URLhaus Database

You are currently viewing the URLhaus database entry for https://edm.nickunj.com/tweetstatus/docs/5cEotrD9rH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:765558
URL: https://edm.nickunj.com/tweetstatus/docs/5cEotrD9rH/
URL Status:Offline
Host: edm.nickunj.com
Date added:2020-10-29 14:23:04 UTC
Last online:2020-10-29 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 14:24:02 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 11 minutes Good (down since 2020-10-29 16:35:54 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29MES.docdoc f9ced4f3230da05ce91d86336fbf75e2da5b320150500353b62b56d125fd288cn/aHeodo
2020-10-29Inf-20201029-72445.docdoc 5597d783bf7dc649677795638f8bbd5f97676ce49e443df3ee1fd032008f5609n/aHeodo
2020-10-29Attachment TAU1194.docdoc 60c1c55c2284d0a4e2c49df31f704f0876b23a306fd984fd609ef27abcb71cf1Virustotal results 26.56%Heodo
2020-10-29Attachments-20201029-1942.docdoc b1a8a3e928824ed9a2a223c1fe05cbdce4ed84661b4407969b59304cbc193e4cn/aHeodo
2020-10-29Attachments-20201029-NKK693450.docdoc 5ce496f13f2728db5457ef356b0cf73e9a390a8016dfb4df1b3d084ad7f0f991n/a Heodo
2020-10-29DAT 2020_10_29 6600941.docdoc f8151488522088cd446eab9728c3cb5d8b4d83f45d167799795d83eb7f4fbac7Virustotal results 26.56%Heodo