URLhaus Database

You are currently viewing the URLhaus database entry for http://brigadecornerstoneutopia.buniyad.co.in/thanks/PXPSCvitHw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:620425
URL: http://brigadecornerstoneutopia.buniyad.co.in/thanks/PXPSCvitHw/
URL Status:Offline
Host: brigadecornerstoneutopia.buniyad.co.in
Date added:2020-09-29 03:12:07 UTC
Last online:2020-09-30 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002971706 created on 2020-09-29 03:14:28 UTC)
Takedown time:1 day, 4 hours, 18 minutes Poor (down since 2020-09-30 07:33:08 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-29inf 2020_09_29 871.docdoc 30490b4f611eb7e7e2458129bda3265befe37d0133dba94e10cf07c5aae28de6Virustotal results 24.19%Heodo
2020-09-29List_2020_09_29_842014.docdoc f8382d886701b5bdb8f0651a1346114c55dfd557cd1f80204a645d9f49a6cd52n/aHeodo
2020-09-29List 2020_09_29 WZL99984.docdoc 475f7a5d5ca5a16e679e4f8cc780cef9765e9cc75a3f7e4c76e1f1ecd0238824n/aHeodo
2020-09-29DAT-JU5878.docdoc 7d083b80052d8095b54f8b51ef125ea68f5981c34b0d562843708e46dc40ba8cn/aHeodo
2020-09-29MES_2020_09_29_416648.docdoc 02b930d350866dbdcc07e0ce90a98efb7b5e4fd14c09e41f986d23fa5c79db21n/aHeodo
2020-09-29VM224-2020_09_29-39078.docdoc dffe6b12754772da4ccc5aa7c07425a752a3680f801e0df24fc609e879e83e8cn/aHeodo
2020-09-29Mes.docdoc 27be7747d9f1e8080ba29e9d11d4623e75d529133896b0c741ad580a77524be1n/aHeodo
2020-09-29ARC 6055732.docdoc 33c4a2fd6323bb9b915d3368cca5015470e2ebe56ac0d7fc33568530acc9fafeVirustotal results 41.67%Heodo
2020-09-29Dat SM720.docdoc 84d5460aef2a23f5767b23450722501823e848fff6d7c0f2c5676a6ab79706feVirustotal results 40.98%Heodo
2020-09-29Untitled.docdoc a172322135f760ced398ed29bdc125263aa20fd42391c0ff1db2c8d29a9fd5can/aHeodo
2020-09-29list 20200929 BU75432.docdoc a721713b9b8dbf3f7afde4ecda5e2161a48cf67c5277c3836c0df121ca2d6b18Virustotal results 40.32%Heodo
2020-09-29DAT_2020_09_29_0669293.docdoc 466ecc37e94d5c4fc81bab60c1395d3cba013f2b4cd613280ee6c9f394f93f19n/aHeodo
2020-09-29Doc I043.docdoc 6393adce2e6fe6411ce0d55abdc750cf798b4d5e95ac789d82fa303e456ff200Virustotal results 40.32%Heodo
2020-09-29Attachments-20200929.docdoc 92f8bccca3a1b18424b20a4cde47574b9446c3cc35c59bd7189cfba6b47f6d6dVirustotal results 40.32%Heodo
2020-09-29Rep-20200929-MK4818.docdoc b19337ff283d5e928eb6bc9b902fc02a47f506746ab9fc02955e02d7112f3be5n/aHeodo
2020-09-29191584_20200929_JV905.docdoc 1340d8450093c4b10ffd24cd42262a4c1115b9f6e0a8a7c0bc184f9973cf8b6bn/aHeodo
2020-09-29REP-20200929-506395.docdoc 4dc9418d6c5b851e2985dd79fb58ad409a9442d22dfa9e5c9e2c4b475bd8f02eVirustotal results 38.71%Heodo