URLhaus Database

You are currently viewing the URLhaus database entry for http://kallistoengineering.com/kallistoengineering.com_2/YcITKEf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974661
URL: http://kallistoengineering.com/kallistoengineering.com_2/YcITKEf/
URL Status:Offline
Host: kallistoengineering.com
Date added:2021-01-23 00:18:09 UTC
Last online:2021-01-23 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-23 00:20:21 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:1 hour, 0 minutes Good (down since 2021-01-23 01:21:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-2354XJHBZZSP.docdoc f2f810ac8d53caf7b5ad3fa8566ed61610f1ef80b7a9ef571b9bd112ba745909Virustotal results 46.77%Heodo
2021-01-233MQFUW2F96.docdoc f34429ad75df699dbcc635b6afcd91b52756fa1d34dce852fead86e0c7eea37fn/aHeodo
2021-01-23H92M91S3D.docdoc 06706618f6fb465f559d7359295a2757c1cfd4311ae5ad13d1b3ed2acac1a2b9Virustotal results 45.16%Heodo
2021-01-23OL54G91LHYTL3.docdoc 9fab5bfdf6aee085fdc28360f1a5473f5ac94a97722377c40c572e0fe20cd9b8Virustotal results 46.03%Heodo
2021-01-23IDQH4DFKLHNL.docdoc d5da4dc5a6a3fc416aca8ffbfaa3b6cb18a1efd11b94eb7f40a584fd96813f8eVirustotal results 46.77%Heodo