URLhaus Database

You are currently viewing the URLhaus database entry for http://nkvkoilterminal.ru/mangerite/sites/L9AW3QutKJZ9YtzP/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:698775
URL: http://nkvkoilterminal.ru/mangerite/sites/L9AW3QutKJZ9YtzP/
URL Status:Offline
Host: nkvkoilterminal.ru
Date added:2020-10-15 23:18:05 UTC
Last online:2020-10-16 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 23:20:03 UTC to abuse{at}reg[dot]ru)
Takedown time:7 hours, 29 minutes Good (down since 2020-10-16 06:49:46 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-16DAT_20201016_T035.docdoc e92ce2936427af8c9ad098f7545082f5075cb392ae497589ae3335a9efb8d7d0n/aHeodo
2020-10-16LIST_2020_10_16_O0583.docdoc 4af8ba6ab36a82d4a7f86ff80bd98152f6b8c7df507558dd21a833a1820dd328n/aHeodo
2020-10-16File_05858.docdoc 37c21f0f578d3c63515c63f95541e4b9415878dbcdd420e28a57ad221d118f2en/aHeodo
2020-10-16INF.docdoc ad29fba32bbfa20e1769369f3a121ce461433fc55e719db4c522855e858262a1n/aHeodo
2020-10-16Dat 2020_10_16.docdoc bdb0f1cdc421b438781b96c48d7679057728f3e3aa13191ed7e4190808678fben/aHeodo
2020-10-16dat QIH862930.docdoc a47762c209b57d46904972127a1289ee6b304fad012783b113472df47b76d81fn/aHeodo
2020-10-16rep 20201016 8163725.docdoc f9d5124fa2f49422eaacc95990935571a667118bbdebac076de0f178e54e9ce3n/aHeodo
2020-10-16mes-2020_10_16-O093.docdoc 594458a8901ca25ac09d46ae9f0fc9a0ecd336da9af62a1a4f46940b80bad38bVirustotal results 46.77%Heodo
2020-10-16inf-20201016.docdoc ef15c47fd8dcd129ee3580f45ef2062281b18b7410002a2631200043b9d170aen/aHeodo
2020-10-16list 2020_10_16 IFU5839.docdoc aabb9ea2a83771f9921f5d074e4cf99314607d95cb6f4b069f4ffbca8b18a8f8n/aHeodo
2020-10-16list-W4797.docdoc 878bb13d04d93f1209ba23990aef838329f86ff7fbd86d5bc6bd24da81dbf0f7n/aHeodo
2020-10-16FILE 2020_10_16 ZR673542.docdoc eecadd7f746afdb1f94c964c104b0bb340a550b78887329ed6a982be9d4455f2n/aHeodo
2020-10-16Inf_331809.docdoc 476b7bf1aa229f05d66696a3bfbea19b4dd3a2a7e504e5fcecac84fe1819d91dn/aHeodo
2020-10-16list 20201016 HVP472.docdoc 0fc7c5948e396de87107663a180678d0eb591acf3e897fc39502c371fe9e17aaVirustotal results 40.00%Heodo
2020-10-1608810RJL_20201016_F5962.docdoc da9a336d9317f48aed4cba7796f4910ab150a17642f0969e23d548e69d1b63cfVirustotal results 40.00%Heodo
2020-10-1567560N_DGP95532.docdoc 519a143d1332d1db35e19ba538eff942e18c6260c55f4fc634fcceecef9d3dc1Virustotal results 39.34% Heodo
2020-10-15Inf.docdoc 7525f0fcd1c0d8d3e9ed758923b6e0ee0090ecdd93dd35f2a901b1bc3bfd8135Virustotal results 37.70% Heodo