URLhaus Database

You are currently viewing the URLhaus database entry for http://groundswellfilms.org/download/Inv/npGHK-yqo_XD-ue/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:123254
URL:http://groundswellfilms.org/download/Inv/npGHK-yqo_XD-ue/
URL Status:Offline
Host:groundswellfilms.org
Date added:2019-02-13 10:03:15 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@spamhaus
Abuse complaint sent (?): Yes (2019-02-13 10:04:05 UTC to abuse{at}gigenet[dot]com)
Takedown time:7 days, 10 hours, 17 minutes Bad
Tags:emotet heodo

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-02-15GTVI04240238032.docdoc87a4be5e902f75b3674c90c4d1497e6800df6bff04472afc6349235b75f7ac01n/aHeodo
2019-02-15ACC3269304350341.docdoc10fee53ef466c2db1469b1e43e8ab0652256b13b21855ec835a07784f48c6f8bVirustotal results 10 / 54 (18.52)Heodo
2019-02-15PAY749865956263417931.docdoc2edb0fc4f343fc9ac272a217b388774e5d1838f919d3dd899ea346a9bf33e899Virustotal results 11 / 55 (20.00)Heodo
2019-02-15AU483630903685400233.docdoc32022e12de45abb4646041fa13bbaf2dc56811a16024df615ea987f875a0a008n/aHeodo
2019-02-15PAY76019287643546044.docdoc60b3e981fc794551b99dfbd3b876173a713b6a23bea42ce77a9179bd2cad4950Virustotal results 26 / 57 (45.61)Heodo
2019-02-15PAY773643891.docdoc969d18906217fb95200a191f6e85e60ca0a0d25f60b61fbdfc091bc5e6158f65Virustotal results 23 / 57 (40.35)Heodo
2019-02-15US7123137277249946924.docdoc5d1417b0af6dfe343eadfb2e942320ddfa640eefab4e67f1fd73944524269c34n/a
2019-02-14723500608944743.docdoc180b861d69ae2c5e56585f77c89c2fc310a77e8eb5dc5bc8b01383ec30466779n/aHeodo
2019-02-14ACC80274452422.docdocb2a825dad3bf548a0d029d06ae7918aaee864f8dd585c2200e43c5fdd9d9b30fVirustotal results 11 / 55 (20.00)Heodo
2019-02-146442692444866254921.docdoc7315f94b01f84b76c1b1884b21bb25c747c89092347515278b32ede89ffa0a1en/aHeodo
2019-02-145930072839768.docdoc8684f6a3902e53492c323711ead750c8bc89cfecf275df6dea172dd6ac2496d3Virustotal results 11 / 56 (19.64)Heodo
2019-02-14INSTR3181703712765.docdoc8883d9a7d7ff701bd2cbe8a02b9925ca3dfa850859c3be1bca4386637658713dn/aHeodo
2019-02-145834764647551914.docdoc479b923b0077f6a80cf191a1727a5cbe4d5c1a25652e598eddbbb611f4b20153n/a
2019-02-14ACC53119387707.docdoc60c11b3685bf6c9c23cca22c440f1035ca43a37cdc4468e8c3ee65590fc1598fn/aHeodo
2019-02-14INSTR560749712767850.docdoca5fceaa60e61bc107521469cca705ecb8e7478d9088dc1db9a24398ac2bf122dn/aHeodo
2019-02-14ACC4643631788705800.docdoc82d8ea7296ebb0ab9e0837ad5f4720a3a93873bbdf6c6f1fdfac51a161abd2f9Virustotal results 18 / 56 (32.14)Heodo
2019-02-14US81852816251744.docdocfdfc9e81e97a868f7682abd638b4864716ce36dcf03c0c88ecde9944e43e7c29Virustotal results 19 / 56 (33.93)Heodo
2019-02-14PAY1443364476707.docdocf3974fa6b3ed42175ebb584065586c9d41679145823dca70513bc9bf1a8df1bcVirustotal results 18 / 55 (32.73)Heodo
2019-02-148001543182.docdocba193225e69c78464bfd795cf91aba262985f7d275828a4b7014af2e9f7e1494Virustotal results 18 / 57 (31.58)Heodo
2019-02-14PAY48798500221.docdoc535dd500af21f1fcd2d774c871c85920c5a4e6e85e9e4c9ad7f6f863f945d1fen/aHeodo
2019-02-14PAY22378180415276180509.docdoc61b55d0f6ef49268ecf9307f87a8c9f9644c1115a249e088eeddab021d4d4719Virustotal results 18 / 57 (31.58)Heodo
2019-02-14US1017036111042.docdoc0d6916f0e3712f614cc2d1a033d68fcc5613576109a3433e8dc3bc0d691978f7n/aHeodo
2019-02-14PAY40705470221137728295.docdoced0bf400d6f097bc6ca1f736c878e9e98146ad177b10c5677b8ec9c9d3ed97ban/aHeodo
2019-02-14US0162268042499.docdoc8392aae0677e08913ad51a48a0c1a13cc5d0e9284811a340ef2dddbef2c49472Virustotal results 17 / 56 (30.36)Heodo
2019-02-14TPVQ97890957474261686782.docdoc5abf0e0ff50beae40763deb3eeb94fc9c8b1b3146fa1d4af4757a2c832a08dccn/aHeodo
2019-02-14US2901594512.docdocd937abd1fbf2905ded05aa57010c1151335e1aed5970f92a1f29062934ba5eabVirustotal results 15 / 55 (27.27)
2019-02-14ACC1335911285229353991.docdoc5f27f1b36393f4bb01d4367b2dad234ac11a033ec6a48e2b50975507ceab8027n/aHeodo
2019-02-14INSTR97315478518945592.docdoc0a63296be569d27f409dd52ab1cac44d5354aae089de3f10812d4ee324cd60faVirustotal results 13 / 55 (23.64)Heodo
2019-02-14US2139782520.docdoc239ff2db96ca0b04cecf3236fc042847b2a1a171dd047fd865ef370107369b76Virustotal results 12 / 56 (21.43)Heodo
2019-02-14PAY1765889383303976.docdocd6c82274e58b1a11abc77ca421e9474c044908713b4e9e7182686989570edb23Virustotal results 12 / 57 (21.05)
2019-02-14PAY511208734034618.docdoc1d062fd8e5908ba8e05cc39bf5adb379fbccc9ad30f368844b31017bdbcc9bd5Virustotal results 9 / 56 (16.07)Heodo
2019-02-1447349852490461049.docdocd57e99d89df9682b97519fbb04e14e58d800662d513faeb03aab88dd2b4c3200n/aHeodo
2019-02-14INSTR07518614309542927.docdoc57da2f66be0439031ae25fbe093479e30adea7e7ee656955e1964e00bf949bf6Virustotal results 12 / 57 (21.05)Heodo
2019-02-14US6899404028818.docdocc422da6ff99c38fea927a6e08024d546c38a0e93402e5e819e700ca6ffe6d250Virustotal results 12 / 56 (21.43)Heodo
2019-02-14INSTR76227205788.docdoc309129a58f1d6851dcd9d72a658ec11258eac9dbd8f889c810ed296a28886471n/aHeodo
2019-02-14US04440598460291259.docdocad5f926f062e448cde3d9cfacd38d57db66488210820c5b39ef8e1d719b432d8Virustotal results 13 / 54 (24.07)
2019-02-14US41344037735949.docdoc297338214812f4f1ca90fe35488c37e9c67f39e3e7c36ff5a9ddcf6ca87c5309Virustotal results 12 / 57 (21.05)Heodo
2019-02-14US174467316.docdoc76170daf591de5f1f31618e9f43c92ec59a157c5a0c3cda6ce228a75d4c64e6en/aHeodo
2019-02-14PAY37585225602.docdoc2f022f5381a776ca0f44649bc4cd20d659917e821e4d4d753fcd7e597192ef0en/aHeodo
2019-02-14L332195081712.docdoc0d6ff348080fd6d7e225934f41e0e7e0ff09fd3b8ff79ed940805282b707f600n/aHeodo
2019-02-14ACC04322254174332576.docdoca74159acb83e97eca7da81b6f5d45772bf2a30780b05254b62abc4927f7a4b3bVirustotal results 12 / 57 (21.05)Heodo
2019-02-1459486061552282162.docdoc2e72e06c767772a9ace4986b7e82f22bb5a86b4ecb5c8611cee0692200d0c770n/a
2019-02-1445439689753774970.docdocd4dd438440f5209a9ef454f32d55503833caf30f3a97b6454c9904c7ea463efcVirustotal results 12 / 55 (21.82)Heodo
2019-02-141509269331749996376.docdoc45339bbfa3d8d6467cff9d7afa2fcabea74fd6be632e21dccff4353a4844b453n/aHeodo
2019-02-14OKX95865320936.docdoc09af2446903f78f4e119c6f09c0370586202e7d7c32b2ab0951de926368849dbn/a
2019-02-14US535398335184284.docdoc997964c4a5c7201259c9fb53afa8f2ab39aeacedaa2d53989062ffb331b70e3dVirustotal results 13 / 57 (22.81)Heodo
2019-02-14AEJ24930216380.docdocc1e542cb3be56dce530c4b97765a172a94d7b2b3e3cbf6d9fb2e23f2f10f8fb2Virustotal results 13 / 57 (22.81)Heodo
2019-02-14PAY5253409351394426.docdocc38e6b749e64976caac387bc52fe55279fdc9fe2630995626efdb0d9fdaea731n/aHeodo
2019-02-14PAY5452712794645110954.docdoc88a2c90031155ebd1b406fe1524664efb62a6833512db27a98bc3c6416462aeen/aHeodo
2019-02-14ACC54309613779.docdoc4068918e0d70f988023b85ebcf4177aae3f893604f9cc8766d43bf4f0c9266adn/aHeodo
2019-02-14ACC608870883678.docdoc79efd0c5cfc8f807bd4a3cfdf8994da0bbdcb54dd7d0e811ce291efbbe9f1502n/aHeodo
2019-02-14WFA50309414411849.docdoc6c4a90e858e33965eed2a0da8bb29fa58c4b52a94824e57f4028d09795638daeVirustotal results 11 / 55 (20.00)Heodo
2019-02-14PAY98348024470324.docdoc03c228319f317c2b78d1a041e396dddb067b2072f7d21d73db0aad149548c865Virustotal results 11 / 55 (20.00)Heodo
2019-02-14PAY6604358313263.docdoc6f8babc146a8c3a582cabed6ef91731c2987f843e3a4623c0d951c0de13ee213n/aHeodo
2019-02-14US577898573242427.docdoce5c55d7780afd1432528adb675fa550097e850edc999ae28efcaaddd905573c8n/aHeodo
2019-02-14ACC478964872125400.docdoc5d680196c68ac6029c83fdcf17b413e5cd82366c46326997f8b608b0e94d0de7n/aHeodo
2019-02-14PAY60907219933402.docdocf8a841f2d60e35c4f6b5651bc77ec27ee0ea378b5805d791255d92340a2fc1d8Virustotal results 10 / 57 (17.54)Heodo
2019-02-13PAY8871360954022741121.docdoc1bda76c2ba98b86a09eedcd6c61ea967072ed354eda52de12da7bdeb94c028c7n/aHeodo
2019-02-13PAY998750742368.docdoc3ca6fb7b3c14305a0c058bd70064084e390431d479063d28adc9078ed037976eVirustotal results 15 / 57 (26.32)Heodo
2019-02-13INSTR130852881.docdocee5cac2feadf5ac1faaf2140aecc3025ca6d564f3ded2ad3e1669be850bd98f1n/aHeodo
2019-02-13PGOF5902640895011289.docdoccdb02a66ce1bac81c2ec4cb7c30c1e5ccc1cf40a5443f086fe5e0194a44eda09n/a
2019-02-13US12102348360461.docdoc7afe82f46fd35382d90e6e1b080e031592b4294939056cfd152f2af7c8ac7338Virustotal results 13 / 57 (22.81)Heodo
2019-02-13US57562812045925065.docdoc87476cb142b08b99b38551267bc4c4012d3878b5dd3e12ddcc6e640df0248cc0n/aHeodo
2019-02-13INSTR4178436330382.docdocf2b87084fd7d4a484703f69de9d3cf58b0c897986acf91b3e31b42819e96ad9bVirustotal results 14 / 56 (25.00)Heodo
2019-02-13US64876328813212739.docdoc460194fa3ba0f9b9179be9681769fb9ad7c133b7c320f58620844771cdc3949aVirustotal results 13 / 56 (23.21)
2019-02-13PAY12092004579.docdocc540e1e175493947abd9f110ef717ddf1b23c8202e5867a137a58cd5bbb55c0fVirustotal results 14 / 56 (25.00)Heodo
2019-02-13US8127126335.docdoc371d3f11c7cbc36239676b3690bc970604fbf547f35d125d006de30c89f884fan/aHeodo
2019-02-13US845662561342993.docdocdf3e2b108b30b7a1151160db533f05c26ef845a7e4411116e2cad0fc47902af3Virustotal results 9 / 55 (16.36)
2019-02-13US36852029609310879.docdoc235a6fa22f1fe41c21f3e797e0a89cb5936856028384b1c9ae71797ccbe01973n/a
2019-02-13ACC2168568429.docdoc0cf39d99bcdd0734e95c8330830c3a4fd66b19321a4b324fb1072251739fbb42n/aHeodo
2019-02-13INSTR1769229479.docdocfbc65fd2d9679ddbb51c60883b6ed0abc6fe6a05d8b96e6261c09c9c18293eaan/a
2019-02-13PAY26267843191334824.docdocb7f94b7a0b316768f0605052ac24265735874aabefc4db75f90332ebb57e357cn/aHeodo
2019-02-13PAY846004203315174973.docdoca29050cf42eb42ac0f2bd0f8b09a8d5b9db98d3bd58b5988ecf704ef1e6f33e1n/a
2019-02-13US1379291510.docdoc5205bb3ecf08a1c9d9c47f9bd4b70724340034bee8b6137b53682f8643e9dabaVirustotal results 9 / 56 (16.07)Heodo
2019-02-13PAY56058111008788.docdocaef842a602a410168ac11b1c17686fb7abd557591bfdd2a88d63d089c1e4f912Virustotal results 9 / 57 (15.79)Heodo
2019-02-13PAY93795823190407893.docdocf11689d6109af04fcb0666e36be4fd5738d72856e37195870d715d64875652f3Virustotal results 9 / 57 (15.79)
2019-02-13US239445266792089240.docdocb8d030c7d0228870de8bd65d62b13804dee44269065314ccffce1a4bede371e9Virustotal results 11 / 57 (19.30)
2019-02-13ACC131429073.docdocd025ffd8f6df5ab50fb3ee7f6c2aff4f4c7bfa1524a41af5102406e1a3e3ab76Virustotal results 11 / 57 (19.30)Heodo
2019-02-13INSTR1658013116538.docdoc1f0243688bbbeafac3da73172779abaf062c3babce6a96ffa4f8cf7e26575c7bVirustotal results 11 / 56 (19.64)Heodo
2019-02-13ACC853098737852244652.docdoc369708bc9937235978ffb8d809722814536ee047dffcfc50c1ed09bcea6eed7eVirustotal results 11 / 56 (19.64)Heodo
2019-02-13ACC50345235541.docdoc53bfebe9d98dcb2f31bba66c17641419467aaeb230b3e22d374e1fa75678f3a3Virustotal results 10 / 56 (17.86)
2019-02-13US23714135238975783.docdocc33ccf1f2cccd5b6bf0c64173529b2369b21cb7711671f5eb39ac10d6280d5d8Virustotal results 10 / 56 (17.86)
2019-02-13ACC1678322794961841258.docdocc9ca949f047f829f579b4cebe4a5deac8e75565fe69a01fbeecf43ff03fb925an/aHeodo
2019-02-13PAY546256167760451247.docdoc6e53b891aed384eca0a218eb9a7944c3b3b08809caaa7d998bbfd5979ba339c3Virustotal results 7 / 49 (14.29)Heodo
2019-02-13ACC4232345803990.docdoc814fc239c1d7adf7b8566d9a2590941cd36076d9d811796d7aa0da770a858f47Virustotal results 9 / 55 (16.36)Heodo
2019-02-13US653558855428.docdoc200c9a7142fc66501f2d9d51e6c25dfd7cbfc9b7892ad9f92feb8c849ffd8876n/aHeodo
2019-02-13US817898025505455.docdoc97553c2b1a1521b54b7c8bd64de298f32e8ca853a3362b61437086ce5d956eefVirustotal results 9 / 56 (16.07)Heodo
2019-02-13FEF7311124809.docdoc3db73446abcba2bee46adbf3aaef02d262f9f1714e6ee00a0f9fef3f8863e770Virustotal results 9 / 56 (16.07)Heodo
2019-02-13WHZ9542925381559528.docdocd354cdf32147b8f652b6782180cc39a45400663810a0f7485280f781e07b404dVirustotal results 9 / 57 (15.79)Heodo
2019-02-138460159078.docdocd11bd02787f71befabc66b6b59d7636a800df74b1402b186055502a2f5f194e2Virustotal results 9 / 56 (16.07)Heodo
2019-02-13US9463658783377904412.docdoc24a58cbcbc314ea1d72a0ea1cdbd8f46c1624cca315589549fe77cc2e916bee6n/a