URLhaus Database

You are currently viewing the URLhaus database entry for http://uss.ac.th/g1/Documentation/qh14xi2/16dpl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:731921
URL: http://uss.ac.th/g1/Documentation/qh14xi2/16dpl/
URL Status:Offline
Host: uss.ac.th
Date added:2020-10-22 00:52:05 UTC
Last online:2021-02-08 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 00:54:02 UTC to noc{at}cat[dot]net[dot]th)
Takedown time:3 months, 19 days, 0 hours, 40 minutes Bad (down since 2021-02-08 01:34:11 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-18PO_10242020EX.docdoc 90a578a0c596e7db4a84fce5c9643cdc00cecb5e858796a31eae9f42e343b8a9n/a Heodo
2020-11-03PO_10242020EX.docdoc a692446a897b7bddc435d17683fd714f85d6a577a0a4e29e6ac37cde784b1a8cn/a Heodo
2020-10-22DOC_JAJ_100120_RQC_102320.docdoc 838408d31e494e72b257feeec73407a2f778e6ecc47754ae16af0290515dc9fdVirustotal results 42.00%Heodo
2020-10-22EU8820214040MN.docdoc b8ece70cf490f0972af7d834da13670c73176dc58bd1d22e254548ea64220df4n/aHeodo
2020-10-22H_LW0783060033ZQ.docdoc dc0ef0bf48199eb407cb13b8506149dd5ecb392ee2682edc318b58f5d1dac769Virustotal results 43.33%Heodo
2020-10-22PO_10222020EX.docdoc c5e2ca43cfaf08706098c33d599b0b3290e871331e604cc8ca58dc71794c8183Virustotal results 42.62% Heodo
2020-10-22DOC_0M2618PAXL7A2.docdoc 7726801f846f3a79f073244ea0ffbfbed6ee847b498b4ae15f94a1dc09489fdcVirustotal results 39.62%Heodo
2020-10-22INV_PO_10222020EX.docdoc a911e1f0602779ec57e20420a5e272f9da645b0f4f8eaba49839dbd37c7b4bacVirustotal results 40.98%Heodo
2020-10-223SVAD8CFQEASEBI.docdoc 160feb6c0a83cf0dab3174f74683de6aa53315477d6679712d47415a2364dc2dVirustotal results 39.22%Heodo
2020-10-22QGW_100120_FBX_102220.docdoc c4d6c72ac1f2925c2af592fd65e1bbdfd5327d959321403faf797ec85d658a6fVirustotal results 38.18%Heodo
2020-10-22DOC_PO_10222020EX.docdoc cf87079fcce12a74d668c62692ec9ba58f422f1474443c9f74283afc2c2e671eVirustotal results 40.32%Heodo
2020-10-22DOC_PO_10222020EX.docdoc 80674fb8973e2a7ee31596d9105d1d897a92f7bbcbf6f07b3bf7a9444f71ca9cVirustotal results 38.33% Heodo
2020-10-22INV_IS9868082676NH.docdoc cda2a4d05c53cff76ef32a29480efec51818dc2f26b02999980a33f1051d732bVirustotal results 40.32%Heodo
2020-10-22INV_PO_10222020EX.docdoc 2337d245436dac2318a71b141e75aebfd4c1e83e960db9e0b032909fd991dc44Virustotal results 41.07%Heodo
2020-10-22BAL_KFT_100120_TMC_102220.docdoc 39f9a4e83cf3f6afff9791b1108e352eca518740f2cc4c2ecedf3c42b886a9daVirustotal results 38.33%Heodo
2020-10-22DOC_AWA_100120_HXI_102220.docdoc 40347dde07281a18b20079ad1bac5b0a981444847f0279db249fa34e2f4b8b1en/aHeodo
2020-10-22INV_SHH_100120_LTT_102220.docdoc 577c203950be63bd35f6a6eea0fceb7ba785d7b2b6d8e3c702fd6d3f59adb81an/aHeodo
2020-10-2286FC59Q2.docdoc 9a25e51de2a4b4280f7006a09e91ed7a4d3d2c9cf24fde4023b14e9d0801a52cVirustotal results 53.85%Heodo
2020-10-22INV_WSP_100120_EMG_102220.docdoc 8a2460eefaab1e7c970a1836dfc66aacd55610790f20f1074e9b30d4eeb71890n/aHeodo
2020-10-22FILE_18363245.docdoc 77de1ed43121b520b0f2810212dbe7e10c305388e6555b5310cf07a7f36396b3Virustotal results 47.54%Heodo
2020-10-22FILE_PO_10222020EX.docdoc 220e3645890122715ff1e995b86a7d014cfce7e53b2576e862d9c686c7fcf553Virustotal results 46.77%Heodo
2020-10-22BAL_98709441.docdoc 9bb4de39d9e3b645efd9378896791c1cdee73c0c1501b95fde6b2adb1334c0e6Virustotal results 49.09%Heodo
2020-10-22FILE_KZZ_100120_ICQ_102220.docdoc 7eaf0df9dd2a33ee958384a9472366f58f1c0a204360efea6a7f8b0d298560d0n/aHeodo
2020-10-22K_01070393.docdoc e2d2ebafc33d7c7819f414031215c3669bccdfb255af3cbe0177b2c601b0e0cdVirustotal results 43.55%Heodo
2020-10-22T_DPJ_100120_PQR_102220.docdoc 0f43e36af3a584e03529dc3f2c9c6b9e26edee46742cb8db7112fbe7be0d2c8aVirustotal results 45.90%Heodo
2020-10-22DS2992379207AZ.docdoc 304e83cb00932f8fb77a9a9d8af78c12589b28dbf798b701a03d5606bff50210Virustotal results 43.55%Heodo
2020-10-22VD2824504118IO.docdoc 84f4bb653bce1ba25b6a2fa6fd300f406fa8b0cfa812b07794f3cc657e327a3bn/aHeodo
2020-10-22W_M0TU4BA859GWS2.docdoc f3bdfdeda759d384ba2dfe4792bab80ad4aa7354badad324c69e0f4c095cdef2Virustotal results 45.16%Heodo
2020-10-22IO1807059075ZF.docdoc e342a83dbf0571e76314698c335781b854f2aa0069942dfe0163c3936b71fc63Virustotal results 44.07%Heodo
2020-10-22S_52554693.docdoc 8d3f3a330ef15519bfb2e3f71de5f5893e321a5e1f09e7f0a7459bb2f27559ccVirustotal results 45.00%Heodo
2020-10-22LUE_67548009.docdoc 4b59c4db6b4d14e2dfe7730fe25ed0dc21bb251a5c1b053cdd70e28cfc195867Virustotal results 43.55%Heodo
2020-10-22DOC_13743483.docdoc 0ed13bfe440f265ced87a03e27334e5bb59ad3d45b345e526577b6d168922975n/aHeodo
2020-10-22BAL_5271533309435393050.docdoc ed5ed9c256dc24f5aeffc1b9b0e7dba316c5c13a1966b7243770318805567ec9Virustotal results 45.28%Heodo
2020-10-22DOC_37198631285193244363544.docdoc d810adecb2a17cc42025465a49799119896605f16af88bb79a6342746b7cd8d8n/aHeodo
2020-10-22HUW_JMRL06BN2L.docdoc 1d2531f558d817649eb30142108364e3d3716712a0e17d4bf033d4b3013fc7c5Virustotal results 50.00%Heodo
2020-10-2219219468.docdoc bad9235b37efab34f7e6cf91e6a80803fdcf8903e2c61d0d6c1f5f9d773da112Virustotal results 48.08%Heodo
2020-10-22IHKLHA1YVUV.docdoc fe8d90884de697451ea446a5dfd254041d252229a8a17175f11f77486dcdc4d4n/aHeodo
2020-10-22INV_PO_10222020EX.docdoc f4485fe8056305da48ac8453716ea0fa9c6633da1a1f87e01dae3908da1bbbe6n/aHeodo
2020-10-22FILE_PO_10222020EX.docdoc 74fdfd61d063ce1229044436c55ac1dba3e3c765e8b26674587cbde6704601a1Virustotal results 49.06%Heodo
2020-10-22FILE_OZ9142894031GM.docdoc 24ca326ece108e2ec02346c32536bd5cd2a990364f8d8c9fa35b082ba4a68f2fVirustotal results 46.15%Heodo
2020-10-22FILE_4AAJPS2V3EDP13LP.docdoc bfcf012480833949d47a52c43762fccfd26a1785b134d1da9a84a2f91bca0778n/aHeodo
2020-10-22REP_JKH_100120_YGW_102220.docdoc 00be3474f86c64b8ed871822ccfe02e7bdcbb4b5132682ee36915e8553952648Virustotal results 45.00%Heodo
2020-10-22ELL_100120_GOF_102220.docdoc 26675160f52f90a778a8e6489be6b67a6982742a192595c69b9d87e49e11cbf9n/aHeodo
2020-10-22PO_10222020EX.docdoc 7a9d24e23c3cd1701c2de8826db43aa1dc7d2b73c6c4fd50f491276725a2ad4bVirustotal results 46.77%Heodo
2020-10-22INV_LGE_100120_XBC_102220.docdoc bffe543ff321cb95dc82dc8c8a96c283d019176537290a63c6bc86d7ae98fe57Virustotal results 46.15%Heodo
2020-10-22T_PO_10222020EX.docdoc 9b4d04d1dad15a8a798ceba5f12e03c81a04335dca8703f2e4790675688590aaVirustotal results 44.26%Heodo
2020-10-22PO_10222020EX.docdoc 95c62759d32e2a426433130be7fc1c17a3d3787359258f3af33f61760463eeeeVirustotal results 40.98%Heodo