URLhaus Database

You are currently viewing the URLhaus database entry for http://geowf.ge/templates/sxewOepbtGY743ko/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123108
URL: http://geowf.ge/templates/sxewOepbtGY743ko/?i=1
URL Status:Offline
Host: geowf.ge
Date added:2022-03-30 19:05:04 UTC
Last online:2022-04-27 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 19:06:05 UTC to abuse{at}proservice[dot]ge)
Takedown time:27 days, 18 hours, 28 minutes Bad (down since 2022-04-27 13:34:11 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31OMM-566777442121345.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31EDF-13268628092.xlsmxlsm 53ef2d3a553342c46f5d3011cb07634e1f02b36dae99808e47dd459dd384e388n/a Heodo
2022-03-31DVV-80767717985.xlsmxlsm bc2b30e9969aa7dc11544b73955d47d12ec3d2febe998b5cef4b57c89dde7215n/a Heodo
2022-03-31JY-09618846.xlsmxlsm a1057f814e603d7b7ff7b711305cac0ef15e48b78499802d411424a19ee235f8Virustotal results 40.98% Heodo
2022-03-31ULN-6373066240355.xlsmxlsm a099f9c9c8eff7049da288a1205f1c0ccd52a4954930cabdd7a00dafbe8bbe6dVirustotal results 38.10% Heodo
2022-03-31QCV-031290384355.xlsmxlsm 8ffdaa8f731fe2148ad8c7dd79ce44c3dc17eadb46af64c64a76395fd0e629acVirustotal results 40.00% Heodo
2022-03-31TC-7976079263.xlsmxlsm 484ac30b71e02b553efb54dd38ddc6e86610a68995e280411a4b9f30c8630c77n/a Heodo
2022-03-31HKQ-970659069568633.xlsmxlsm f1a59459dc11d8edab701cdd7610dd6310993ddb1aa04ab43f8fc3536040700dn/a Heodo
2022-03-31KQZ-7024909722767.xlsmxlsm 52939ecf287fe6bf3435960c423bf17f7ea8452f102024e9aca86cf806fdd533n/a Heodo
2022-03-31VT-58171288.xlsmxlsm 0c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3Virustotal results 36.51% Heodo
2022-03-31WB-7239626028.xlsmxlsm 08e924859a3a3f17c099cca75fbb3cfd7f8cd726fa2e89fb47ff02f9687143baVirustotal results 34.43% Heodo
2022-03-30FP-820399998831.xlsmxlsm d3ad5641b527c4ec7e77e037ed81f1913c394f063e13677b8744b26fb09bdecen/a Heodo
2022-03-30UJ-21356718.xlsmxlsm 60198b10fd3c8daeeb186be258cdf74b24c18a364638c8b6c6370e0bf4a005e5Virustotal results 33.87% Heodo
2022-03-30PV-215830641.xlsmxlsm 93629f0e94046fc0c1c1a2779a8e58d101136842695fc4ad3addbde6c7757dcdVirustotal results 31.67% Heodo
2022-03-30IT-274191622.xlsxls bc3aadb828bf8f9442d01bb0a1d6b11b7633b19d2d0f8dc6711897611c0a5c3dn/a SilentBuilder
2022-03-3058976858068151.xlsxls 3493b3210a3ce325a05cc7da5ffc69d323e0a0a645d8bdfaf1016a2de52ee1b5n/a SilentBuilder
2022-03-3081392623943952.xlsxls 47d56d48a9d1124c93c30fceca3e85139262e561196d7e483048f00952a1dfaeVirustotal results 28.81% SilentBuilder
2022-03-30978808931833403.xlsxls 6fc96a58c317377d9ff8276f95b48d0891d63dfae2c3ec8b8960037107578322Virustotal results 26.67% SilentBuilder