URLhaus Database

You are currently viewing the URLhaus database entry for https://nhatcuong.xyz/cummins-onan/Overview/uGGlbH6kfK3CI7YsR/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:762956
URL: https://nhatcuong.xyz/cummins-onan/Overview/uGGlbH6kfK3CI7YsR/
URL Status:Offline
Host: nhatcuong.xyz
Date added:2020-10-29 00:09:05 UTC
Last online:2020-10-29 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 00:10:05 UTC to CloudFlare Anti-Abuse API)
Takedown time:7 hours, 27 minutes Good (down since 2020-10-29 07:37:55 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29File_20201029.docdoc d06c24a09106daa1032a15c8cff9c4eb399881b463ccefee9a51744197fed53cn/aHeodo
2020-10-29Mes-2020_10_29-566097.docdoc 6dd8b8f7c8acd972e6fa7b0ebe0452b0f6ccb671e5c4ba12d156e8d376a542d2n/aHeodo
2020-10-29Dat 7767380.docdoc 4f2f8a8fef03110fe0af0be6dda05249f96b6a915b1c7d1a9fcaa7c9f79ce288n/aHeodo
2020-10-29Dat 86891.docdoc 41ad376a9521ae341bd5a60e9084150f0745b92fb26a5b44001e11579d180316n/aHeodo
2020-10-29inf_AM059699.docdoc b9275b6099be967ff38eaab7ab232ce6ec1f903fc98fda4de1f2c057d3f85f70n/aHeodo
2020-10-29Untitled-4333167.docdoc b213e87540cb4152478d07f8211e8c5210925f974e403ec713ce5e5f9f4eadf1n/a Heodo
2020-10-29File_20201029_UUH252.docdoc 192e7f20388641538ab4e7e243d6c81dfd520107bc8854005b2096b31981a624Virustotal results 35.00%Heodo
2020-10-29mes 20201029 G7038.docdoc 772b14f20e166cb1f21d538a8d1dd0c81dc22a2907ca07f299a1c90053c25d5eVirustotal results 34.92%Heodo
2020-10-29ARC 2020_10_29 5097221.docdoc 230145518bd1bee6679f4ebc0546c94c0e1b45c47e78117a0e523ada0cf39ac5Virustotal results 33.87%Heodo
2020-10-29mes_2020_10_29_P236.docdoc 9a82999019fd20e3e31fabe6fd23e85218b9c833d75b08c3ab428710b9de9ff3n/aHeodo
2020-10-29DAT_WT476230.docdoc 01832091bf1c1ecee3623274c0a9d173d305fb1b0f1059cafa86eab41961f498n/aHeodo
2020-10-29Inf 2020_10_29 150159.docdoc 754b3e1caf1ff6a8d35d59b3ba921a8ac224f6118520865d02140c0277724a73Virustotal results 28.81%Heodo
2020-10-29LIST 20201029 N02195.docdoc baa7a5c8cd03cdbad3f018274a9ce821b056f2d7bbb6bdbd6285485e3b56338en/aHeodo
2020-10-29MES 2020_10_29 SQ8267.docdoc 1057624fd741f170fc4a05bb538ab9a3d863abf1ca31d713b1d13cd57a03e8c4Virustotal results 26.98%Heodo
2020-10-29DAT_2020_10_29_928443.docdoc c70d77f7786f19c28c6d7b174832b42fc69d47808b6aa5ee197250ab24b32cbaVirustotal results 25.40%Heodo
2020-10-29MES_20201029_440.docdoc f8b55420ef4b3052e8b71f5a228e16219e3f6372d19e8c3e175e8fac7482824en/aHeodo
2020-10-29ARC_20201029_DS34469.docdoc f49637e7159ed3b8f29519c003193985c2d5de0638a9386d637a2e62a8910160n/aHeodo