URLhaus Database

You are currently viewing the URLhaus database entry for http://gged.nl/geocaches/trust.accs.docs.net/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:166527
URL: http://gged.nl/geocaches/trust.accs.docs.net/
URL Status:Offline
Host: gged.nl
Date added:2019-03-26 18:07:11 UTC
Last online:2019-03-27 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-03-26 18:08:17 UTC to abuse{at}sohosted[dot]com)
Takedown time:12 hours, 14 minutes Good (down since 2019-03-27 06:23:10 UTC)
Tags:emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-27eINVOICE_FILEP7_36-02_U963.docdoc 28558d1a2e24e5a4488d71b7ca4de29d553efae10b81d2a57cd35517cf0ae7e6Virustotal results 37.93% Heodo
2019-03-27inv_num-03_2019_T8_48-53_T0515.docdoc bb3c5b56d6d614cb598b4794bd07676807d804cd97d4e9888ce7578b7a75fb60Virustotal results 38.60% Heodo
2019-03-27inv_num-S1_87-48_15696.docdoc d6d376d37614aca98ed335758933ad30bba597f57e037c16456e17125053ee1fn/a Heodo
2019-03-27last_invoice-03_2019_S9_2-52_B3684.docdoc 32b50465098b642879702c1a118a933d239466fed0cab72cfb595e0bcf20a4b9n/a Heodo
2019-03-27NEWFILE_K3_9-25_X600.docdoc 6461067f4cc442b618f615cb2550d49a22e3713cc8ded5c37e4c33790e6b3ac6Virustotal results 34.48% Heodo
2019-03-27inv_num-201903_K4_73-57_Y1217.docdoc 0d10fe705e970034049229c93062cce13a3c212827b5a94aa9bd51764fac480fn/a Heodo
2019-03-27INVOICE_DOC_J7_77-32_T451.docdoc c61249e0be72032f2d7e5c7077675d4a8b727a4fc34939242138578ac36fe4f8n/a Heodo
2019-03-27NEWFILE_032019_L0_57-17_15394.docdoc 5bc71bb74dbe33abc468fd251e325c62d499668d3b5559064a46c8ed96be330fVirustotal results 36.84% Heodo
2019-03-27INVOICE_DOC_201903_F8_6-10_P342.docdoc d33c2f96facfd8a2e38b608449676b53fb7816e319196208acc1c89f3aed6687Virustotal results 35.09% Heodo
2019-03-27NEWFILE_S2_15-53_Z2339.docdoc a8c972d20ee636ae08ea92cc42bf637b0b563120d0769fe624bfae2ca9fea616n/a Heodo
2019-03-27UNTITLED_FILE_M2_7-29_J9823.docdoc f10851f56f0d72b44f10858d77f34b90554550c6c536a59814014c608da10afbVirustotal results 33.90% Heodo
2019-03-26last_invoice-F7_01-80_2297.docdoc b45d76d8d15602f881a3758aabc9803f085f804c2eb4b2365a6de844550adec4Virustotal results 32.79% Heodo
2019-03-26eINVOICE_FILE201903_W4_2-80_04784.docdoc 8a72e9a09b39f3e902704a4773670aa9943a1bece3483a86a687c355c5a24bc8Virustotal results 34.48% Heodo
2019-03-26last_invoice-032019_D5_79-95_L644.docdoc 4c6eeeabdf7cd01e8b5eea4afd8aaa1196f891c9cca4d762225d014bb38200a3n/a Heodo
2019-03-26NEWFILE_032019_G2_83-11_L335.docdoc 51eb2718354554ebb1d700d8ce340d517af0736c33c636414259ca8921ab3087Virustotal results 36.21% Heodo
2019-03-26INVOICE_DOC_G5_4-04_Q997.docdoc 3b830090200e332b076c8cc1844a217be005a562aac2d27c4e355e74fc73326fVirustotal results 30.00% Heodo
2019-03-26OPEN_INVOICE_032019_D0_15-21_E7380.docdoc 5751b2a8d795d362f66a6e1ae7a5bc4d06cf242453667f7ac5600cc960b5444bVirustotal results 24.14% Heodo
2019-03-26NEW_INVOICE_032019_P8_10-03_N2695.docdoc 2374ec382a76e66bade5c869b9634f31863fdfb0ac2e92ce40609c29a37a5612Virustotal results 27.59% Heodo
2019-03-26inv_num-201903_F8_5-69_1859.docdoc 69ea3847f4be1650782e07dfc4db91afa83bc8cb45338d2a07d8b239316f7420Virustotal results 24.59% Heodo
2019-03-26eINVOICE_FILE03_2019_F5_15-46_R140.docdoc b1c7fb74a741ad220d6d40b0a6cebde3cdf0a44b23876ae633d8ba8898bc5d97Virustotal results 26.67% Heodo
2019-03-26invoice_number-E2_7-39_J0552.docdoc 9be5058df2129c1748805d72561af8c6c4a1bd80f265adeed685cbc19b1ff2a1Virustotal results 27.12% Heodo
2019-03-26inv_num-C4_63-59_H8999.docdoc b2eb60826f06aed5ab872a82b0716861b3a3bae9cd780652ece22a8ddfdf98c1Virustotal results 26.67% Heodo
2019-03-26invoice_number-K8_52-22_T1916.docdoc 6d5c5712555024da4599d1e9dcc9caa1e23e169746ec4c6c177ded06664e33bdVirustotal results 24.56% Heodo
2019-03-26invoice_number-03_2019_A0_4-97_A530.docdoc 4e867558dbe59b6e4930fae30fa396798583590c9d608dcd636f2523ce529a14Virustotal results 25.00% Heodo
2019-03-26last_invoice-201903_E1_51-84_16386.docdoc 7fbcedbcfbe3904e6099bdf1680ee4e953a24560c3ed84269e546e7f75345a12Virustotal results 26.23% Heodo