URLhaus Database

You are currently viewing the URLhaus database entry for http://cosmicnewmedia.com/cgi-bin/oKWc77ORJHQeeCYKq9TkDy360slAe2d8SQvD8CQi5gT9vIkHPPqoxHxOh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:758361
URL: http://cosmicnewmedia.com/cgi-bin/oKWc77ORJHQeeCYKq9TkDy360slAe2d8SQvD8CQi5gT9vIkHPPqoxHxOh/
URL Status:Offline
Host: cosmicnewmedia.com
Date added:2020-10-27 22:57:05 UTC
Last online:2020-10-28 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 22:58:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:4 hours, 5 minutes Good (down since 2020-10-28 03:03:37 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28inf_2955961630214620617.docdoc 384f0ac6af41ed895424d29854b510286d7b1c075150dbd313f8682f26eb4249n/aHeodo
2020-10-28REP_MAR32XC8FKGG.docdoc aeb7e85b2cafde9f05807a7b77f48f79c431e3c6cdaaaea539d2fb42a7ed47c4n/aHeodo
2020-10-28MES_WQ4VJO28GIOUR8.docdoc 5e692d0f6341638d540a0dd0458062a4852cdc65dd6551956aaa28c4d417416an/aHeodo
2020-10-28UNTITLED_PSQ_100120_ZRG_102820.docdoc 42437dded751c17d78164701713e5a181726b5fa47472556a1eaede5aac86c17n/aHeodo
2020-10-28List_HM7LZ6G.docdoc b1667802a4201e50d756b921bd73789dabdc6e0ead93ccde248f9634cef63d6aVirustotal results 22.22%Heodo
2020-10-28Dat_6D0YGIXCT.docdoc a30d2b343e3646a2a05e98c5b7f976a1f67e12574ecb880a2a460bec35735f6fn/aHeodo
2020-10-28Attachment_96943535.docdoc 4d2065b87b5e9b6d1f4bc0bb53b3244c9d61eb3fd8c95d64757935758065ff29Virustotal results 22.58%Heodo
2020-10-28Untitled_WTIT78G4UIA5O.docdoc d3c0be044c41601dfa9c299cdd01957fdb3368175976582bc1d83c203391c78dn/aHeodo
2020-10-281A3AOG8BP02HT6A.docdoc 6310463115ebc704a66281738da24d3ddc5e2b7142db330ffc61d25899c74869n/aHeodo
2020-10-27Doc_PO_10282020EX.docdoc 90f1f20d90c0a5c6c32d6eca01833ff1db7b1325a5db427d7c5871fe3d5096f3n/aHeodo
2020-10-27Mes_442615593668094305190158.docdoc bab42b7ee6d4b385f15274f7900f7f2a4d5d68d7f527d20b0bfac926752f9b3an/aHeodo
2020-10-27FILE_KIR_100120_LDB_102820.docdoc 7179df59ef9df561ef65cd5b7036f02fa09b49c0abd229b6a5c4ea270c49d318Virustotal results 19.05%Heodo
2020-10-27Attachment_RRACR4YH.docdoc 30fd05291d39b5fa6a8f5ce2a03818679f4c7bd25f18fe933c78efa7516cd787Virustotal results 20.97%Heodo