URLhaus Database

You are currently viewing the URLhaus database entry for http://wpgtxdtgifr.ga/wp-content/secure.accounts.send.com/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:159718
URL: http://wpgtxdtgifr.ga/wp-content/secure.accounts.send.com/
URL Status:Offline
Host: wpgtxdtgifr.ga
Date added:2019-03-14 22:58:06 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@zbetcheckin
Abuse complaint sent (?): Yes (2019-03-14 23:00:03 UTC to abuse{at}quadranet[dot]com)
Takedown time:9 days, 22 hours, 42 minutes Bad
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-03-16Untitled_03_2019_90394839.docdoc 176fc8d7c9b766558643e303d26923c6fa2986729865aacc86f3221f2c97f05eVirustotal results 39.29%
2019-03-16Receipt_132065.docdoc 321803fc2fe67c1970f91ef6d946c027bce814014127b61ab283ecf3af660fddVirustotal results 41.07%Heodo
2019-03-16Receipt_032019_223510888.docdoc 379e9857bb740f4443cf3ec144d39eb6108d6d30bd939b6cbc68461d45aec375n/aHeodo
2019-03-16Receipt_201903_419655.docdoc 3826137a54e6d54a11fd3abc91ccf1f6a8ebe5fb97249b9acc1b78743e7fd2b6Virustotal results 41.07%Heodo
2019-03-16Untitled_448291.docdoc c2fafdea65121542a5eaabc866c357056578622b9ad35c5eec9d6b1f0a0e32ccn/aHeodo
2019-03-16Untitled_9841078612.docdoc b542e1dcee9bd6b5f6e568ab45e96067c823d00510b6e557f2ac138d3ef0ba70Virustotal results 41.07%
2019-03-16Untitled_201903_54843320.docdoc f02e6224c6abab128890cb86360afa3503ae97f368223ee0a55f0fa90e412152Virustotal results 38.60%Heodo
2019-03-16Receipt_032019.docdoc d92dcadbddefbfb244f1f8b98b642fc25769f48a7ddca9cf2717ab7535ef3179n/a
2019-03-16Receipt_201903_3401527851.docdoc f973bf6429cd7f943327f693d3b924b7d8f205a063e82afb324704c3656c7f0aVirustotal results 40.00%Heodo
2019-03-16Receipt_032019_2157433195.docdoc 3dbd2c570a9fefab5ae5423b4a1e4ee2e5880690db9d44a85e76352e07b2421eVirustotal results 39.29%
2019-03-16Receipt_6409302911.docdoc d5045f79618588abf0f79ca1aecd5e75e586453da66a54efc266df943852d44fVirustotal results 36.84%Heodo
2019-03-16Receipt_201903_105220295.docdoc c3ea24f00b1c7d19ab9a5950fca634cc48472ef956529aa76fd97e5bb3acedc0Virustotal results 37.50%Heodo
2019-03-15Invoice_7346959.docdoc 8835c4045c9d6fbd9e4ea35529a3ab434369458feab327a7d08ed878cc6f5925Virustotal results 37.29%Heodo
2019-03-15Invoice_201903_0302883099.docdoc a203b6af59485d57d4530f2ba99f787233466005eef20da05b17976311370e2fVirustotal results 36.84%Heodo
2019-03-15Invoice_032019.docdoc 60683e4d53f06d4fa4501753e6fc6068adce1da7e23903635406e85bbd299607Virustotal results 34.48%Heodo
2019-03-15Receipt_03_2019_793290974.docdoc c4fbe1560255335c1841233e59cb2311a29a0c8e9fa048e5b9c17d63229a9af2n/aHeodo
2019-03-15Invoice_03_2019_5892854.docdoc a5509b36a9b9f001b6ec7abf32474ea8f71e3d79df8567e19b2bb3b30009deeeVirustotal results 35.09%Heodo
2019-03-15Untitled_201903_1143367.docdoc bf14aedaf97ce161aa6c05eb12a9d956ccd320a333e7df811eab261657efaecaVirustotal results 35.71%Heodo
2019-03-15Invoice_03_2019.docdoc 14db79623415fc45e2354cfed559f6c56aa3cae7385f9eb7359f5ad7335cb583n/aHeodo
2019-03-15Receipt_21819150.docdoc 6a1a7e4618a1803fce47331915610ffacc49abf261ee5783ef409e20b78c8e6dVirustotal results 33.93%Heodo
2019-03-15Invoice_262892293.docdoc 781ac0d18d99b193564766a40fbfea262a48883f0700958abc9ec2e579cfbd8dVirustotal results 27.59%Heodo
2019-03-15Untitled_206606969.docdoc 57277c706a102860896ee631755e31fa9624d1fb3e1683da4ae2bdef627b5b72Virustotal results 24.14%Heodo
2019-03-15Invoice_032019.docdoc 21af84f4b453bf740bd23fd90d43f3f3c135895f04f838a9ddcbc50bcb7f3754Virustotal results 24.14%Heodo
2019-03-15Untitled_032019.docdoc 531d1d9c1f88f2f4608df5714cded69207e27052a9efa757a95da6007a790dc4Virustotal results 25.42%Heodo
2019-03-15Untitled_03_2019.docdoc aefe7bc9669501aac86e7657da9bee8eae28002b3e1744cdcc1710a242e1fc5bVirustotal results 30.36%Heodo
2019-03-15Invoice_032019_5935697213.docdoc da8c3f7530bd78692ddccf4acc9f5d2fe679e80df6af930f7950e3e8ff8ded5aVirustotal results 26.79%Heodo
2019-03-15Untitled_03_2019_8003622.docdoc 2931f22ed1ea9b8ce4617a6e56d11b0c991b0157ef3b7beaa52971aa961b6dfbVirustotal results 26.79%Heodo
2019-03-15Untitled_032019.docdoc 749d4a8f81cfe055e906209ab8c3982145c601e90a9cc3a3160a7e41a676652cn/aHeodo
2019-03-15Untitled_03_2019.docdoc 159fea99bc86316d12bdebbc878569a8c861e1eb4c22e49515c3a3c849de1a90Virustotal results 24.14%Heodo
2019-03-15Untitled_201903_11136288.docdoc 8cb8fc03cc319a0ca1e0ed71273170d852f4229205c14b23222e92850c5837cbVirustotal results 23.73%
2019-03-15Receipt_03_2019.docdoc 361eec42c87c66770fa6aa1a378108bf75eea4167272f7ab80ec0dbe89170ff7Virustotal results 24.56%Heodo
2019-03-15Receipt_201903_767948761.docdoc 873c8022389ef6de529d43d977be29e3c393625c37fa67a8f4532213f1331514Virustotal results 26.32%Heodo
2019-03-15Invoice_032019.docdoc f2bdad40e4c32b6595b4f39c03906c6c2361dee4b15d458940a1b60572ff60efn/aHeodo
2019-03-15Invoice.docdoc ea952c143ad267a71ff1325bde9c87b1458bca74a11e4e7299e9562edc82ccedVirustotal results 23.21%Heodo
2019-03-15Untitled_201903.docdoc 42d21fa68553d21d0f3e96bbbbd346212d1f139c78c5933ff6ae703368418ad6Virustotal results 22.81%Heodo
2019-03-15Untitled_03_2019_4285104995.docdoc c9007a2fb68a440060989bfd3d03b9cbffe0464449abf6d7430d2d674e3f3022Virustotal results 22.41%Heodo
2019-03-15Untitled_923851424.docdoc 5df9828f7b15497e7b1fb3d96e96bbed8bd484797e15b2c498d099c8ebf811abn/aHeodo
2019-03-15Untitled_13911367.docdoc 0bdcdfc3679be739984ccc267b0080a347cde63fd307bb78cc004a62a1c64319n/aHeodo
2019-03-15Invoice_201903_1045680.docdoc 1b8ebfae3f67ae9044fa15c079c2fe6834611c94d3847e5a340499e6688a7a5bVirustotal results 22.41%Heodo
2019-03-15Untitled_03_2019.docdoc 2a0abc135cb7e2b2131b838babfbf4cef210ab2609fd0f964ba92bc14e69a6b4Virustotal results 33.93%Heodo
2019-03-15Invoice_00771952.docdoc e7cec0c1e38ddd872cdca6da84ab406daab78cff6a250b7213e7b9596f3ecfc2n/aHeodo
2019-03-15Untitled_201903_289289520.docdoc 4668b7f974f775d249b8be01939690872e95ad042e329d57592aac2b825c6cd8Virustotal results 38.33%Heodo
2019-03-15Receipt_201903.docdoc 28022a215b0f681b76943cc9fc6f9e1f2c64cc67b9b75e70aa444d226a00eacfn/aHeodo
2019-03-15Untitled_032019_1985677.docdoc 1b382931218e4adee9bec367b378dd97983695af76e0e195e62fd52064c82727Virustotal results 33.93%Heodo
2019-03-15Receipt_201903_10615741.docdoc dacfc2496b0464d3bc29d95c0cf3cf67560d631c769c7a0692d10edc384da835Virustotal results 33.90%Heodo
2019-03-15Invoice_03_2019_11884022.docdoc 71b06b15649960e7540ffc5c8ee111d3522e969c8d2207e967fc009e2c906321Virustotal results 36.67%Heodo
2019-03-15Untitled_032019.docdoc b063bfd0b93101229534a7ff69e1bef6ead5f51091f0b0ecea450deece99e2dbVirustotal results 33.33%Heodo
2019-03-15Invoice_0119750718.docdoc d9906755f505fcd060c4672d7977e82d21863eb023b58fbd82954243c840118aVirustotal results 33.33%Heodo
2019-03-15Invoice_201903.docdoc 2b1299c5f8decdff75dc37ef25e7abebfed25e9287e2ba37177d242c6667696cVirustotal results 33.33%Heodo
2019-03-15Untitled_201903_68679509.docdoc 00c1ed0fb173c266b5a3135fb548b3280477d5f712dcf8ee6a6030927d804270Virustotal results 35.71%Heodo
2019-03-14Untitled_032019_7599388.docdoc 3a38e8a5483c9fcf4c1698acc4e1b174c14b55e16403f8134f71ef8d89353726Virustotal results 23.21%Heodo
2019-03-14Untitled_7345827793.docdoc e56b6c4628483fc445a05c5de3ade068442b407edabd0cccaae7326f6299e4b3Virustotal results 33.90%Heodo
2019-03-14Receipt.docdoc b8bea3cff408c6cd5b38e4c80821b7f4b6ca241790301ed43fe42c9298c02018n/aHeodo