🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://groovy-server.com/masjid/backend/web/assets/rhhl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:264311
URL: http://groovy-server.com/masjid/backend/web/assets/rhhl/
URL Status:Offline
Host: groovy-server.com
Date added:2019-12-06 17:58:20 UTC
Last online:2019-12-12 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-06 18:00:19 UTC to abuse{at}digitalocean[dot]com)
Takedown time:5 days, 11 hours, 19 minutes Bad (down since 2019-12-12 05:19:20 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-07INVOICE_X97_919.docdoc e4d7d49e9ef80bc034115f9c6bf145e8970266cb42641ec07f3bdeac913f83f6Virustotal results 29.51% 
2019-12-07Inv-V75_09427.docdoc 20baf8f1f4f97306c4cb244f2ac5b6404fee457e1f227cd19030b207b409baa5Virustotal results 30.00% Heodo
2019-12-07Invoice_DT87_215.docdoc a83c34fff50b7e5bc5e00794ec139db888abb47cf1847c3e1cc64737dac54e4fVirustotal results 29.51% Heodo
2019-12-07Inv_ZRD91_16.docdoc 81289cbff004394f08cd5ba840b2ae6066ffd3ea942fe359ad34db6d8a07ae7cVirustotal results 29.03% 
2019-12-07INVOICE-WU244_4127.docdoc 0c159e0e8060d2b0b382a4e61fd6d473f3efbc6891c8afa43e48e159ae4dc287Virustotal results 29.03% Heodo
2019-12-07Invoice SJ14_866.docdoc 819273b637aa3d7db7f8e436d37513443d2eb96b7d449bf11cdd3f1fc221d2b6Virustotal results 33.87% Heodo
2019-12-07invoice-LYO52_5149.docdoc 7a743f758e06530c4d7aaa024ccef94eb93f201138417160a6937d28b26dce17Virustotal results 29.51% 
2019-12-07Inv-TX951_1527.docdoc 8a34c30566de585e38b1d24df4adab7f62b294658336dd5237ac461823b73b0fVirustotal results 29.03% Heodo
2019-12-06Inv OI11_2658.docdoc b8f8976fb561850ed96f9a185f734fc87b21f186f0ffdb40379f0137bd460147n/a Heodo
2019-12-06Inv-ZB19_9546.docdoc bd66ce5877dd63401f1a4cad09598c1d73206bf04f3f1d6bbab1be6f28f79fa6Virustotal results 29.51% Heodo
2019-12-06invoice G78_939.docdoc 45f63ba57fd017b834fabec1976e4ab1eb57d949849ea020c8c85d80d0164c3cn/a Heodo
2019-12-06invoice-C41_87.docdoc 82b9b97f8e5ca40acff72f74380716ce160f5880b21e072e7658825d23bf2f79Virustotal results 34.43% Heodo
2019-12-06invoice-NXA80_46.docdoc 1b88229e6342a2ab51cdd2390020fe3ff11cd053980f8fe23209c11c0b66c4e1Virustotal results 29.51% Heodo