f8c76d56fdVirustotal results 33.87%Heodo
2020-09-29BAL_99624770.docdoc d44b534f8c20e7e7c7fe8d7434575f4fbfe7a42960fe2afa6e940537a8d10c2eVirustotal results 32.79%Heodo
2020-09-28S_PO_09292020EX.docdoc 81931603dbb92f78032227c21c6bcc3a3dfe98352c81d885a9c28d8fe622b957Virustotal results 32.26%Heodo
2020-09-28INV_PO_09292020EX.docdoc 062b6c361a8a16a16a0a473b92473450686b604fb275c6a38d95dc46477444faVirustotal results 32.26%Heodo
2020-09-28INV_ME0952538019TH.docdoc 5511a4406f3aac11acd3a67d5b5a567088a88e946caf868616b1de1bc329b09fVirustotal results 32.26%Heodo
2020-09-28FILE_UU4887629616SG.docdoc ca07979b399d505a206ec7c3db9d742e72efee8adcfa6e2c517a553d3102e2adVirustotal results 31.15%Heodo