URLhaus Database

You are currently viewing the URLhaus database entry for http://oboi-nn.ru/content/omXllU8C4tReWjevkIZsLhgRex815TMPHJA7Iiq2Pn2VgO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:945677
URL: http://oboi-nn.ru/content/omXllU8C4tReWjevkIZsLhgRex815TMPHJA7Iiq2Pn2VgO/
URL Status:Offline
Host: oboi-nn.ru
Date added:2020-12-30 16:28:04 UTC
Last online:2020-12-31 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-30 16:30:19 UTC to abuse{at}reg[dot]ru)
Takedown time:20 hours, 6 minutes Good (down since 2020-12-31 12:36:22 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-31H5EGU8FN4.docdoc 43af38ecd27585f00463abfee0ca7f492fb36fa862c8d215447d59be27652589Virustotal results 50.00%Heodo
2020-12-31JAXHIWT.docdoc 38bbd83de3da247dd96f8f463e73ebc76a9165bb783fc85432714e863675d87fVirustotal results 49.21%Heodo
2020-12-31TP4IIC8C.docdoc e43be8ecf4cbc6b3d85f07d75f2e9e4666b38fbe656d5179697bca7246a4d924n/aHeodo
2020-12-31BZJ160.docdoc f188a66e42ab843218ecec727c9910b6205a89b8f96a980c0738f83cb7190e5eVirustotal results 49.21%Heodo
2020-12-318CUJHLV8WW967.docdoc b3f17e4feb7e3617fdff582ab7012dc57c64c1baf55d92a0af205cacd82bce98Virustotal results 49.18%Heodo
2020-12-313ZXMFRQPD.docdoc 5b4299a14a7a1bcac53b86176777b6fbe902fbb5a440e9040126b39743db254dVirustotal results 49.21%Heodo
2020-12-31IFIDYCJZAR1U9GK.docdoc 8b8ee2d2fa51b5a1c72a0b26ea27569873c8b69955d1ea8aa665ae2ffb1513c6n/aHeodo
2020-12-31KOI7HHBK7O2.docdoc 1486fe920f39107bae3cba0f5fbfee0eeee6a5ff8389360cf26868c9bb692730Virustotal results 46.77%Heodo
2020-12-31RS1LIJ1P.docdoc e05aadbe41028646840c187217377776330ff87cf0c0aad82cb1cf15236243cdVirustotal results 42.86%Heodo
2020-12-31HUX0D5CO27E54.docdoc f9929b5a3d5cb50bece6e6dd8e553d79f36e34bcf71e2f302d709d108582e6d8Virustotal results 42.86%Heodo
2020-12-312VGXFK1B.docdoc a60ff35ef82526eb15d040ad870e8c2808dc694bb52b1095ba863c960b40678bVirustotal results 51.61%Heodo
2020-12-31APJXMNULX7LSA.docdoc 9c05cd41d8c7fb3746acbcaad200dc66bdc79609905a06213a787799c9661985n/aHeodo
2020-12-31P0M73K.docdoc 9e067dddbde70837fe2f8227c507629d2ccc7735fd8dc9950f9d9b2c6c5ba6a3Virustotal results 46.03%Heodo
2020-12-31MQALHIO.docdoc 75e6fc7e5c98a20bc64f7944d2bead6901f575fe20135e9aafe210ee2e1e2c49Virustotal results 42.86%Heodo
2020-12-31WOX9D874X7O3VT.docdoc a076dfb0f7e5a9217dd1cde4b003fd8714d6693b990f2ac4fd1b70fdbea38296Virustotal results 42.86%Heodo
2020-12-310YJ3VQUU.docdoc 6b85d222fb12df6466d8b1dae31bb6e7706463ec73fd86f85e46ef7867183df1Virustotal results 43.55%Heodo
2020-12-31W4CB5P2CG.docdoc 14eef594729b6784626929323d1f4a040cf76e3774ad5b77a16c28449db182cfVirustotal results 43.55%Heodo
2020-12-31TQP6JXCW77OQVJY.docdoc d6704fdc1942538d16ddedbe3eff3c429e462d4378b33040597c5a218c0e852fVirustotal results 42.86%Heodo
2020-12-313FE311L.docdoc 0b9ad72f95097098c7273fc3e89e96d14537deadfe1570a2e36b8ec40bf241a7Virustotal results 41.94%Heodo
2020-12-31P50IQKUODNQTG.docdoc 712989be681e3a6e8cd47b84ce5feb957d2cfb47367d96bbc7dcd6551bef1f51Virustotal results 38.71%Heodo
2020-12-31TRSTS99KOK.docdoc c3995c2fa8060e207a999e9ba7fac45ac419f717a024eb0bc1059e197a595595Virustotal results 39.68%Heodo
2020-12-31BZXATKJ4.docdoc 399701ae00f1f4e019e97b788362403c8323b417cd0f72fef7f9a39dd4ad4436Virustotal results 37.70%Heodo
2020-12-310S0EXJYF.docdoc b19c3ed6b6012da42e3a700410a21231588c6b1da97f92911a540b9e3ae71b08Virustotal results 32.26%Heodo
2020-12-30ACULQOZ01.docdoc ece0d267bc9cfa2b32d2d93569757b8895f379ef0b752fdafdb457da534a0de9Virustotal results 31.75%Heodo
2020-12-30A6CCDDFDB2U39QX3.docdoc e561d015ba417615f931d69404149b840e6f30d937c6d1e8765462d08c33384eVirustotal results 30.65%Heodo
2020-12-30OG95JS1WCNRJUXV.docdoc 8c39bdef7f9491fc985afb40906aa1f0d4427bb9cb2299ebacd5511b442e9982Virustotal results 30.16%Heodo
2020-12-30JMTOV96HWW10ANL.docdoc 22c9b454977f772e641fd2d5d4c08fb9e124cdc9ec47c69ed037fed87bbf1abbVirustotal results 42.86%Heodo
2020-12-3049D21DBOIMU6.docdoc 7dbe3e3f4d5e95b69111858fc5e96f73c1b7f8284276a1280486ab64139324a2Virustotal results 40.98%Heodo
2020-12-30CRYKIIC3OLOFT.docdoc 48242492ae400d1b2e95ed96ed2298bc76c87036b1f79e92d38a07e5cb14712bn/aHeodo
2020-12-30CEPX3EFQTFV31.docdoc 3bf59384c4c1a24eb5fef4453dd1fc63a75324f4aa6b86a62ba47de3393027a9Virustotal results 41.27%Heodo
2020-12-30D3L06UA7L81NC.docdoc 9d7889fe83c60f08711f29825a62cc029f17329e4008a7298e7c3ba5cb6ae8ffVirustotal results 41.67%Heodo
2020-12-30XUZZHIC4CR.docdoc 214c118a6ea6243f11f97d6a83c14ce0efa696dcf534eb46de221d4199cb7c88Virustotal results 37.10%Heodo
2020-12-30JY3UPC.docdoc d6dae3570b800a4a54bbb661e945c2870952058174a0ac704127c7cfe8330bcdn/aHeodo
2020-12-3088MASSRJ4U2V.docdoc cd86c55218a19d3c739795e4da8c0c8b34a731b1d89fcc0685a5ceed2f3f8feeVirustotal results 37.70%Heodo
2020-12-303NUAO1L8C4W.docdoc 24b9b439815155d6b338c75f2ae2d92deb41c580a893dac9153f5042abc8b702Virustotal results 31.75%Heodo
2020-12-301Q2TCP27U18P3.docdoc ebb494890c3756f3bd2d17fe15fea7443671ce48c7d22821b6f0e73920ab061bn/aHeodo
2020-12-30ZK6LYDQG1HD.docdoc 643eeead31f1c79f2a2d191699189bd671ca0169fff0feeb3824ff0b57281e3bn/aHeodo
2020-12-30VKRUUS.docdoc a2bee4290712595f0afb87e5a247cafe694d279fb7350e43bc163630e926aaa4Virustotal results 27.42%Heodo
2020-12-3041MPGDI3AK5.docdoc e1068c52aa236bb0111f08ab3140850d7fbe24bf3e5f32697f64701390f5d516Virustotal results 29.03%Heodo
2020-12-30SH1799TB4W6NT8V.docdoc be2287f06352c21f4412b81411c76a2e3c23bc99bfd67a39549574e6f0143ec5Virustotal results 28.57%Heodo