URLhaus Database

You are currently viewing the URLhaus database entry for http://natunkantha.com/wp-content/ffUKhyiX1ar1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:944090
URL: http://natunkantha.com/wp-content/ffUKhyiX1ar1/
URL Status:Offline
Host: natunkantha.com
Date added:2020-12-28 22:15:06 UTC
Last online:2020-12-29 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-28 22:16:10 UTC to ipadmin{at}primary[dot]net,ipadmin{at}us[dot]net)
Takedown time:10 hours, 2 minutes Good (down since 2020-12-29 08:18:51 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-29QJ5VPYU6HF4H.docdoc 2c65b3ad0c28b1f2d1ca15afde94e344d663fa438341bf9a8d8634649026824eVirustotal results 35.48%Heodo
2020-12-29KNGX7OU1U58K17.docdoc e54bd0f6b647b09226b4d2a8436f15a1921877d85a1f7173eb6bfc8d8fd5f93en/aHeodo
2020-12-29VWTBN137CJ9P20TR.docdoc 8464ce9c05a162a1b025bd1d312acb11b02371989481b2c82fac0cff35cd40aeVirustotal results 30.16%Heodo
2020-12-299T5OJRATANGHX1.docdoc 78b41c5f490bb27af82882cce670ccba92a5d25baef2dcd45e7efcc42e76bc56n/aHeodo
2020-12-29D5J1ZGV7T3T94C.docdoc 868e1f279db75c1af75c2aeb9cb452603048550fcc9c16f549e4ce524f30837eVirustotal results 32.26%Heodo
2020-12-294VM7D5210XVE7BUI.docdoc fe829f49465fa85f7a3c46ee46583bb2607645f0fa5bf2b5446ff5508e9b340fVirustotal results 32.79%Heodo
2020-12-29QM6T34AR.docdoc 351ef40fcf2e2f7447eca693ce677f24a13f75a05e9dd8d3f981dc268ac6aefbVirustotal results 32.26%Heodo
2020-12-29L56EBTQTGG8RW4.docdoc fc5042a0a7a79977b649e3a965f21e042eca483a0c23ace92ecb7262085df16dVirustotal results 20.63%Heodo
2020-12-29ZTQC1U.docdoc 6912cfcfbbd57211314ac15f1f60de45708fd6dec388160710b1bada06a292b8Virustotal results 19.05%Heodo
2020-12-29IMIH4LG4CGQ8QTN.docdoc adddf3bf69b22644e48e094fe612082137f1dfd38d2f4d6f07f9824e1e0ad061n/aHeodo
2020-12-29XUAEVCU59.docdoc cebbcd00eca12847a36571a9d527efc2e2c2a2f00e994ab7c6057de2f82c5cadVirustotal results 31.75%Heodo
2020-12-29MXOOSGI06XYJ.docdoc 04bf812417d992c76ac28f24f029de65f9cf227b3d836032afc6472ceeb84e10Virustotal results 30.65%Heodo
2020-12-296TXMIQR5AOE00K.docdoc 7015585930577d63d591c0c67ef9adcead3f1b43a9e39a25ee23e42c7921ab2cVirustotal results 32.26%Heodo
2020-12-29S29MHZ52D3E8RN.docdoc 6a6b38bbe6ab4ad48d5bdd6473f77b3591719ab4aefd21c5158ba603e855b784n/aHeodo
2020-12-29DUA2NU53E91V.docdoc b269900e50a09030b6f6136a521a9699860ccb7c5259ebe74717711299da973eVirustotal results 31.75%Heodo
2020-12-29QS0UYSMXPHB15.docdoc 848e0330cd1da1e2fb741d0be0318a12fa415811131c0a6b7c52e5cf867821c6Virustotal results 25.81%Heodo
2020-12-298YJJ2INA35.docdoc 587699784919c3bea79454f4cb031d3793801c4fed1d07b5767be6371ad8edd2Virustotal results 26.98%Heodo
2020-12-29ISRXRR6P.docdoc 79a074f71a273b9dad370fefe33704deaf5e9b989812929e5d33900324dad3ffVirustotal results 21.31%Heodo
2020-12-29HP203DGL7.docdoc 31635b1f0402afa859abcb541f33761eafab1551aec0b47118b78f3e671b1590Virustotal results 22.58%Heodo
2020-12-29B30NMPNQJQGX.docdoc f8558e66e35c0908e148fc2fee062a31346b00b7ef270ab1f062f17e6350a8cbVirustotal results 22.22%Heodo
2020-12-29U25EVF.docdoc 3f9b8498660385229fa4c9000d3b46ca6a43f6f2d91bbde9391d1e752762134an/aHeodo
2020-12-297V1V6EUPAS.docdoc fcc61c1b3639ee120a6b1e8e9709614682434b8a6017bea91fef29a063f0d3b9Virustotal results 20.97%Heodo
2020-12-29LGJBJSR2BQ0T3.docdoc 4b2c9f87676f3cf3eb61380529d83e39e8ba3f87eaf2d64bde0dc70d75941104Virustotal results 22.22%Heodo
2020-12-29TQRMJYPAMGQKES6Z.docdoc 6648b51c5a828a4b145d0292f72e3333278e3c97b08ce2faa174a6513b4964e7Virustotal results 20.63%Heodo
2020-12-29HEGMNGOZ6410CCIU.docdoc 3e74772e9bdd856ca6c3d6f86e9f7b83f73f245f45316370725d07276660e6b3Virustotal results 20.97%Heodo
2020-12-280KSVN2OK4U.docdoc 20648a91667ad6547f61ad92bf6b7bfcccb4c3ecbafd54fae8cbcabf75cad1e0Virustotal results 22.22%Heodo
2020-12-28S69NFKH0.docdoc 0b30502c830f8cc7c87978637d0e47918353373f4b11cc38c90853f3c1aee639n/aHeodo
2020-12-28Z2P73LFTPGC1OT.docdoc e437f954e87f11e67021195a8e2f952ca08a52d6816f5742b999121cb1634c1dVirustotal results 20.63%Heodo
2020-12-28OSD2RSN9YFNGO.docdoc 6e89e614b08b28c95ee56efc9086c1d5677b78fae8a8e48036f3d467f936f2baVirustotal results 20.63%Heodo
2020-12-28WZQGBTJ9C.docdoc 7b31f0e87b058f66367a842f7de451706cb4bdc9ba42669293fc7fad0d25dba9Virustotal results 20.97%Heodo
2020-12-285TUSC65T58.docdoc ff93fe7d28dd2c2a8a72162aff79196bd63579f20438476d305375a3ec3b70e1n/aHeodo
2020-12-28798IVBZ3NZF.docdoc 34c2de918dd4a97d37efa6fcc06e6c8c635f13ceb3de47e1dbb0b04393b9c298Virustotal results 20.97%Heodo
2020-12-284LYRUKF.docdoc cae404af78e1ccf5ea32dbb545812c3f072d88a53b7489af336ef649539ea4c0Virustotal results 22.22%Heodo