URLhaus Database

You are currently viewing the URLhaus database entry for http://klaksona2.net/_dump/BUyy0Zaa4VOb1rf8Ff0ABcgsiggRypyXBLFQAmlRXAG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:948970
URL: http://klaksona2.net/_dump/BUyy0Zaa4VOb1rf8Ff0ABcgsiggRypyXBLFQAmlRXAG/
URL Status:Offline
Host: klaksona2.net
Date added:2021-01-04 19:04:06 UTC
Last online:2021-01-05 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-04 19:06:02 UTC to abuse{at}fornex[dot]com)
Takedown time:5 hours, 1 minutes Good (down since 2021-01-05 00:07:11 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-04S7MVFGK.docdoc bf2f59ecb85a6029a908bdf90f5dae875e68196bf1987cf72959bd568355c702Virustotal results 31.75%Heodo
2021-01-04HECOOEUCSY58I.docdoc 9e43571bf7a712feb6f6f6f2dbbef7876ee0a5895f2219bb76775b6809d98f09Virustotal results 30.65%Heodo
2021-01-04HKQJ999QRA6RCUSW.docdoc e2de08e5eefb901fdc1050f3870f4efc4d9853158f3a93a1db37b2f4b140459en/aHeodo
2021-01-04F4WWI7PINP0.docdoc 145466e49f1ebf4ed38896709a64733353a2389bd676b7ef055c79637f53c082Virustotal results 30.65%Heodo
2021-01-04PDJEN7YZMH6KJ6S.docdoc bd71cb5216319d67b7163d101b227e46c1b8172480c96aee9172be8670c32fbfn/aHeodo
2021-01-0436IKVECDSR3ZT.docdoc ec3397b618b0b92c5556cac23ae40686fe9fca8c6fb2097fe84de3909ae48e1dn/aHeodo
2021-01-04ILFFRBX1QHGI2HVZ.docdoc 70364c0d02f4a1d61a76caf33b3c7b6349e382fc465685ce6ff04f6b1f422b1eVirustotal results 32.26%Heodo
2021-01-04N5PYTA01X.docdoc 6a61b4d6424c45621d9da70561c8bb5c1a28772e43241374ea706bb04cbfc058n/aHeodo
2021-01-04IRVWA7TMH.docdoc 7bb94464b3d84793306c5871494ec5b557815c2dee93f5ff5ba01e1fe7c85d88n/aHeodo
2021-01-04T4SVVMC1MU2FZ29B.docdoc 17c93d81b95f2b725804776e87495cb9c024cd0c25c389dbb1931bfe5b335824Virustotal results 32.26%Heodo
2021-01-042H05HW8QUA3LN1S.docdoc 8c09b7c7b59889f547395a4d9d2832a4b32b88e8d5e3bb22bb560842190c58d0n/aHeodo
2021-01-04FYN91J.docdoc ee679637d75a8f5af5112158416276ace0f51e892a1b1bbf0987c2e3f8d366e5Virustotal results 31.75%Heodo
2021-01-04FQDBTZKHWG.docdoc e17ab8ab24888272311390fa534231d03447787b2c7f69a691c30b04f9c18c51Virustotal results 32.26%Heodo
2021-01-0464LTO3OO1Q.docdoc 2cc7e1f0bd0691c4398e97ad98573985d7c28a85712210379e667f7573baad2en/aHeodo
2021-01-046ZUOWUAS7325BM.docdoc 49a4678f9b33879cb16662dd5d05bc7e7ec713bbf6a85741a81f9e1e0f3c37f4Virustotal results 31.67%Heodo
2021-01-0428KE8WU4LXI.docdoc bfb1730113cb5053d74406fb4fef94281848b94a36f77692bfa06724fb26712fVirustotal results 32.79%Heodo
2021-01-04ZYVHL48GB329LP0E.docdoc 4ce9c1ba330aeca51cd7b8f6b7e1796c1ead42dde6868d7a5fd636b9a3a9f4f9Virustotal results 31.75%Heodo
2021-01-04T98IJJJVYFB7JT1.docdoc 82d7ccf8a708facd6356a918e9930803db68740bffed556687da9891ebb7910cVirustotal results 31.75%Heodo
2021-01-04ZCMRM9G36AIP5Q0K.docdoc 40977b89d6a6667e3e77e68d8a87500fb5461c61c6aaab7355550246e0f03cd6Virustotal results 31.75%Heodo
2021-01-04Z86P8Q.docdoc eaa2a7a6ead0fb817d96de5539291d86caf887cbba94836c246755105a7a1429n/aHeodo
2021-01-04FUFK79T934.docdoc fea083de9b31b49497005d6f38cc508f73e1853f6563eb2775257b8a48b9ff42n/aHeodo
2021-01-04AHA4DC3X69B7V.docdoc 7e6a510852e8b5039c2dc9ea63d7420b5dc842c21c534cf29b343454d726a4bfVirustotal results 31.75%Heodo
2021-01-04Z1H7AGAWFV6KJGQ.docdoc ac2433d19823522a5239c92113bcd6b6e9bd92a56465ec572b75490cdbe14ea1n/aHeodo
2021-01-04FBL30C2A2I0.docdoc 6dbcc0255f24c2876b32acaea6ac383eb2995ef52d51806db60df781d4b15e54Virustotal results 31.75%Heodo