URLhaus Database

You are currently viewing the URLhaus database entry for http://cursos.graftech.mindlink.mx/cache/NAXcr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974254
URL: http://cursos.graftech.mindlink.mx/cache/NAXcr/
URL Status:Offline
Host: cursos.graftech.mindlink.mx
Date added:2021-01-22 16:37:08 UTC
Last online:2021-01-22 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-01-22 16:38:02 UTC to abuse{at}asmallorange[dot]com,eig-abuse{at}endurance[dot]com)
Takedown time:4 hours, 14 minutes Good (down since 2021-01-22 20:52:41 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-22DF4LST5S.docdoc d25d5d359b01bb46095375c553f2b4ea91e2e4abee77df10d21d6ab08740dc97Virustotal results 35.48%Heodo
2021-01-22PGOP7MG7F.docdoc 1cc3ce82c3d5c07a7ad73b7890969696e032964b0773b29a1f21a68dc55e23d6Virustotal results 33.87%Heodo
2021-01-22HS2H22O.docdoc fd740860d3a13f655a4dbba01a3721f0a412082b7ba59f4b04650493fe6a3e53Virustotal results 35.48%Heodo
2021-01-22ZVU75ZFWLF.docdoc 7d208c37e1692e448cb66adc388c1d5a77f06bc1ffef7dcf756ee681530158abn/aHeodo
2021-01-22V7I4C2XFN.docdoc 37866f94856a5faf43b8d90001a46a03ed9a8c10d666298bcc0341d28842a1a6n/aHeodo
2021-01-22HAQODZH6PDB4.docdoc a6e3f80247934f88e6f81b410856f90de3c0f41e5ae883b9f469e68c8c67ea38n/aHeodo
2021-01-22VNBA9TNV1F4Z.docdoc 1d6af24aae07d7b11397907b44aa3108efeaaa211b182a6dc28246b79a36a2c4Virustotal results 32.79%Heodo
2021-01-22ITWQ46SYFI.docdoc c47dd140c6bc057daadb9ee597e65f4354bd84521ed7631a0f100eb027f6adb8Virustotal results 31.75%Heodo
2021-01-224I5509OR.docdoc e35524adab62617f979bf2093ed1c81d50ea11bbf40b3f32bc000a58fe99a39cn/aHeodo
2021-01-22VS4RMBSCE3Z20I35.docdoc 1d2d80a3a1d3ba28ca88d827cc5fb6b166f7d41b3f91065e8448f691275bcd3cVirustotal results 33.87%Heodo
2021-01-22EU5IRYWENB.docdoc a9cd44d0dd7d458a7b1e6368dbd0f0d2693a1da40c46561532d097f7f79300a6Virustotal results 31.75%Heodo
2021-01-2293414JD5G.docdoc 361afbb90589c1dbaba30c9c8b380772449df5b01544e084fe473b501f583129n/aHeodo
2021-01-22HKGQVK.docdoc e26acfd8ba9ac131426a2d9667e8ad19344e9977a884531fd2a2127615481f99Virustotal results 32.26%Heodo
2021-01-2259KB4Z.docdoc 4645da6dadb364b09a0a89f510be736a7bf0d088e5b79a002bdd4bf430ff9fa0Virustotal results 32.26%Heodo
2021-01-22AUIH0DJZHTPKBPP.docdoc c56e64333878661b5c0a2ca6fafb49c64b2c59dcbbc71dfb9835e5b22d7a80ffn/aHeodo
2021-01-22KH7N4RY.docdoc 0dc0f00a3ed385b6bff2f9188766ae977a173405c9bfed86474e9f7fccfde9c1Virustotal results 31.75%Heodo
2021-01-22X53UGKIEPDW4BY.docdoc 6faf81f488e12cb29d73fd407214f06c3b94e083a11756827ab37874616df7a2Virustotal results 31.75%Heodo
2021-01-22NQ0OGIWW5.docdoc 980a3949995d00c52383ec46cfdb15a05a9ad20aea7fc2a11a834a7ceffb5484Virustotal results 31.75%Heodo
2021-01-22MYG8R2CT5.docdoc fa73aaf86c492584aab024beb61b333cb383c5a742ae789e1c20f40d599a9457n/aHeodo
2021-01-224MDW5WUI1Y.docdoc 50b8d46bcf2478298f38ac41a4d18e945a2767d6c2e2ca192472ed6b12174b3bn/aHeodo