URLhaus Database

You are currently viewing the URLhaus database entry for https://securityskills.com.co/wp-content/Scan/4207/CtniK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:721013
URL: https://securityskills.com.co/wp-content/Scan/4207/CtniK/
URL Status:Offline
Host: securityskills.com.co
Date added:2020-10-20 01:52:05 UTC
Last online:2020-11-02 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 01:54:04 UTC to abuse{at}iweb[dot]com)
Takedown time:13 days, 12 hours, 57 minutes Bad (down since 2020-11-02 14:51:39 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20Invoice 856804.docdoc f58cbfc9a8abe26d8ee344b97d04bac6ed709bdc6e3920b6b4cc4f6fe22bdabfVirustotal results 30.51% Heodo
2020-10-20October invoice.docdoc 7e136d3bc68a6578cdb157624c2783f78b48a13944133de3d0f5b0d34ce6ffa2Virustotal results 30.00% Heodo
2020-10-20V102 invoicing.docdoc f64d1d64e95cb52e8ac1e43c619b165f65e0a882fb8d0e8314f2e82271425089Virustotal results 32.79% Heodo
2020-10-200034370193.docdoc 2578a0f788096c10b3bcb14ac8c024f44b035e361ca8e1af809c81fb4cdc6ad6Virustotal results 32.79% Heodo
2020-10-20Copy invoice #35489.docdoc f86eebc5209b2e92bd174a3c00c80a3b021c7ab0ba5c60b46e91b9d92d8f23d6Virustotal results 30.51% Heodo
2020-10-20Electronic form.docdoc 0c826456d4bf7da7aaf36377a19de56cb2712b94c047a86518ff7745d252479cVirustotal results 32.26% Heodo
2020-10-20I-100120 LTWV-102020.docdoc bd285e352fbd21f0dc81df11d362338b6d68c0feade3946cfb351cd09759a9a6Virustotal results 51.61% Heodo
2020-10-20Inv_504330.docdoc fcf66fd33f42c75abf852452c661e3ccc4f85c48a721dbc4471bd28332760145Virustotal results 51.61% Heodo
2020-10-20PO# 10202020.docdoc 8bec43e2d05761c02be362fef3cf9b6f0f4963f122c275c7c7686e3cea6fd5b1Virustotal results 51.61% Heodo
2020-10-20H9187604684TI.docdoc 2f0abbe89ce350352b4029575dffb4895f42d2296aadc1745287763704b7093dVirustotal results 51.67% Heodo
2020-10-20Form.docdoc 00fddc023c2f5c9f500b8592592b4399de427ab2e657776af747214d6e85f282Virustotal results 50.94% Heodo
2020-10-20Payment status.docdoc 62a9b643f7765043465accb55ca13d6a5249f8166f886d84499ca76b247a149eVirustotal results 49.18% Heodo
2020-10-20Inv. 00709268230.docdoc 03ed194d560f6e7b976f45dd5678707c7132079b5d6d1bf0366c7163e939cb1bVirustotal results 49.06% Heodo
2020-10-200972312.docdoc 31c9941b5e674b482e7b5020bce1c27dd86c8529fe254326dcd4a86d137492e1Virustotal results 48.39% Heodo
2020-10-20invoice.docdoc 365d3d49f5595f8f953aea3c3d22743b8319fad46a667472b4c3504b8efb805bVirustotal results 52.83% Heodo
2020-10-20Invoice #09810.docdoc 2e7f73ead896b7eef85db343d77418c1307c087dccf1c575b506835d23cdcf99n/a Heodo
2020-10-20Inv_4911.docdoc 9274f1cccd6ac0af51801682a093404e9f2f3453120e01d07f4e2086d73606eeVirustotal results 50.00% Heodo
2020-10-20invoice #523223.docdoc 9dead7615c9982a5935592ea257a1c754b61ee79c39b61345ce30c18e1756cb2Virustotal results 50.94% Heodo
2020-10-20INV_66785.docdoc 775679d5aaee59d4fca6fbf59e84b48cfc8c975b4b5f57e5638a67885a2012b0Virustotal results 50.00% Heodo
2020-10-20Copy invoice #21801.docdoc 45327af6d3d75a274f4c5d122adc41d42ddff44e520c7c02efb3df87adc64be0Virustotal results 50.82% Heodo
2020-10-20Electronic form.docdoc 19aad5040fee8a81772e4326aa715f5fdfa438971518f212a8a8a8f96bf9ae1fVirustotal results 51.02% Heodo
2020-10-20R08 invoicing.docdoc a7a71a8db9345289a21c62edb7085cbff3e0dfcbaf3b66e6e17506a60af10fd2Virustotal results 45.00% Heodo
2020-10-20PO# 10202020.docdoc 9fe84df0e721c3be3f87b18797064adf7294d5fc84605bdd396e1d7492e85c0aVirustotal results 50.91% Heodo
2020-10-20Invoice 0499933.docdoc 29b284995c7be9561c22f89c9c4d4ed2f4abad490ff34aafd2fb0cc7c0312b90Virustotal results 48.21% Heodo
2020-10-20PO# 10202020.docdoc cfbd735346e1dd406313623ca27397cf3cf30e3197a1914b77a6f10f22f11633Virustotal results 50.00% Heodo
2020-10-20W-100120 SUGB-102020.docdoc b53ae43743c6308bc894bdee9df0745d8c360217f26cf37ceda3a979b519969bVirustotal results 48.39% Heodo
2020-10-20Inv. 039737667139.docdoc 1dbba69603fe6866b9b3762959b8d745e12bd325c1a203a5160e547f7ac4997eVirustotal results 46.77% Heodo
2020-10-20C9525816570QU.docdoc b52f4d01a0ab4d1cc721d51d83479234dda82213536075936f096f0d1203552eVirustotal results 45.16%Heodo