URLhaus Database

You are currently viewing the URLhaus database entry for https://rajathm.com/skysurge/nNx2tZRI1GsT6S5BuJbjZmB2a7QvSSJi4jFwRqG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:752700
URL: https://rajathm.com/skysurge/nNx2tZRI1GsT6S5BuJbjZmB2a7QvSSJi4jFwRqG/
URL Status:Offline
Host: rajathm.com
Date added:2020-10-26 17:47:06 UTC
Last online:2020-10-26 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 17:48:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 31 minutes Good (down since 2020-10-26 20:19:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26INV_KUL_100120_EBS_102620.docdoc 76afe2552588f38f318120b1778e8d66eff5ccef7e49ea2fa3c650aa573149aen/aHeodo
2020-10-26BAL_UW4597043997GZ.docdoc fef9e77f6d9e84345a020f567b892fb4718af268465b5a6d505a6f2bbfa19e92Virustotal results 39.34%Heodo
2020-10-26FILE_8997836068412160577.docdoc 5015b3d571a67fc015e9ae62b064f6a8357b86db998aa2fc1eafe6bfd053ee44Virustotal results 39.66%Heodo
2020-10-26INV_LV8448274193YA.docdoc 9c6f43dcc3bd1778ac7082fcd98251f2ebbc67b02f5d6e41ab97c2e8924a4e17Virustotal results 38.89%Heodo
2020-10-26REP_97YX3TV67L.docdoc 9a5ff2d10eb6a49a82083f2f52e3daba519399794197d526ab76a68dd6849e69n/aHeodo
2020-10-26BAL_437634084591944.docdoc fad47e8ab42aab56d8198f885e7943c5b9f9c86bd8983e3ddd4dcaaae8c36f2cVirustotal results 42.86%Heodo
2020-10-26ME4385641742TE.docdoc 7569ec933b0114593361c66c86f8317cdb131aece55945e0634987155a0d0ddeVirustotal results 37.10%Heodo
2020-10-26BAL_ON7435688629GD.docdoc 38aab154593e33db94fe1e004077686960619c545a743f38800582ddd036f413n/a Heodo