URLhaus Database

You are currently viewing the URLhaus database entry for http://gandhitoday.org/video/tciTHleuwlagM6dsS9AFBHBSb1u/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123147
URL: http://gandhitoday.org/video/tciTHleuwlagM6dsS9AFBHBSb1u/
URL Status:Offline
Host: gandhitoday.org
Date added:2022-03-30 19:34:05 UTC
Last online:2022-04-21 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 19:35:09 UTC to abuse{at}dimenoc[dot]com)
Takedown time:21 days, 8 hours, 52 minutes Bad (down since 2022-04-21 04:27:51 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01ZIE-0558477.xlsmxlsm 8d85241fa9e4b815618a159681381b11248ae1d6ebac31af9036814028b205ecVirustotal results 42.62% Heodo
2022-04-01MIX-96411931350795.xlsmxlsm 0a23b203754e6a043fa99f6cf518c8ffa19a34557a7471edad072d54c4a76dacVirustotal results 42.86% Heodo
2022-04-01SIR-6055122190105.xlsmxlsm 0f6cfe4c94b7444729077741d333e0388edf05a02cd4dc40e515a03f5d4bf01bVirustotal results 40.32% Heodo
2022-04-01JAE-17205441.xlsmxlsm de11fbbfacd6c871dc2033f96f1dacb1815ef7122825f3a2fd1fbcc9459ce4cen/a Heodo
2022-04-01NFP-32894687465.xlsmxlsm b67f378396a813307cf0d9d7c4f272be83010272fcfa9af1791b517cf4f1ba05Virustotal results 42.62% Heodo
2022-04-01ZLV-850403060.xlsmxlsm 64d236fdcb188d517ddb0fd6ffcaf1759dddd828de26d1cf6b605031589da663n/a Heodo
2022-04-01OLX-62051816861012.xlsmxlsm 534f4ab246459c91599d4d14e916a2f16707134075a5a88d897105a0e782632bn/a Heodo
2022-04-01AH-004051942.xlsmxlsm 2efeae28ad35e91b7abb28eec555e20e394693d8454514a43fc119fde473348eVirustotal results 42.86% Heodo
2022-04-01GF-007940811603.xlsmxlsm 60833a18e14a8b4eb21cec280bdac63e8a03eeda78c1c5e0e641624b72000be8n/a Heodo
2022-04-01WI-20517155962822.xlsmxlsm 606cbdc0ecdc8c68efea96696850b401a2f42925109a960adc15b100ad3c8175n/a Heodo
2022-04-01QV-275399477.xlsmxlsm f9b634d0fc322b2f8b2bbc77c5e3ea1c1bee950fa5f931dd9b69f46348863ee5Virustotal results 46.77% Heodo
2022-04-01EAT-9979886498.xlsmxlsm db05585c173bca5c340fd01dffcf23be710be4b482131d5bc16f4eedb265754dn/a Heodo
2022-04-01VGZ-4884992796131.xlsmxlsm 7aadba6319e34f3f67650c7e4835b28bad03ae427d25c01860412b9180eb0d7bn/a Heodo
2022-04-01YOS-308227646590.xlsmxlsm 2fff16868f10c6160310b0a347d813df22d0876f07b6d43eef2bf272eb84723dVirustotal results 40.32% Heodo
2022-04-01JSX-640063762462.xlsmxlsm 525f6667c0439d7c21905eb0aec33c64c4b4ee34d0f3896f67f5140927b44d90Virustotal results 42.62% Heodo
2022-04-01LTK-766813208092011.xlsmxlsm f9c9f51df261403227f4db33c8a418d0d9e90e02cba1b750d1b6c0cbd6b1892an/a Heodo
2022-04-01EN-47741589011024.xlsmxlsm 05aecb805762b1c7cae04f8f46d0d43392d1b6e4880c93d82f69ef52d8dd2660n/a Heodo
2022-04-01IKO-38109865.xlsmxlsm 004f6c9fad398f8dda13f421a6faa1a78916ba04c3eabe988acd669f8cb1b112n/a Heodo
2022-04-01ICT-989862085.xlsmxlsm e40bfb9b0a236fa78f9150e560fa82b899430dd6cf6da41388a30f8e09496ecen/a c8fc17ff030feb3383d8889f69abbb
2022-04-01LA-796896268.xlsmxlsm 886b5540d8a7234ca4d384341ef859f08d555dcf16aeb021075140bb81459b9aVirustotal results 43.55% Heodo
2022-04-01WW-47757121.xlsmxlsm 9ca7e881cd1e46ca3a73efbad250390fbb3fbc92c6d90d0f25c6a218055f323bn/a Heodo
2022-04-01VZD-304409815832259.xlsmxlsm 57a73cab7fb65bf97b094b8ea188937cff862e7e55cb179ad32cc6d9200d8855n/a Heodo
2022-04-01TL-6477907607321.xlsmxlsm 4fa09bf32b85b3833ade1083764b776848c0d1455d84823012134e6297f9c773Virustotal results 37.10% c8fc17ff030feb3383d8889f69abbb
2022-03-31QJ-79384976.xlsmxlsm 1f89665519be0af8fa6ccf11e12d78adc54cf5560f8826352dd036d8663a9bdbn/a Heodo
2022-03-31FPC-495295696.xlsmxlsm 5fb54e96fe17c395fa69dc06933558b083ae9cfb1391218f12c539c2645a8311n/a Heodo
2022-03-31JZI-2242927539.xlsmxlsm 1bdada6954ab20722dfb51b2ace2e6fcdfb556210c74bb059752552f5fa8f78fVirustotal results 42.86% Heodo
2022-03-31WQG-2609411906168.xlsmxlsm dffde7ff06d4b4d38ae8f02750d5c59b2a1a293d05af04210b8e79d0b3fd4043Virustotal results 38.10% Heodo
2022-03-31FK-00783875.xlsmxlsm a395d2ca627270c1b53481050d39c6395c778682e98aeedcb00d1f68fd1ec23fn/a Heodo
2022-03-31JY-718985743755.xlsmxlsm 99bacd00ff714e00339dc64c1418b2c0c26ca69120e34bd32ba8e73d2044cd9cVirustotal results 40.00% Heodo
2022-03-31EZ-715544147.xlsmxlsm 1ced9273a6ee8877064196bee5023e889b35f9c84d1e0d3a5920d438aa763618Virustotal results 35.48% Heodo
2022-03-31LM-466723088.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31LBE-3533727136.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31RG-233462535908.xlsmxlsm fea58fae76c86e5f07c7f8b032f84174206bc489d92c49fe54a5b51d2658faf8Virustotal results 34.92% Heodo
2022-03-31JP-9139162620.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31SN-7374048956002.xlsmxlsm 9098c46a233798193c0587711f5a9be2a4aa97567db08504452748dde516053an/a Heodo
2022-03-31SZ-568301910.xlsmxlsm f88eb7101fdc0fe20190969ec3bb4651bf4f270d9a9636d6c1e1a84ae46a9cd6Virustotal results 37.10% Heodo
2022-03-31MNB-66045568.xlsmxlsm bb415157a1b9bbe60b44a718eaed436370f6a07df786986c3adde6f5f22c12feVirustotal results 39.68% Heodo
2022-03-31EF-7698416451630.xlsmxlsm 484ac30b71e02b553efb54dd38ddc6e86610a68995e280411a4b9f30c8630c77n/a Heodo
2022-03-31ZF-773500081403553.xlsmxlsm 52939ecf287fe6bf3435960c423bf17f7ea8452f102024e9aca86cf806fdd533Virustotal results 39.68% Heodo
2022-03-31YV-754877675648.xlsmxlsm 70c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080Virustotal results 43.55% Heodo
2022-03-31RFJ-225850055.xlsmxlsm 93e06d8850641586fe31c662da490f8ff442f4f86021f50799e1174dcace1f72n/a Heodo
2022-03-30ILR-5729000919466.xlsmxlsm 24499993a94d9888bcdc8a5b9c58aadb86dbd363efdfc2fe1996d98dba57bde8Virustotal results 39.68% Heodo
2022-03-30OJ-10962659628.xlsmxlsm 0d52cf42b7a5f7ec21d78ec1ab0861571f4136b9d08a6de2c4baea447cac0a6aVirustotal results 39.34% Heodo
2022-03-30NF-40302038330976.xlsmxlsm 7b790cb9f037644da2aa7daf038bef787f020bc8aad1932fb1e8c4c5ab3b4766Virustotal results 32.26% Heodo
2022-03-30DT-17971210.xlsxls f3101b6d16751623f8a025bfbf75ae9a32c68b534dccbab4452ee72a9fbe0f5fVirustotal results 28.33%SilentBuilder
2022-03-30n/ahtml fd57f7327f5067317241bf941a0a7fd500e8c37ca9b7ec612a947bd0b5b5ced7n/a