URLhaus Database

You are currently viewing the URLhaus database entry for http://highlandslasvegas.atakdev.com/elite-dangerous-80no0/hyNCvpykM38TCHCHBtumlqWMosQ8vBkVJfIwtxNwDYEk8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:955910
URL: http://highlandslasvegas.atakdev.com/elite-dangerous-80no0/hyNCvpykM38TCHCHBtumlqWMosQ8vBkVJfIwtxNwDYEk8/
URL Status:Offline
Host: highlandslasvegas.atakdev.com
Date added:2021-01-12 17:57:05 UTC
Last online:2022-02-08 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-01-12 17:58:02 UTC to abuse{at}totalserversolutions[dot]com)
Takedown time:1 year, 1 month, 2 days, 0 hours, 48 minutes Bad (down since 2022-02-08 18:46:45 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-12WAXG52ZN9F6G.docdoc 137602cebf7c61fe1bb6647160167813271afbd74a52fcccf03a0ad590a9ef61Virustotal results 23.81%Heodo
2021-01-127OL680TKILYPK.docdoc 7627eda11db6d5331a7931781d0dc65d79582d05ee0bd74c9a8fe845b2191c64Virustotal results 19.05%Heodo
2021-01-125YYIFPGA.docdoc a2bcf8448d750c86b5c731c98eb8cfa82794467d5ca033cddf314ce3e491306dVirustotal results 17.74%Heodo
2021-01-12BHT99D4FSK6U.docdoc e0b3fe914319d6fbbca54226cc93de6f4b5c84a9f076aaa3a897f7a46a45d6cdn/aHeodo
2021-01-1283AL7N.docdoc 1c5577ae92907b0a10a1bef6a52aad25cc73e79b523c737d07e2f012009d7eb7Virustotal results 26.98%Heodo
2021-01-127QWLDHDP84VJ.docdoc 9da23b3c04fcfa19a1abc9124178a69e76e95246fe1a5065bc2a0876543890daVirustotal results 26.98%Heodo
2021-01-12ZJ1T4RXZCTP1OBU.docdoc 5dc8879e45c66e6828353ae4f543d11ff810806cf4609fd4cd3f8d5e768a722dVirustotal results 26.98%Heodo
2021-01-12720ILHZ2UW.docdoc b142fa1e2d0996a6e33f8ee0ae3d42f87ecd62b3c86a1a0535b0cba6f4ae28d0Virustotal results 27.59%Heodo
2021-01-12Z0ZQWP04Z.docdoc 66732b32c134ca0f64b5f3a526b4232854bc11ef34861a78ded6bcfa03112d4dn/aHeodo
2021-01-1273LOAP0ATM.docdoc 10ca32d172e5dafd7c07e4e27f6c6a24bbb6af319a78a66691b819532b1d2dc1n/aHeodo
2021-01-12A361HA7UX0SYAAHC.docdoc 1c5dadca018d0b95208e3d1b84f4200ddaf6a290df549880c032ec214e62c2d5n/aHeodo
2021-01-12RUXSY670DNWTC.docdoc d9942c14d06f8723dec0e7a052837f0d09fe1787cc4a1ea50541e7b024ea61d7n/aHeodo
2021-01-12L68GBH.docdoc 473be24c31a196370f07078e057c2a02475604a900bac4afa15e998af344718bn/a Heodo
2021-01-12AR8N75GT238ME.docdoc 82d74900fb08eb37fb22e7498949dfc2d25c97435f7d3882f2902afdeb6de88an/a Heodo
2021-01-12W8XG5ZPTG3D.docdoc a82aee5b05a1f8714068bf50b59b239fd6119efc6f5759385763c2080ac69c9dn/aHeodo
2021-01-1240BOOP70YNE5P.docdoc 4a26133d82be72ab9a606016e5ec52ed71bde72f1b2b788f18b5c16d24403c28n/a Heodo