URLhaus Database

You are currently viewing the URLhaus database entry for http://gla.ge/old/enG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122979
URL: http://gla.ge/old/enG/
URL Status:Offline
Host: gla.ge
Date added:2022-03-30 17:55:05 UTC
Last online:2023-01-21 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 17:56:05 UTC to abuse{at}proservice[dot]ge)
Takedown time:9 months, 26 days, 16 hours, 17 minutes Bad (down since 2023-01-21 10:14:03 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31JB-7742887909.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31VWN-4600804.xlsmxlsm c477d7314db2e481dc0afaafdc010642699dff0e0b641a374e91754a51fbf094Virustotal results 38.33% Heodo
2022-03-31HY-268056186252.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31MF-75034074.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31LHV-336861572083.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51Virustotal results 41.94% Heodo
2022-03-31QX-78084798.xlsmxlsm 30deb7a7086f74317285271a2e26e40dc43b461a1a77c77480ea742b02cbe51fVirustotal results 38.10% Heodo
2022-03-31KC-520531315.xlsmxlsm 265f4ce97b8c4a17c8f27359496edc3f97e2e6926a267fba16797dd5c6e3a70bVirustotal results 45.16% Heodo
2022-03-31KBV-999115688369689.xlsmxlsm 52939ecf287fe6bf3435960c423bf17f7ea8452f102024e9aca86cf806fdd533n/a Heodo
2022-03-31KP-6654645581451.xlsmxlsm 0c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3Virustotal results 36.51% Heodo
2022-03-31JNT-298268256.xlsmxlsm d0e1bf9a8969b0e7856ed1015033cef4c745a120413c76d61b1560e323de2359n/a Heodo
2022-03-30XQ-405378422735615.xlsmxlsm 7bd47c2f3e932a049d450f5a54be51e401ea041d669c7df91f71b903358f99d9n/a Heodo
2022-03-30NUL-3801097980598.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30AT-49512890.xlsmxlsm 7b790cb9f037644da2aa7daf038bef787f020bc8aad1932fb1e8c4c5ab3b4766Virustotal results 32.26% Heodo
2022-03-30WJ-276339758836.xlsxls 82be92d18fb73fad9b6f0e90da074abbf2aaffd91c4493491620452f19bd281dVirustotal results 26.67%SilentBuilder
2022-03-30n/ahtml ac3b188b7cf196c52f99733600d8e34edcc0ecbd1958dbb1b92e18fcf8abfb5dn/a