URLhaus Database

You are currently viewing the URLhaus database entry for http://www.calcuttanews.live/test/INC/957316/qx7nvgcb-0024081/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:734807
URL: http://www.calcuttanews.live/test/INC/957316/qx7nvgcb-0024081/
URL Status:Offline
Host: www.calcuttanews.live
Date added:2020-10-22 13:31:05 UTC
Last online:2020-10-27 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 13:32:03 UTC to abuse{at}amazonaws[dot]com)
Takedown time:5 days, 1 hours, 7 minutes Bad (down since 2020-10-27 14:39:27 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22PO# 10232020.docdoc 59235980108e00a0011ebeca9348c5a39ef6d6ec0b052e15ddeb825e9c21e3d5Virustotal results 39.66%Heodo
2020-10-22Payment.docdoc 69af96e96aafc755df2b99ba9d1925a163cac2579277136ed1a6bc9b24d0bfe0n/a Heodo
2020-10-22invoices 7121 & 67104.docdoc 73afab923f309960ba6ef1f00b4d373abce5e6605b10a2b214ca42b7736f1f6bVirustotal results 40.74% Heodo
2020-10-22form.docdoc 980307d89e587b452b4070afed9ad8494e035481816544a310dec6a81a7aa8c2Virustotal results 39.62% Heodo
2020-10-22Form - Oct 23, 2020.docdoc b5cd5400335751a69f615e20dee539318086e0a345b5f6460aa2971f55d1317aVirustotal results 40.00% Heodo
2020-10-22ZR8324695425MJ.docdoc ee5fa6da862f50e1ac9babeca493ba621ca3bc57ab73fb88480bc716457e36f0n/a Heodo
2020-10-22invoices 0133 & 2708.docdoc 40ad317b6909d6800860af835411d7aedd3ff816bd1e02c7aa0553dadb8735b1n/a Heodo
2020-10-22O632 invoicing.docdoc 966cb3c467c7adddec5950e40aff3b25c8341aeb0919de56c54ec4edc738d19fn/a Heodo
2020-10-22Inv_3634.docdoc d18c0e979f37984b270f0c13f5be14520443ccf55b445d68ffaf6c48b89cf5c6n/a Heodo
2020-10-220085622.docdoc 171b68003d3217f50e0238721e0957d775d8eb225067a0191f56f2a31b998629Virustotal results 40.74% Heodo
2020-10-22Payment status.docdoc d078837cdc9042641925b36475f87954994b19f05d89c10b4ab4a1ea28a806efn/a Heodo
2020-10-22Invoice.docdoc 2acac0803d5b5de2f17bb7d2c43af5ad438be8af04faec7bdb33b4cddda2a4d8Virustotal results 35.85% Heodo
2020-10-22N8479829851DX.docdoc 2f11fb391c4e5106c86f7af02261b1ce605f84877b62af40538177fc258c9e05Virustotal results 37.04% Heodo
2020-10-22invoice.docdoc 54e4fc3613affad5354fc1058f7879031c1191f2e8e79b72df4673bae4603695Virustotal results 50.00% Heodo
2020-10-22invoice.docdoc 74e16bd58ef88cfbc4267cf32b54a6444f5a01675811af2f8da025c1dd9e7272n/a Heodo
2020-10-22Inv. 03538165.docdoc 8849667217cbf5aaf17be7bc7eaef3b073f32d6d7d7a6f36a022c270228a0d8bVirustotal results 50.00% Heodo
2020-10-226370270481CA.docdoc 4184aff59a80548872251572d47d8a0f88865d08d8b944efeadb47c07d6f30d8Virustotal results 47.37% Heodo
2020-10-22Invoice #5384275.docdoc 61c90e0b60ab1ac4a891679a1e051a65654201f44b65be90543c41691ebe8204n/a Heodo
2020-10-22V00586 invoicing.docdoc 46035df42146415903e45c8938c23ce819bf83cb2e5328b555ec947a0d1b9bd0Virustotal results 49.06% Heodo
2020-10-22069412608.docdoc f22e043076e2cafc9155e8e740e5ab74406ed9e83d3f875772e3f82b69d8d93cVirustotal results 49.15% Heodo
2020-10-22INV #007119 FOR PO #640363403.docdoc 3cea95fe241c36b02ffc90f1260df43c8fc77e7acde8d5804ba4a461203332d0n/a Heodo
2020-10-22Form.docdoc 7132fddab8ccd72577838968f3e91a36c9ce64950fde88e34635e5e008be8a13Virustotal results 43.33% Heodo
2020-10-22RES-100120 FYWF-102220.docdoc 2bc5c1591569f6e8a480a530bf343df21867da564b7503824cb0e5193d3f8937n/a Heodo