URLhaus Database

You are currently viewing the URLhaus database entry for http://www.khuvsgulsant.mn/ezio-death-fyuzn/Q8Wfc1YVyvNYzb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:945036
URL: http://www.khuvsgulsant.mn/ezio-death-fyuzn/Q8Wfc1YVyvNYzb/
URL Status:Offline
Host: www.khuvsgulsant.mn
Date added:2020-12-29 22:18:06 UTC
Last online:2021-01-03 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-29 22:20:18 UTC to abuse{at}publicdomainregistry[dot]com)
Takedown time:4 days, 19 hours, 27 minutes Bad (down since 2021-01-03 17:47:58 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-31JMRQDNZY0CSKTKZY.docdoc 43af38ecd27585f00463abfee0ca7f492fb36fa862c8d215447d59be27652589Virustotal results 60.32%Heodo
2020-12-30BRO76W4JUQ.docdoc 22c9b454977f772e641fd2d5d4c08fb9e124cdc9ec47c69ed037fed87bbf1abbVirustotal results 42.86%Heodo
2020-12-30N6E6JSGLY7ENZ.docdoc 7dbe3e3f4d5e95b69111858fc5e96f73c1b7f8284276a1280486ab64139324a2Virustotal results 40.98%Heodo
2020-12-30RWHGO5IOTRX.docdoc 6aac95dd3f2a6b9cdc5ddfbda6e548ab8d93a61f48640d3a0a98a312fad42e56n/aHeodo
2020-12-30GQGDUZC5870R9H.docdoc 3d426817cb9506ac02f7d7ae3cebe38e2125efde6eb7ee4af0251a6afdfa2d26Virustotal results 42.86%Heodo
2020-12-30XKPCRW.docdoc 14eef594729b6784626929323d1f4a040cf76e3774ad5b77a16c28449db182cfVirustotal results 43.55%Heodo
2020-12-30YGJGXBG2Q5P.docdoc d6704fdc1942538d16ddedbe3eff3c429e462d4378b33040597c5a218c0e852fVirustotal results 42.86%Heodo
2020-12-30KTRXXUNNZ4TDS1.docdoc 3bf59384c4c1a24eb5fef4453dd1fc63a75324f4aa6b86a62ba47de3393027a9Virustotal results 41.27%Heodo
2020-12-30GC5FIJO6KY.docdoc 9d7889fe83c60f08711f29825a62cc029f17329e4008a7298e7c3ba5cb6ae8ffVirustotal results 41.67%Heodo
2020-12-30EB4TZ8EK03.docdoc c3995c2fa8060e207a999e9ba7fac45ac419f717a024eb0bc1059e197a595595Virustotal results 39.34%Heodo
2020-12-30AF9CD6AFRWY5B8UL.docdoc 399701ae00f1f4e019e97b788362403c8323b417cd0f72fef7f9a39dd4ad4436Virustotal results 38.10%Heodo
2020-12-3060CLN2X6L8C.docdoc d2178edbfb636aa2baf306d59be6a8c651aa2167f67893e6ee70469cc13de307Virustotal results 34.92%Heodo
2020-12-300WFIBW.docdoc 24b9b439815155d6b338c75f2ae2d92deb41c580a893dac9153f5042abc8b702Virustotal results 31.75%Heodo
2020-12-30QVTZ482.docdoc b19c3ed6b6012da42e3a700410a21231588c6b1da97f92911a540b9e3ae71b08Virustotal results 31.75%Heodo
2020-12-30HYBNKNFWPYYYHTY.docdoc 643eeead31f1c79f2a2d191699189bd671ca0169fff0feeb3824ff0b57281e3bVirustotal results 31.75%Heodo
2020-12-30E3AT9TAQ.docdoc e561d015ba417615f931d69404149b840e6f30d937c6d1e8765462d08c33384eVirustotal results 30.65%Heodo
2020-12-30F2S7AK79.docdoc a3c7030635319611442140f4e775bd30cb0379b86a430e9b54df0ce366d7db30Virustotal results 29.03%Heodo
2020-12-30LB0L1SCAPU.docdoc cecc306de3cae60a1f3d988356054754d0d3dcf8666045f718d5cfbf53e6a730Virustotal results 28.57% Heodo
2020-12-30H0NUP41L.docdoc e1068c52aa236bb0111f08ab3140850d7fbe24bf3e5f32697f64701390f5d516Virustotal results 29.03%Heodo
2020-12-30FII00RZ5OR5.docdoc 2247e8d912eac0fe04e0d232db8ed716ddb81a5a2f24f343b03041e267bf3d7fVirustotal results 35.48%Heodo
2020-12-30BPZCZ3Z7CVC.docdoc 74aa8c23f8dd77cacfebbdb1173e5dc164f1f441bbfc2a3045a3936ff133e007n/aHeodo
2020-12-30G6C8QMZPHFY.docdoc 5f6b7c56f5a98721b71d91dcd9a177298006b37c11ca8dc6b0bacae198e17feeVirustotal results 31.75%Heodo
2020-12-309EES55GI6B1389K0.docdoc 86021463cd37d17a19790c9163e7a8dd719a64dde5aaa93b0ff7833ee3b269e6Virustotal results 31.75%Heodo
2020-12-30GQAJJGFX.docdoc 2a21ff7a18b4f0acbed3e8bb4f2b3bd74388c458e0953be7c9a21c9986dd72d4Virustotal results 31.15%Heodo
2020-12-30NM98OF9QL9BO.docdoc bc7f4cd13c74dc42e2862078e4c814def5484f8cba7f2b61834770e2f0f0684cVirustotal results 30.00%Heodo
2020-12-30VT3RSATJOIGG8C2.docdoc d34dfac031661724abb4626c78172927bd98aec10118ac0117285d1ee6be8cc8Virustotal results 28.57%Heodo
2020-12-309ISC5BZD9YCP.docdoc 7a12dc16a3d69c13a76f68eede554c67e41f35dfd4a1eabe274751a1a8752d4bVirustotal results 28.57%Heodo
2020-12-307R1E2X.docdoc 0d90ca158eabbf8ebd00e4093c2ccbd118833f31c3c6902dc7cc079b6ad27560Virustotal results 28.57%Heodo
2020-12-307K6PA7R8WG.docdoc 4c0bd56c72fbb8e4fc45f671c03970329a3070b215f7727f83040d529e44f5e3n/aHeodo
2020-12-30429DUOH5457AQ.docdoc ff851095aca5969d1f70e5be1a645bf840e10b191b9037c50da8be304f5c01baVirustotal results 29.31%Heodo
2020-12-30I4XOW1.docdoc 038ce32c78cddd37592b182971d0c98b8c1d4dc9b398b593a5d28aba6e947b2aVirustotal results 29.03%Heodo
2020-12-30F8Z5381.docdoc 62e5f85a3afbef81f4dd4d8281a0fe697d0dfdb6e714ade5175a0f2b68d40083Virustotal results 29.31%Heodo
2020-12-3051N1XN66LLOH.docdoc 7fef2f36b64703910def4f6a15cfe314b2ac2f9691465ecd3999a29daf6b25c7n/aHeodo
2020-12-3052LHXGQAGHX.docdoc b8b8a0b9feb659e1a9f61285a8f8e98642fa46eda26a61a780df9fb698c63131Virustotal results 28.57%Heodo
2020-12-30VRXWD5H8YNZ9S.docdoc a90b5fb7fe68a65962a5023189a8c8184bbaaa72f39ee8a1e071183398cfde46Virustotal results 28.57%Heodo
2020-12-30HLLWS73PIPEW.docdoc 4239d149bdc65c62946a2bffabc81bcc602baf67a1d402b898c4c036073d627bVirustotal results 28.57%Heodo
2020-12-3009YM87XJF.docdoc ad471901c1ed7f1674111218352a68322ba2b1d0a4c7c0f5757dc0bdc2e4bc56n/aHeodo
2020-12-30RACZQ4.docdoc 40862d0b1aafeb508f97893ee74e2b324ec7e1eb96bc924b3248b9174e43c1afVirustotal results 28.57%Heodo
2020-12-30U50DA61POF6M4N.docdoc 76283689c929908f5d50f086c098143c982d804cceec6b10d530d67f181704ebVirustotal results 28.57%Heodo
2020-12-305ONFG9NH7.docdoc 39e24a73656d38c94f1c4abc67b93be532659af2fa07966c372424780e54cb24Virustotal results 27.42%Heodo
2020-12-308BLOBUVT9XMN.docdoc c8b49c2292e087f722d2422f84d52d6850ce69b6cf230ee27f2b2e82d4df7cddVirustotal results 29.51%Heodo
2020-12-30QYT0I7IB516SWU.docdoc fc5f218a335827dae3d47a83de79fbe3bf8e3da9308f22edf5d9a17c8d1ee1ffn/aHeodo
2020-12-30RB7ZGZS2UWG7E2.docdoc 3c2ed9471901c2a6ecb559a6af4a9ae579b9e6e93ffd08595f002d8b0ea1afd9Virustotal results 28.57%Heodo
2020-12-300EHEL8.docdoc 3c5a0e1906eb2a02dc597a235c6ba9b3faccc526ef1aa3b2f34f462257ff7261Virustotal results 27.87%Heodo
2020-12-30V736HLHZ7QFUN.docdoc dcb7872fbcfd5c4d82665480c0e8995b991d25272fbd21eaf39d7b376421fb95n/aHeodo
2020-12-30THG0OD096.docdoc 4f7771f7916dab6379a8d67278d7b2e73ea25fa1352afbf2e9bba877cfd31846Virustotal results 28.57%Heodo
2020-12-303H5C03DPRBZ3Y8.docdoc de4a09254125ce840b5896e5d3916478c404f565764aed34eb1506ea0cb87402n/aHeodo
2020-12-30R96Q9F3.docdoc 5866f3b91372a6d516f905a7d68435727224cd7b9e42fefa0ea4c7e052aee237Virustotal results 26.98%Heodo
2020-12-30QJWX8T.docdoc 61b5de9bb6347eccd43cffef6ac55d594b32e785232e21ef49eac3c70f3cd582Virustotal results 26.98%Heodo
2020-12-30BG8C63IGDJH07V.docdoc 9c22bfd1ad2f398e3014c41d31582d8e2c886c6fd376836b72aa02dbb6c5ef71Virustotal results 26.98%Heodo
2020-12-309QR0XOBJ5ER8IK5R.docdoc 130e863a38580cb4113b3a1ac7820638134d6a548115152e3e1bd910d88240e6n/aHeodo
2020-12-3008K8Q5SIXU3LL3.docdoc 5ff309e15ed409297bf10da249a2d68038b70b8032f305f43310e8930cc7d606n/aHeodo
2020-12-3004S714320PC20L.docdoc 3923d298d53a6550b2db2d758b6b9bf6c077ce7cf964195aeb1dbcd7f1a717dbn/aHeodo
2020-12-305E6W8EVZWYQR.docdoc e9a7000b6216e1cdd6280e0d3b11b52bfa0cfc1a49f3eb8488ebb26b6f0852c5Virustotal results 23.81%Heodo
2020-12-30E5WKZCPQFEW4YEV4.docdoc 19dee3df18f9767d4dd14ee1c3ed05a893f7ba7592926caea0284cafeb4326efn/aHeodo
2020-12-30M4UHJDQNZ.docdoc 6ea37605aea5591d5271248f640a3dbeb9edec2ae1fcef4954213d025a812d4en/aHeodo
2020-12-30LE1C06IPV83.docdoc 2070255299f9038c17285167aa260f27b016a672a64452ec46bc5c371f1cd71fn/aHeodo
2020-12-300E6ZFAZ.docdoc cbf2fe0231f079d952671879c0b8c938067f5c5dea8bbd0e17508a3855416c64Virustotal results 21.31%Heodo
2020-12-30SEKC42SVE.docdoc c67e6b627484a2883191b35e4db1994df75620dffa6ce55f960a11a2280be3e0Virustotal results 24.59%Heodo
2020-12-30DR2T6OFQK9S.docdoc f075b561422f41b4412421cd0aa5bbcb988f960c4c632de46179b64e8467601cn/aHeodo
2020-12-3004VABK7ED99HY.docdoc 34d114c948d93bbce1a1b9ecc92c641ef3c8ca4ec755ce893e55f8b89f7c4c54n/aHeodo
2020-12-3095VS3795QMJ2JG1.docdoc 98434e35b67922ba13789c603c7e90797ae599f7458b281dae2823eb14389296n/aHeodo
2020-12-30QM3NK7KKVPRBTCL.docdoc 2ed291cc9976df382951483bb2c77fe908b724d01b6360d1e61ee698f052ab11n/aHeodo
2020-12-30OIVTA6N9I.docdoc 4b7778c74f084c7cbe57205e56c590730227816f7212231df1ac32dc21e18c71n/aHeodo
2020-12-30TQG46G6F7B.docdoc 8ccaf45b8c50a7ae2a58de3d8634a80db84f06872e358c3a80f9900662f27f86n/aHeodo
2020-12-30E3GV7YOW.docdoc 4a5d601a84c5c5244615e1f860e6d52fed614858dfbd0215b97b32414ca56f43n/aHeodo
2020-12-30NITH2HCLXQ.docdoc e0a65e088a3f0987db1372c2d63e8cccd384d3a4e98402c919d7a49557d49e21n/aHeodo
2020-12-30UI5O74YT4LS7GLAK.docdoc 475aad7f21e14f905a091f4289932e4a8f2c9c518c3ded3fd3709632e8e75c91n/aHeodo
2020-12-30B86SLTO4.docdoc b5f5bab1debd9fd60535f3a992c4f90f462f3c42896c05138b18e67c36d111edn/aHeodo
2020-12-30UTF3VROWIOW07.docdoc a015e402908723d20de5ce0e32b55d2dc47b10b36619d08893cf6212a5bf9957n/aHeodo
2020-12-30UIZPZJ0P.docdoc 9a9706902460c2e3ac9e44ed6aff62a001ce31641d96c49072c4750106c3de50n/aHeodo
2020-12-30GUZM3YENMCWZT.docdoc a586bd9284e08911b3ba6a021732d976be512698b16238e9ada5a5d08b477fban/aHeodo
2020-12-30N1VZ5V0.docdoc e0ea0fe16907efa6fba0c7da966c01d5e9c2a7f4024db84c8113a51b22b3a110n/aHeodo
2020-12-3018ZQWZMV.docdoc fc88d7102891698ce09ee38c1af90b8e225c496491ddaee1b739a12f1a2eaf33n/aHeodo
2020-12-3052EBNAPW1C4275.docdoc c0f2fe87220adb36dad5fca93cee589c0de457481655e1d64b220de2e89a11ben/aHeodo
2020-12-30ZXSG2NI51SCJ7TU.docdoc e61885a7717cc4121ce91ae5195765d765f9bef414ff079ae2476307a1fdbcaen/aHeodo
2020-12-30DBP0HFDF0Y.docdoc 400265d4687c120a0f5ac2f335dfa97bdae5a45c2dab4f11ba4ea9309b55f550Virustotal results 56.45%Heodo
2020-12-30ZLTEEOW0IUGNPT41.docdoc 94b586e5a285387c08041e2a39bc999a222670b33b5e3793cf3136cc9ca4add6Virustotal results 47.46%Heodo
2020-12-302142M41864.docdoc 6516e329e7d2f720e9cd95f5f61a9ebd0af6b0cf0f35e31e872a9eef210a2ed0Virustotal results 50.82%Heodo
2020-12-309EE6CJOB.docdoc aa1cc31a552a26f2449d7de153aab95b4b585fb76e58b5abfb6cec0e7af7921en/aHeodo
2020-12-30PAOXCSE.docdoc bf0427321d4aa0c51a23e5ce90c1565b8701260d54170233811f2629de50af99Virustotal results 51.61%Heodo
2020-12-30BGXPH5.docdoc 84ff4b1cc97853c325a80d9ea06156582a5b00d8a2dbf43e776796904b5ba7cbn/aHeodo
2020-12-306FE52UWMNU.docdoc b418b8729a429df3b5029222db61b762411c34971aa6c76b3fed3d12146a984dVirustotal results 47.62%Heodo
2020-12-306PO4HQHTTWXN.docdoc 0bd4e7dd4ab7c8f023e4df01d0012cb40b1ee9d7fb10353779eaf1fd47d53c04n/aHeodo
2020-12-30TM4B5E.docdoc a3553d4da88c65554d145c8efde7312447904dd78f21dc173354ef0b3257e555n/aHeodo
2020-12-30DX2H453GKUZ1QQ.docdoc f370e183c671a04e456590269adc4f69a59350308909cc63683d705bc0213b96Virustotal results 45.45%Heodo
2020-12-30IRCEXBARM2.docdoc c1c222eea5baec06081295edddf806c2bbd101f35d5c554d3f3b63aabe8fb576n/aHeodo
2020-12-30FTK5IVV.docdoc b0286fc6b2b0354bf5bb297ad8f8f81577bb23a3568133181a5daa3eb75954c4Virustotal results 47.62%Heodo
2020-12-30O1F07P1.docdoc dbd973f39130f458c16efc43bd6876fed237a2499fc0f270e453947730486f72Virustotal results 45.90%Heodo
2020-12-30H2L6BMMSLSCYH564.docdoc a59638db98772da1dc6e7a99d209a4373ec89b7fdc7bc87c200eeb5f793a73d8n/aHeodo
2020-12-302VT88OV74U.docdoc fb536ddde6cab869be41f798e99515c6ee28c45eabaceabb3ac1ca568fcfd723Virustotal results 47.62%Heodo
2020-12-30K8Y468TRCXLLY.docdoc ddfe5d80323178ceb4c5120878ac5448907826e95c3b76bd9c2306e16af00092n/aHeodo
2020-12-30V4IWZX.docdoc 1af286a5a937026e62b7a7b6b972f03109862f815f785d9d9d3ba20346da0eeeVirustotal results 47.62%Heodo
2020-12-30BAEM9T9N2N6CHN.docdoc a353494dd669a02ee28c0495169608f2ccd8a7d5e42a10547f7026ec218d4814Virustotal results 49.18%Heodo
2020-12-30X0AUBDHFSOXU6.docdoc 33483667c69c712c22eb8cd4c4d68c7405a8fd2ebb78aff4bdf518b997d17d4cn/aHeodo
2020-12-29OFSFTL03RTC63M.docdoc 2ac4c55baa15d3719031c845766adf59717598fe67e7434f595f28120c916528Virustotal results 47.62%Heodo
2020-12-292GJXZXHV07.docdoc 487b15fce52676130b3320631eed9f16eeeffc6e11fff1aa6b6a4aa4f694315fVirustotal results 47.54%Heodo
2020-12-29BGIRDT6GTK27.docdoc 66a2b350efaf60cc7b59b9de600b6a8183d3a8393688914c52ab4bf9d1e84ac9Virustotal results 47.62%Heodo
2020-12-2916V9TNIDU09TG.docdoc 812a1640b65eee9ca03e9030b3fb05e9ce0f467e022839fa3959cd2e4f0e7194Virustotal results 47.62%Heodo
2020-12-29ZCCSKWAHNV0.docdoc 004ffe5fdd488817ced5a47937acb4d2e3130187329de56fdb5920a56d3118a2Virustotal results 47.62%Heodo
2020-12-29L7V0ON9.docdoc d6480e873d81be6637d3ba474138b40d9773c0d9294fc530019ed6f3d1fcb1d5Virustotal results 47.62%Heodo