URLhaus Database

You are currently viewing the URLhaus database entry for https://nicetelecom.us/vsr/81CqdFelyiUdYH4cxNWZGPBnWFEhI3yXPjkGDGJhMZzv6Idk8iSNYm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:937972
URL: https://nicetelecom.us/vsr/81CqdFelyiUdYH4cxNWZGPBnWFEhI3yXPjkGDGJhMZzv6Idk8iSNYm/
URL Status:Offline
Host: nicetelecom.us
Date added:2020-12-22 11:18:04 UTC
Last online:2020-12-22 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-22 11:20:13 UTC to abuse{at}contabo[dot]de)
Takedown time:5 hours, 56 minutes Good (down since 2020-12-22 17:16:27 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-220PWXVL9.docdoc 258bf32591a0ac34fc68c8d36075c55b6f45b79eaaf16e3e853ba48e90a3a220Virustotal results 41.27%Heodo
2020-12-22W9NY7VNAG.docdoc a447c84f7560c4f1edf551724e02c90c1b0ad6b1e96e42db4020d2a749940e80n/aHeodo
2020-12-22EG8H1NYH28FWG.docdoc ca93317d1d526ec7ad19a487cfff9df808e5ca37aefd09b481f17cb982adf0ben/aHeodo
2020-12-229H9ODVC.docdoc be0dbaaec3415c76acd2fa6e9c3969d8bf86f058be7e69e357518e173ba4d246n/aHeodo
2020-12-22FRUW66P3.docdoc 02da530f198d747d124f0554938c6718e94f78528286171a3a3298e4eee488a4Virustotal results 36.07%Heodo
2020-12-221IVDVF8SSMW7J.docdoc 72526ea70462d80cfb3edea310592329d47c4081c3ee6df1184a219a17b1a731Virustotal results 33.87%Heodo
2020-12-22CCEGBF.docdoc 30fcb0b638fa78c9ec712cfdde89641c5d6a6ae28c3bd1fa75b29f9b78855721Virustotal results 34.92%Heodo
2020-12-226EKVLFX02.docdoc 110c702523b61a449c85889be0f1f3a8b2c0375bc3de47eb9051189eabd03445n/aHeodo
2020-12-22T4IMMB.docdoc 7ec200a834392208ae8521c4804d11ff669137b4265b732a17660527ccf3cf36Virustotal results 36.51%Heodo
2020-12-22P6HF7EXNQRJH7.docdoc 0ebdff0201647a1df0ad578dcdfff8ca9e91c379b6183c53845de8e226b95c39Virustotal results 36.51%Heodo
2020-12-22AHUIVLVCR6SIW2.docdoc d75b0d66078627d8cf65aad41048ad00049bac791f122b3946f0119aa758273aVirustotal results 36.51%Heodo
2020-12-22P3RYP6Z4TENVA.docdoc bf71d36b2ba7d0198a2bebd6c351f932fba9da682a76a354de6b798db426a9e9n/aHeodo
2020-12-223GZAAQXX9AN.docdoc 7be2388880d2ad20b0cfa616a726d7c91d2904da8f3f8ad4d2236d3c79e935fcVirustotal results 36.51%Heodo