URLhaus Database

You are currently viewing the URLhaus database entry for http://email.undp-fakhoora.ps/cgi-bin/docs/hiSllZZdJJsCkbXiehmy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:630796
URL: http://email.undp-fakhoora.ps/cgi-bin/docs/hiSllZZdJJsCkbXiehmy/
URL Status:Offline
Host: email.undp-fakhoora.ps
Date added:2020-09-30 16:53:34 UTC
Last online:2020-10-01 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-30 16:54:08 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:23 hours, 5 minutes Good (down since 2020-10-01 15:59:57 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-01AM98369_20201001.docdoc f4aeb1fb3ee7a1e47154bd3b5b2209626b73ca9812072ce7597fd191cc384e93n/aHeodo
2020-10-01Attachment_20201001_IE020778.docdoc 70fb53e73b6f88f473daeff54fd683ca2520516013df40ed5446b86bfc4a097en/aHeodo
2020-10-015268 20201001 9487086.docdoc d09def23b85e52761ab948f8a0a73e9d2f43f1a06c27f35973dcedbc87954564n/aHeodo
2020-10-01inf_2020_10_01_3135899.docdoc bde7001edeb6f299d49c1bd80bfa2368ed58033c8a6f3da6fc35e3b77b6fb79dn/aHeodo
2020-10-01PEA19783_2020_10_01.docdoc 4b931434cdbde8e532c7a09e37b78dd2166f37a0fecbabaecdd38a2217049341Virustotal results 37.70%Heodo
2020-10-01Attachment_K62430.docdoc c37536624e100c6928618bde49c7c002a4795fe400199b57806f7e5a6bfb1c4en/aHeodo
2020-10-01Dat-3838.docdoc c831c106f8014dfb9f2010acf1b27a73896a4def52607e403a2a9740926ed0ben/aHeodo
2020-10-01ARC_2020_10_01_8550656.docdoc 2316491908b1b0175a9782d21fef85f16d29b5dd05d72c00c8dc943ee110afb4Virustotal results 35.48%Heodo
2020-10-01Rep-20201001-164632.docdoc 180e17d6d6ede320ae7e947ea1e473ebdb11480a9200cb3bdeb8d38a15e5e4b3Virustotal results 35.48%Heodo
2020-10-01inf_20201001_RAR47936.docdoc bae61d952a3f4eced141514b551812240ae6ef483a185a834760c8421992f1e3n/aHeodo
2020-10-01TWA44746 9771023.docdoc 6ffe1f1e0b366f49f5644ef9775e58ea1aa808bdfea4ced1aa367e2e44cded16Virustotal results 31.15%Heodo
2020-10-01Mes 20201001 V169.docdoc bc473e3c095e5c8fc312b29ee596cfb5c7f89bd4795e09377e0a3258761b3c25Virustotal results 29.51%Heodo
2020-10-01Arc-522875.docdoc 87441c831ad7808d1f9a4fc6533c65071a13b9ef979ab68ffd24565426558597Virustotal results 28.81%Heodo
2020-10-0159217-20201001.docdoc 2236eced769acbff98e98c0f0f46643a46d2411d661697211da7a01b9ed7eb2cn/aHeodo
2020-10-01inf-20201001-XHH7203.docdoc f599f04651361e4298bea8b9c219e4588d021a8cbf00802660a69c92584446d8n/aHeodo
2020-10-01List-20201001.docdoc 750f3ddf6c6bd8e7cf26c3d8103a0dd26becbf4a754fbd78bcb33a8bd165741fn/aHeodo
2020-10-011628309_20201001_6292.docdoc e79f250400c358da91a7a87f73902980819c94e0b51c91323cb3b3b77fcd4283Virustotal results 27.87%Heodo
2020-09-30mes 2020_10_01 690.docdoc 83528dd86f27eafffd6b8b9bc31bcd40ce046ae2f1eadc585ccc3125af320625Virustotal results 27.87%Heodo
2020-09-30DAT-20124.docdoc 22fe0364950c229cd81ec4900c5082c63179d87b3475e0ba2533f7d02d0a9658Virustotal results 27.42%Heodo
2020-09-30DAT 20201001 QMD260568.docdoc 111272b4f9fa36b17efc27ee4685f0300764cbf2aa0f028174a6d6f249393844Virustotal results 27.59%Heodo
2020-09-30LIST_2020_10_01_ENZ40061.docdoc 00811b4a43db0ac2a88c49f0f4cbda45da02316ba871e9e1fca39f1217a92f46n/aHeodo
2020-09-30Mes_845759.docdoc 59218dd633aa6e55d901c1a8227ace241e21d80c34af6fbd4dd99400832ef122n/aHeodo
2020-09-30FILE-2020_10_01-43936.docdoc 7b2561cccd85d4a2dd4d7c8c873b6e498f1030c959b48a8899a4032502d0c4c4Virustotal results 26.23%Heodo
2020-09-30dat L2126.docdoc fe188a82b959918eac4007d04f619ee4ad081730eaa6da718e8e4e0cd9d594a0Virustotal results 25.81%Heodo
2020-09-30INF_2020_10_01_436.docdoc 32a1991f3cccd7f0d787d1fd9ef745328cefd8d134d25a6a2e12d49808143952Virustotal results 25.81%Heodo
2020-09-30Attachments 2020_09_30 412608.docdoc 7894db05f1e0bf0341427a40ee7bac8f5ef35bc7acac378caa332c08586b9514n/aHeodo
2020-09-3038676296_20200930_287908.docdoc ddf8988ebd5fa555488322ed3fe2302ded38b89794abacdfd52a46ee6b1f0ddcVirustotal results 24.59%Heodo
2020-09-30Dat_20200930_7366810.docdoc 9bd5e78a295d861307808771659e53c1312461fb22f61de2b49e870ff1d7ce81n/aHeodo
2020-09-30mes_2020_09_30_G875.docdoc 86c6b7b0bcb5c5ba4062cb3cf30ae97c00932ea003bcb4ab638a0c2bea73b2f1n/aHeodo
2020-09-30List 5184521.docdoc 5f1b7ea2789bf23bdbd87c87daded72bb53aad07fc776bd6622709482c002b33n/aHeodo
2020-09-30doc-XSO048.docdoc 98a129783214c4f848182d4ee393f9778ea81fad1808c5d1e589afa4738e38adn/aHeodo
2020-09-30REP 2020_09_30 GWA5502.docdoc dc681f3d1933c88a3830910384602c5c5b3f2f3c0fce741e5becebf377a6ad03n/aHeodo
2020-09-30doc_20200930_0153.docdoc 7b88d7d16e92fe2b43237503e65687bab67b65fb283976f5bbaf6118da398422Virustotal results 24.59%Heodo
2020-09-30Doc_2020_09_30_7507.docdoc f47d11699a95847586f0da23f16b981f953514459199b7edd30f723054c057f7n/aHeodo
2020-09-30List-2020_09_30-8565425.docdoc 78c3d9c43524e6cad2289a2edef0f563b37f586414c83c73c0e57050d79f6f58Virustotal results 24.19%Heodo
2020-09-30Arc-NIS2665.docdoc 7783a01f4659fa35c499ce2c254283694b258a8e829b13cc83a58e060dcdc112n/aHeodo