URLhaus Database

You are currently viewing the URLhaus database entry for http://football.g-sports.gr/paok/jkL8M4zza4PwF84/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2119216
URL: http://football.g-sports.gr/paok/jkL8M4zza4PwF84/
URL Status:Offline
Host: football.g-sports.gr
Date added:2022-03-29 12:56:04 UTC
Last online:2022-06-08 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 12:57:06 UTC to abuse{at}pointer[dot]gr)
Takedown time:2 months, 11 days, 2 hours, 16 minutes Bad (down since 2022-06-08 15:14:01 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31LIM-050944816330838.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31IL-40373418419383.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231Virustotal results 40.98% Heodo
2022-03-31OVU-32849315255361.xlsmxlsm a7ae8fb40c5d93e9ddbfc68b000b65ba19b085e7a19d3a5d9bef1c243a6add91Virustotal results 43.55% Heodo
2022-03-31IPM-311698437747.xlsmxlsm 9098c46a233798193c0587711f5a9be2a4aa97567db08504452748dde516053an/a Heodo
2022-03-31WN-94826031.xlsmxlsm 2e8dfaff0039f7b69af5f699d0efff85cca1b5dbe2a50082b7ccc49503545053Virustotal results 40.32% Heodo
2022-03-31XO-98350412831409.xlsmxlsm eb39b29661d81cbcd7a00f191c61ce9902b80b68e1e03215e56221bfc85863efVirustotal results 39.68% Heodo
2022-03-31OM-5852798.xlsmxlsm d4f941f7232c98be2d39a4a97edcad5b4648430bb60ad5a21747b37e705ff2d2n/a Heodo
2022-03-31FFA-26212255249.xlsmxlsm 4409b097292f1ed1adedbae38fcecf71370a64209f9bb5ffff019b71e8a88533n/a Heodo
2022-03-31RX-358332603605739.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564n/a Heodo
2022-03-31ODM-2038653532.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31GNE-630872679654680.xlsmxlsm 355981d4c8400968deaa8a13a04a79c90bf9aab795af2ff1b3273b825a477968n/a Heodo
2022-03-30VC-15091168010.xlsmxlsm d3ad5641b527c4ec7e77e037ed81f1913c394f063e13677b8744b26fb09bdecen/a Heodo
2022-03-30XO-7107367.xlsmxlsm 533372e6130ad44ced6eae30ab3af8be4ae172cc7585719b61074bb861f2dbbeVirustotal results 32.26% Heodo
2022-03-30RPF-04892041.xlsmxlsm 9da38d7964f16ed0c46e5a0ee55152196bf8368f5e2d2b08cbf8c24932ec490dn/a Heodo
2022-03-30CJ-8932624346467.xlsmxlsm b10ed69f8e9b0da709cfaae8849ada80e45de31d91fbc07e9bf9a838aa73b1f9Virustotal results 37.70%Heodo
2022-03-30XUJ-0666026.xlsxls 2fb5d6b4684b1f180fd682f92fc346420c16376d64b8b8ec6b0564247000dc58n/a SilentBuilder
2022-03-29n/ahtml ae0a2ec164fcf7992be6afc7c5ecca706f28dad3e8f56fada69346574e778ab9n/a