URLhaus Database

You are currently viewing the URLhaus database entry for http://gandhitoday.org/video/tciTHleuwlagM6dsS9AFBHBSb1u/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123153
URL: http://gandhitoday.org/video/tciTHleuwlagM6dsS9AFBHBSb1u/?i=1
URL Status:Offline
Host: gandhitoday.org
Date added:2022-03-30 19:34:08 UTC
Last online:2022-04-21 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 19:35:09 UTC to abuse{at}dimenoc[dot]com)
Takedown time:21 days, 8 hours, 41 minutes Bad (down since 2022-04-21 04:16:27 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01ZIE-0558477.xlsmxlsm 8d85241fa9e4b815618a159681381b11248ae1d6ebac31af9036814028b205ecVirustotal results 42.62% Heodo
2022-04-01IWN-46161495.xlsmxlsm ea8981ffdb13c6d1dd874a5a86e7079bb053c862a92849bc571846a6762dc7d4Virustotal results 45.16% Heodo
2022-04-01LR-202342834900.xlsmxlsm 178e56af34b8983297784e7e795578c7567350c8ef3be2b30a43a05de59b9e8bVirustotal results 47.62% Heodo
2022-04-01GJ-7772068861636.xlsmxlsm 875624a88021db5860b95862981fb858e5864d3a6d0edf195e528bd268876577Virustotal results 50.00% Heodo
2022-04-01JOT-695813577941.xlsmxlsm 7e16b96f674b1b3fa812fb1720851a37cb88e781ae92220bb858320fbe62c331Virustotal results 39.68% Heodo
2022-04-01WA-81949839325.xlsmxlsm 1cef59b0cfd651edd1b587c50988c75a14b39c325a3f41839e3ce51c08f7f753Virustotal results 42.86% Heodo
2022-04-01AH-004051942.xlsmxlsm 2efeae28ad35e91b7abb28eec555e20e394693d8454514a43fc119fde473348eVirustotal results 41.27% Heodo
2022-04-01GF-007940811603.xlsmxlsm 60833a18e14a8b4eb21cec280bdac63e8a03eeda78c1c5e0e641624b72000be8n/a Heodo
2022-04-01AU-753564631335.xlsmxlsm 5a5c8a3d5de13a95ffc29d40c54fe8440d1c84f706e59960f5f1621715b8a1dcn/a Heodo
2022-04-01GW-3513846503.xlsmxlsm db05585c173bca5c340fd01dffcf23be710be4b482131d5bc16f4eedb265754dVirustotal results 37.70% Heodo
2022-04-01SF-60373252724267.xlsmxlsm 0f6cfe4c94b7444729077741d333e0388edf05a02cd4dc40e515a03f5d4bf01bVirustotal results 40.32% Heodo
2022-04-01IY-4130702.xlsmxlsm 5ea7243ee6fea62276b79e7f2bf602ec3058d33fb8ddbc31faf71eb0eadf1a90n/a Heodo
2022-04-01KYX-173833561853.xlsmxlsm 4fe9cdc6b35e9992d206f5a0bb6ebcb063618ed502e651ba2f5c014a2aea5776n/a Heodo
2022-04-01JSX-640063762462.xlsmxlsm 525f6667c0439d7c21905eb0aec33c64c4b4ee34d0f3896f67f5140927b44d90Virustotal results 42.62% Heodo
2022-04-01WPP-608132024258.xlsmxlsm bba184efb454972191ec837362eddc4ef35f60b616033ef54cbd77d1a70f8f3fn/a Heodo
2022-04-01EN-47741589011024.xlsmxlsm 05aecb805762b1c7cae04f8f46d0d43392d1b6e4880c93d82f69ef52d8dd2660n/a Heodo
2022-04-01ET-79073606.xlsmxlsm 4967f52b4eec67dedea5ef764a47c545db43f04f5b0f1355dfa16c8b8bc6e1e8Virustotal results 41.27% Heodo
2022-04-01QTZ-2582628.xlsmxlsm 3623198cf3a1c1fa6b945622bc0877af82f973eebcca8a89240665cd06e38b8fn/a Heodo
2022-04-01MH-500001247678.xlsmxlsm 5c887aec3ff6d6b86adb64e688521d4b396689f6e29bb2106125af1b20b9d5c3Virustotal results 38.10% c8fc17ff030feb3383d8889f69abbb
2022-04-01YW-319111501.xlsmxlsm b7a2ba71c06e47b7011fb3b7f3a263a34c991d3eead33a69dbcf967bdeda5a96n/a Heodo
2022-04-01HT-2813274404331.xlsmxlsm 2cbe77b879d18d1912fc160e101f3ec30a74eebfb2d138b01259a14979f15060n/a Heodo
2022-04-01QPZ-0447953267580.xlsmxlsm 95ef55ebe10de62e86f04fbe1ade582e008dfa6d36bdc7207146525626b6638bn/a Heodo
2022-04-01ZNF-22076399.xlsmxlsm 299bb2145f0b8204975127a266633cb549cef59d4f53ac9a21aa2d9ef1adf13en/a Heodo
2022-03-31EKO-31936213620980.xlsmxlsm 5165a1e19391e7f4c4a5d6f8113fb024b3a6ba299312f9cc3afab95d6bf84cben/a c8fc17ff030feb3383d8889f69abbb
2022-03-31ZOJ-4735172233513.xlsmxlsm bbf1ee7ac4c4ec95b8f5be027d6d0063d9067480f0bd4f7efcdbeeaa827dceefn/a Heodo
2022-03-31XH-30142964640549.xlsmxlsm b240ff1edec81e1d31562cbd34499c1f2085346a7de34e51016cb82e3cb85716n/a Heodo
2022-03-31WQG-2609411906168.xlsmxlsm dffde7ff06d4b4d38ae8f02750d5c59b2a1a293d05af04210b8e79d0b3fd4043Virustotal results 38.10% Heodo
2022-03-31GV-8887239485858.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 35.48% Heodo
2022-03-31KPQ-27333842062632.xlsmxlsm 317b14af792a2e4b877fd65cd6dc1cdceaf3d9573dcc1cf673e5008d38f7b6caVirustotal results 35.59% Heodo
2022-03-31FE-68275338677524.xlsmxlsm 2fa93c2dfef003816d473094a03ffe57ed6fd6cbbd21f22831af88634fc3287dVirustotal results 37.10% Heodo
2022-03-31KXW-993356817244131.xlsmxlsm 764dc9c37da82215bfa8dce451fc0946c901984084015a98478a65bd670835c2n/a Heodo
2022-03-31PXS-871277943929969.xlsmxlsm 36828e7a04990e1d0b2b67ccfa64ea170ff92c77cf92107d904f1e106c1d676bn/a Heodo
2022-03-31MG-5193989072839.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31II-45150821.xlsmxlsm 53ef2d3a553342c46f5d3011cb07634e1f02b36dae99808e47dd459dd384e388n/a Heodo
2022-03-31TW-56532995.xlsmxlsm a1057f814e603d7b7ff7b711305cac0ef15e48b78499802d411424a19ee235f8Virustotal results 40.98% Heodo
2022-03-31ST-919357627340116.xlsmxlsm a099f9c9c8eff7049da288a1205f1c0ccd52a4954930cabdd7a00dafbe8bbe6dVirustotal results 38.10% Heodo
2022-03-31HW-11733460.xlsmxlsm db67f0509c5f982c9eb1fab5a17d14ea07d5a1e13b2f5ee3b35ccf93700588e4Virustotal results 38.71% Heodo
2022-03-31EF-7698416451630.xlsmxlsm 484ac30b71e02b553efb54dd38ddc6e86610a68995e280411a4b9f30c8630c77n/a Heodo
2022-03-31GQ-7221829.xlsmxlsm a43da1637de01a06d72a9d09981de5132b8bd971844704ee9fc7c5e07450a49dVirustotal results 36.51% Heodo
2022-03-31ZC-660469389.xlsmxlsm 61ad9b2b8c9707a14412bf30d2e17c11d75dd548e841d9b4eb6299ca1e0456d5n/aHeodo
2022-03-31DY-986856538492.xlsmxlsm 0c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3n/a Heodo
2022-03-31DLN-5645313602363.xlsmxlsm 08e924859a3a3f17c099cca75fbb3cfd7f8cd726fa2e89fb47ff02f9687143baVirustotal results 38.10% Heodo
2022-03-30UC-868876908985676.xlsmxlsm 9a0b2121a81929d3ea98a8b4b0e20693192eabb5c4081e2ac411fe4ed06f9f7bn/a Heodo
2022-03-30OJ-10962659628.xlsmxlsm 0d52cf42b7a5f7ec21d78ec1ab0861571f4136b9d08a6de2c4baea447cac0a6aVirustotal results 39.34% Heodo
2022-03-30WAF-83893554.xlsmxlsm 70c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080Virustotal results 33.87% Heodo
2022-03-30GTP-40068408717.xlsxls 403c28ce1df56f185d0824575299bea20d7d1738e6a9688c551d039b6d1aaea2n/a Heodo
2022-03-30RMF-887764821906290.xlsxls 31ad327541ee0627096151e901dee22241e584b78b52c17eee5a1c40a6f25490n/a SilentBuilder
2022-03-301791287634372773540.xlsxls 7e0fed83342cb9194e28095ab63cea9de221517ac891b52d151316e4a6b0647an/aSilentBuilder