URLhaus Database

You are currently viewing the URLhaus database entry for http://159.65.156.124/csci-4061-cbljt/bMukLRmM89gc1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:945540
URL: http://159.65.156.124/csci-4061-cbljt/bMukLRmM89gc1/
URL Status:Offline
Host: 159.65.156.124
Date added:2020-12-30 12:14:04 UTC
Last online:2020-12-30 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-30 12:16:02 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 hour, 9 minutes Good (down since 2020-12-30 13:25:58 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-30KDURJOGZYYN.docdoc 0ba1937af38c05e2b7dbff1968cfe0f4be186f31d6c80248c907cf869d12fd0bn/aHeodo
2020-12-30ZBXU51OTD.docdoc 30123f50820037c7241d7a3052aca6a9ebb345b5b4ceccfd1ba9563356e15b50n/aHeodo
2020-12-30XYUYGVDIECFQX.docdoc 9828c9c819155af174adfcce8cc53b4dbc8e10db6f0f4b0661fe7225bb7f1b55Virustotal results 26.98%Heodo
2020-12-30CGWAK893I.docdoc d3c400cfbcbb1324f78b4207f0db99af1eedb7e13839a26b1c016c5070931934n/aHeodo