URLhaus Database

You are currently viewing the URLhaus database entry for https://sangmesh.in/wp-content/esp/gk7c1wk5-958/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761970
URL: https://sangmesh.in/wp-content/esp/gk7c1wk5-958/
URL Status:Offline
Host: sangmesh.in
Date added:2020-10-28 18:14:06 UTC
Last online:2020-10-28 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 18:16:02 UTC to abuse{at}cloudtechiq[dot]com)
Takedown time:4 hours, 35 minutes Good (down since 2020-10-28 22:51:14 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28Form - Oct 29, 2020.docdoc 767adf40099224255f150c5dab97873a98b3aa9a0516b068d3412b1302ab2352Virustotal results 26.98% Heodo
2020-10-28Electronic form.docdoc 7cc83c598727e703f73b7d3877cbfc0e396707362df568d8c2727eca119600ddVirustotal results 26.98% Heodo
2020-10-28Inv. 005425785266.docdoc 92ae5315a4de0857a9f23fa0d4ef298bf2e87573ec75de5c05c6b82c0ca67155Virustotal results 25.40% Heodo
2020-10-28October invoice.docdoc 47777481ca315073bee9224d1ef95b64203170ca33c9295b1519e18a004ea2a1n/a Heodo
2020-10-28Form - Oct 29, 2020.docdoc 5177894154a2ad0d67c6ea62534a27cdc18b7cfe9c73c8ec6071d72fb8c198a2Virustotal results 22.58% Heodo
2020-10-28FO008 invoicing.docdoc 1ffb519f7ee20c735692e941193543d406a780fa0756200654c9d442c5166fd4Virustotal results 22.58% Heodo
2020-10-28Form.docdoc ceeeec1a0762510ef1333ebf615afbba2090908a722702a3e81a03f0e17f3a9eVirustotal results 21.31% Heodo
2020-10-2800199474.docdoc 0402eac76e97d2bc47ed688412a18594674b7e981d4307bbe0b8491d8ba0268cn/a Heodo
2020-10-28R-100120 OOUJ-102820.docdoc a489db63b3d5de10623868c1348ded5fa888b398c6c9ecd199dc5c1fe55ac9d9Virustotal results 17.46% Heodo
2020-10-28Copy invoice #0219.docdoc 6b556db13a6bc97a4628816c0d73e375e246ba9dcf0767a7ff38910b06976de6Virustotal results 18.03% Heodo
2020-10-28Inv_4909.docdoc 1f83279e11907f0f3b4b2164f90fc56c5043732bb07681b9c8827bc91f3d7181Virustotal results 17.46% Heodo
2020-10-28invoice.docdoc c6d94cabee4abe9dc14f1ccdfcec3f631453b9e19046806554808e77ddda2cf1n/aHeodo
2020-10-28PO# 10282020.docdoc 24fc98fb4608b0e6216b4bf1a61772268c565b9b40cf66c95011f32d64591333Virustotal results 17.74% Heodo