URLhaus Database

You are currently viewing the URLhaus database entry for http://nb-sangbad.com/eSzjRTDXxKKDUPGE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761042
URL: http://nb-sangbad.com/eSzjRTDXxKKDUPGE/
URL Status:Offline
Host: nb-sangbad.com
Date added:2020-10-28 13:34:15 UTC
Last online:2020-11-03 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 13:36:02 UTC to abuse{at}alpha[dot]net[dot]bd)
Takedown time:5 days, 20 hours, 35 minutes Bad (down since 2020-11-03 10:12:00 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28Untitled_PO_10282020EX.docdoc cbdad95e70675a32092409e3e9fc5e8afc9a1844bfda99ad00943433da36e4fdVirustotal results 26.32%Heodo
2020-10-28File_PO_10282020EX.docdoc 88ecbebf3f50eca1713851898cb315638b520a2c46f5d21f370de5ac8a4de484Virustotal results 22.22%Heodo
2020-10-28Attachments_IOB7G0LU0C9H3.docdoc 81c78e098a3815757ed038c5f386d54156fe5ea85eeea2bc5baceff398d35a3aVirustotal results 19.05%Heodo
2020-10-28N_I9UZO8KNQ.docdoc aa4fa922d7e80e83494ebc5639c0549754860e3de9ffd6b8f4f455a8ef6f8a2fVirustotal results 19.35%Heodo
2020-10-28FILE_PO_10282020EX.docdoc c0a2014dfca67b622a9a96e4d169601563264a29bb55b9e9b8f1934d610183bcVirustotal results 17.74% Heodo
2020-10-28Rep_FX9036126191UH.docdoc 548e2dd3c73fb009710071b48a2afd21140eb1328ad31397857707060efc61a3Virustotal results 17.46%Heodo
2020-10-28DAT_PO_10282020EX.docdoc 72bb45f25da9afa46d5e326089675c0a79d3ffe30eade356cd8114e74b2e58e9Virustotal results 17.46%Heodo
2020-10-28Arc_KH2155837535VO.docdoc 78e751cac2d36740d34f5137f239e1966d34a62e63cb14bf6d6fb1ad7fe5deecVirustotal results 17.74%Heodo
2020-10-2871396345.docdoc 7d38c4d98d05cd3a7a0fc6898c9d86ef1c29cd8dcfa3403d0222ff508843a325Virustotal results 15.00%Heodo
2020-10-28List_58076923.docdoc 8abc1a41fddc4a3a107138900b0401334fddf0298fa9fe0ec4e7e1f4fede979aVirustotal results 17.46%Heodo
2020-10-28DAT_ZC9023266124IJ.docdoc a3f1465cf2e8a92e8d9f932ab8d561cd6a02e5f832b42bfa856a5cac7fb96566Virustotal results 16.67%Heodo
2020-10-28ARC_YS0072735053BW.docdoc 670d89e5fcdc28a3e39901eaa4e232b7ad534728dea0607e198d767393e23de8Virustotal results 17.46%Heodo
2020-10-28mes_IVEVEGV3CKB.docdoc c3f9c25daaea07684a67a58d2ec8115321b592a8b0edc6eaafd2e8844f22c10bVirustotal results 16.39%Heodo
2020-10-28rep_SU1479140248EE.docdoc 7eeb30a34016ac7c6d48178f44b12c48df17acb131f0a96847d1cd67c464ce30Virustotal results 25.81%Heodo
2020-10-28LIST_9RECBLYQD5Y.docdoc 7123fe5464dfce65a1bbac28244f6a100c49c281f037ad8d6830275d85bddf44Virustotal results 18.03%Heodo
2020-10-28doc_WY2DJP5BA.docdoc c7a9fcbd5e7cf2f7c00c2ce737e5f37d79fca2af4840700fbec2812fe888df80n/aHeodo
2020-10-28A_2CYENRPDNFC4.docdoc 19c244f40868914450fb2bccb57e67ab4fb5679b222017b8c0dfd53dc1980334Virustotal results 17.46%Heodo