URLhaus Database

You are currently viewing the URLhaus database entry for http://www.patna.savenzer.in/js/ThF4TUupM0X2NNT5YvIjkrBmcQR2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:756921
URL: http://www.patna.savenzer.in/js/ThF4TUupM0X2NNT5YvIjkrBmcQR2/
URL Status:Offline
Host: www.patna.savenzer.in
Date added:2020-10-27 15:36:05 UTC
Last online:2020-11-01 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 15:38:03 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:5 days, 2 hours, 15 minutes Bad (down since 2020-11-01 17:54:00 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29mes_61K7LS12.docdoc d285ea691c4ccf35668c9aeb1166e56bea695d95174c38282af932e47157a46dn/aHeodo
2020-10-29rep_X9HVXWEK5.docdoc 02ded378bb9171cb19579495299062441281f67002a8f88beaee43c2dbdd94b4Virustotal results 24.19%Heodo
2020-10-2997634801.docdoc d7edab7749baa696b995be184437050a249c40992deb7cbd3472cf93fd8a154fVirustotal results 20.97%Heodo
2020-10-29UNTITLED_51048320.docdoc 3dda8251733c1b96b75d29bcbe3466add36d495368b4b44232fae1dba4a4cec6Virustotal results 20.63%Heodo
2020-10-29Doc_PO_10292020EX.docdoc 8b4afb8076a68f93b44032c82700252f8971b853903b31fd0eaf50671f7c3cd7Virustotal results 20.31%Heodo
2020-10-29file_24365885.docdoc 4cb60e699616e7b7d56209bab753b251a0f0190eacaf40dc8ee0efe6503a3512Virustotal results 20.97%Heodo
2020-10-29Untitled_29988155.docdoc b0144d3b84fcb16e6d521e31100944499659d0ed9065e7295eb557d60254be7bVirustotal results 20.31%Heodo
2020-10-29FILE_PX4X1WMC.docdoc 2427ee3cc0798fcee02c718a1fb58d735d9cf3b0ebd9bb10c14cb9326bb5e489Virustotal results 20.31%Heodo
2020-10-29HDST_PO_10292020EX.docdoc a943a1b78c2ddb8ea536ad08b2eaaec624c324079322f272f1e1a319b5603a28Virustotal results 20.63%Heodo
2020-10-29G_13520936615732204.docdoc 1ecf50c67d4c4bf7eba5ed050c6500f7ab6a2b63b66f12dd23748e22e9a34ce7Virustotal results 40.98%Heodo
2020-10-29Attachments_92458629.docdoc 332d48b31116922bc05e18e6322ac17328b888d5e0b92ad3ddd4d665111b7ce8Virustotal results 41.94%Heodo
2020-10-29INF_77924405494158.docdoc 6cff316da0b26621e5b1fc3d5a85c6931a68a90fde20acf702195a175fb4ce44Virustotal results 41.27%Heodo
2020-10-29List_MSYBKDB6JGUPRBMO.docdoc c914f79bcecd36e66a0afaafa94fea889077dc0eeba31cb470833af137c79564Virustotal results 41.94%Heodo
2020-10-29dat_9925789632.docdoc c353f3d728d9ff052a3ee47d7dd1c5e8bcd8813238a8e20f2f2d0a97fe5bd8e0Virustotal results 38.33%Heodo
2020-10-29Mes_232852387368.docdoc ddff5ab1d127fa30a0f2353857d3ac72c8b28191737e15516420dc25abaa6784Virustotal results 37.70%Heodo
2020-10-29MES_PO_10292020EX.docdoc ab7a59b346e75d68ff9a689f85a0d2a96833a3048478fab68af1e8f1bd4d5905Virustotal results 36.51%Heodo
2020-10-28File_14315021.docdoc ad10b386d964b6056e529c2bdb70ccb19ba21b3b0a59ac606113fedc49626b81Virustotal results 23.81%Heodo
2020-10-28DOC_HW5799034804HJ.docdoc f60c05abd97590b8b38e8fdebfbd9f6dc73dfef0a767d075be889c4646ad19d4Virustotal results 16.39%Heodo
2020-10-28File_PO_10282020EX.docdoc 9727e61b54cb94d7ee0efb897b46e6090d7840219900592a82751723ad457649Virustotal results 25.81%Heodo
2020-10-28TDFY0RMFSE3.docdoc 7123fe5464dfce65a1bbac28244f6a100c49c281f037ad8d6830275d85bddf44Virustotal results 18.03%Heodo
2020-10-28list_EHS_100120_NWD_102820.docdoc 19c244f40868914450fb2bccb57e67ab4fb5679b222017b8c0dfd53dc1980334Virustotal results 17.46%Heodo
2020-10-28MES_680991170.docdoc 4760301c9f69ac873695b32575bfb814706e3f43c55aec6c05de900156550254n/aHeodo
2020-10-28Attachments_FB5618220983PA.docdoc 778c2b97449426c3f3827a8041a05fcbb0e648267612cde21370c9f152bcf255Virustotal results 16.39%Heodo
2020-10-28Mes_XG1725418471KO.docdoc 0baa66a446892d388453495c26ee71f8be5dadb844ad77c000f2c4de90976b7cn/aHeodo
2020-10-28FILE_PO_10282020EX.docdoc 852d88f248a132193134baba17eb75649f9aab9cb04fc39652d337149c5dfd87n/aHeodo
2020-10-28Attachments_50ZILGT8ITD.docdoc cb10354a6aff051fe7ae1c2cfb38b40e5ed1c8fd1a4c4b1a35724efed4885995Virustotal results 17.46%Heodo
2020-10-28List_181675796054403924.docdoc 328e64552392319bae85832b13d929359ac21842a9df53528cd720f0f06eea2eVirustotal results 28.57%Heodo
2020-10-28Attachment_KLSQZKDQL06G0.docdoc 237787a670daf0b6ee3f6e85c75ca3501a3d0ed0c6761afb36b467a32d31c2fcVirustotal results 32.69%Heodo
2020-10-28LIST_QR8934522094GH.docdoc b2fd50c9b74180bf57162267feec075ce16b9d37ead25cca5f97840e44e61a1en/aHeodo
2020-10-28Dat_HXX_100120_XDW_102820.docdoc b749fa9443216bb372f3a786fe6f921aaf83800f69c46eec065ad8b2bfb0ad89n/aHeodo
2020-10-28List_D6ATUXG.docdoc 5acee595ee1bc75adea710f92e969aa5c62d0a2693b6dc8c678b2bff8a4a7e51n/aHeodo
2020-10-28Dat_380811293867455999707519.docdoc 0fdb302c3db79d7ed89244d7adf4c56d5cc9e4643c3e5bac39c3e82cff3834e7n/aHeodo
2020-10-28UNTITLED_38008470.docdoc b544ff42f8c38e91027ec7df20b912d3c55dfe9235c6f4a609f7c8b57798b979n/aHeodo
2020-10-28inf_NK3577784094PO.docdoc 520ca27ad3a13618d306b397f83a91daf238997358520459895991c6285328e5Virustotal results 29.03%Heodo
2020-10-28PO_10282020EX.docdoc 06472f9f7853e0506b85ea1db0bb693aacedee79ad413c1ca0839a322f834df8Virustotal results 31.48%Heodo
2020-10-28Mes_HWC_100120_XVX_102820.docdoc 969f5e0df23f888aebe6c8cd981961e3bb23f514d3d55148d8c56d0309a7532dn/aHeodo
2020-10-28FILE_UD5659502449EN.docdoc 21f741f58102f6494c54d7fc6830b266d1ab2f8afc85546d8e2a2d7b6d51c767Virustotal results 31.48%Heodo
2020-10-28rep_4543128282661568871219.docdoc 089982175b8c27323227a0cbe60942992e1cd89852436e481f6947e75cb25d67n/aHeodo
2020-10-28Untitled_WUG_100120_ZHW_102820.docdoc 34eea5e4f2e92b636f9fcade14a7aec223d0ef960f9c0f6c749b2b806096aeb5n/aHeodo
2020-10-28UNTITLED_IDX_100120_RTD_102820.docdoc 5dae469fdf99625a0b53d223a55b04fc4e77d3e660e1ab904e79071d5dc13c9bn/aHeodo
2020-10-28DAT_PO_10282020EX.docdoc 2a87dc4a8eb48efe3380d6d3fa99507c81bb9356c90ea39b1156d82f32396c18n/aHeodo
2020-10-28D_SD0282396175KH.docdoc fe13971c49c4731ae4fdc32c49bbb6796383a27db3ca2340642ed9d0c1753880Virustotal results 31.48%Heodo
2020-10-27inf_16141534.docdoc 47a36aa6f44f68488681fb4c7eef56b83e5003f35562442d29e744354581e8f0Virustotal results 23.33%Heodo
2020-10-27Doc_NCALDCE05MNQD0.docdoc bfc255c1fae47d22c3a502329ae24b49b0fc4169c49c13a4b1091cb686e3ccedn/aHeodo
2020-10-27VHW8A9KB4NV.docdoc d63d4a763ad9df9bb9fa87fece48df3f857bcd1e1aa9a3f37a472c4b7394c500n/aHeodo
2020-10-27Doc_PK3681847484TM.docdoc cf37bc70aa99bf4d8ac44a3ded10f1d82deac713ad88ca9aa9f6f550ccf52f2cn/aHeodo
2020-10-27DOC_PO_10282020EX.docdoc 45130c5318fcc42b669d0caaf4357938d1f8ec66f9d5f96b8790e6f08f05e13dn/aHeodo
2020-10-27Attachments_PU9089781204QK.docdoc 444561d4fffc7ef6089bcd8ff849a9688f26c828917dc6f29ebc13ef1a813568n/aHeodo
2020-10-27Mes_PO_10282020EX.docdoc b01b01566c73b1c2ecfd4f04bda6c7cc3c1c12646562ae1f615733fb1cc89b37n/aHeodo
2020-10-27arc_5538147875.docdoc f0cfa5e0da830c64b718ca4ef0e2a826727e13e6f59321d4bd07c41f1ce888d7n/aHeodo
2020-10-27A7MU1QXGCTK.docdoc ef29a8422b09e506af3affcef90be9236f769d51ce6a686df8fb8dfc6fcd1284n/aHeodo
2020-10-27arc_92202711.docdoc 02c01cbb6b7a75728869e7f91ecb921e05225fa91093cf83377f87b12fc36bc3n/aHeodo
2020-10-27Untitled_OPG_100120_MEV_102720.docdoc a39da0d5b56f1c56b4cdd6c0cf65d313381721f0a2b832d46e35311c0d583babn/aHeodo
2020-10-27Arc_NG0423827679LD.docdoc cb505678e0c2debe5c5b4647af5940e08ffbb2d7a1c73de09136d64560cc0696n/aHeodo
2020-10-27Untitled_64904144.docdoc ac38635cf95cd57e39ddffbf34b5723f519de18d171802bfef7ad76a439a59d6Virustotal results 44.44% Heodo
2020-10-27Attachment_RS9720137330OA.docdoc 1ad28606bff91478a2383c7deb56c563f2c3912df1f1ae81b0fd16892f3842d4Virustotal results 46.67%Heodo
2020-10-27MES_76278041.docdoc 69c66278b808dbebfd0dbcd3869f502a33b285251e49e1fa7f9fb6fc7deff266Virustotal results 44.44%Heodo
2020-10-27doc_PO_10272020EX.docdoc cf1755db847790e09d27102e42e4de72525a7430fb714314809577906196589dn/aHeodo
2020-10-27list_LWE0SN05ABWNU.docdoc 3a6999a4a9e86c13cc7384d88715d7e2ba2f571b311c29c076b654a9d15aeb1fVirustotal results 46.55%Heodo
2020-10-27rep_KS16DOY.docdoc f3d927fe91283ea8a18625acafb7908f40e11ffe5243f2ebb7a5511f99a0ed87Virustotal results 45.16% Heodo
2020-10-27doc_V113ZIF5HU5JW.docdoc 75642eb51b57507a5a4777048331da127ab8e0eac81c31e69d50e3372ce28dd9n/aHeodo
2020-10-27dat_BCMMKL8SBD3PMES.docdoc 82e13c6c6c28efe1784b06b488b4ef8303c4c9ada6e9f8815a30bea58b19629en/aHeodo
2020-10-27rep_55259119.docdoc 16b99f7444f5e97d0fce8d7730fb1437f62f71827293d7d94965735f45ad9334n/aHeodo
2020-10-27Untitled_TPH_100120_SYZ_102720.docdoc 46a3e3abecccb7dab19ff4c6940f0d2b503d409524a59b07bea431da55dac765n/aHeodo
2020-10-27Rep_PO_10272020EX.docdoc 22ac8237bc5e3f90f62a2b7fc69ed3ecc6bf52f767e8b8a52ebdee9e4e09d8a6n/aHeodo
2020-10-27FILE_LPPUB5RJ1UQJ.docdoc bbc60f6a3e441d49e8c3797ddfab56b309bf6e162bcdf8400e73e7651d117c54n/aHeodo
2020-10-27DAT_94829853.docdoc e7209fda6a92ab1c1d55690ebcbfa32f2f0dd773e2912bcd0259bb91509a2e94n/aHeodo