URLhaus Database

You are currently viewing the URLhaus database entry for http://nifadp.gov.np/gradle-pass/Document/l2n970d9pddt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:697902
URL: http://nifadp.gov.np/gradle-pass/Document/l2n970d9pddt/
URL Status:Offline
Host: nifadp.gov.np
Date added:2020-10-15 13:38:06 UTC
Last online:2020-10-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 13:40:03 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:2 hours, 54 minutes Good (down since 2020-10-15 16:34:46 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-15FILE_VJT6NJ1.docdoc 80b86ab3fd2dc47857dfaed61fdc9398efa3f97a1ac898fdc453fdcf5a36091aVirustotal results 40.32%Heodo
2020-10-1585967077176140250570.docdoc 5ab7feb155d115d799a41194045fc38c07b387a68020f3a94e1cbc64c18d4893Virustotal results 40.32%Heodo
2020-10-15DOC_PO_10152020EX.docdoc 1c16646cfeab936d7c06b734940cc016e92adedd7f48dd60de9d7ae5b9c0f0f1n/aHeodo
2020-10-15K_IQV2NJLO4CTV26CY.docdoc 108c2c7c6598b9ff017de74522cabbaee096e3a62cc018573c6ce7c759a7dceaVirustotal results 38.71%Heodo
2020-10-15APE_100120_KBW_101520.docdoc d86352496d079f14dc91a06448f118b5035b992f0edc956a2d8a58b92a0f7417Virustotal results 40.32%Heodo
2020-10-15YAJ_100120_QFZ_101520.docdoc 0850678a5e71af1138fff503d804bcefac8f4f1879bd6ef978b7b2ef7ec7a5f4n/aHeodo
2020-10-1592631395.docdoc 150a907ef1ed91483bb2a8f713e223b4f30c5e5fbe1850280053b1ad4a8a05a4Virustotal results 38.71% Heodo