URLhaus Database

You are currently viewing the URLhaus database entry for http://gabeclogston.com/wp-includes/KClHvcfyi3350/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:272215
URL: http://gabeclogston.com/wp-includes/KClHvcfyi3350/
URL Status:Offline
Host: gabeclogston.com
Date added:2019-12-19 01:06:04 UTC
Last online:2019-12-26 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-19 01:08:02 UTC to postmaster{at}myhostcenter[dot]com)
Takedown time:7 days, 16 hours, 12 minutes Bad (down since 2019-12-26 17:20:02 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-21Pay Payment mHZr40645.docdoc 00ab1ebcd1d58173fd34c16ffaa7c0d90d18d42fd32c7fc02712b579aff9412dVirustotal results 33.87% Heodo
2019-12-20Bonus EV75527.docdoc d16ee5e6a801ea10cc27c7479ff07817082f40b992d08f0c1ac4c85d7116c409Virustotal results 29.03% Heodo
2019-12-20Pay Payment coL19123.docdoc 2c46b65e08a68113d8e5218b14a44c4cda753f1ca3507e33e1da477e7d365b89Virustotal results 29.51% Heodo
2019-12-20Bonus Payment Notification z7943227.docdoc 34c38d43e0762eb291cb497d18c9651c5441d1bbaab25f847c0ddc419947b3ceVirustotal results 32.79% 
2019-12-20Bonus Payment Notification SaSv5331629.docdoc f19e6a6fab57bb7157e808a0b892131f6c3e373286283a34f19cc5db1ab55a3cVirustotal results 31.67% Heodo
2019-12-20Bonus Payment Notification CptI41.docdoc 1f53b3c43a43ef79659e6cecb0dfdfe31037e5ed092ec67e6f5f9ac2cd26338aVirustotal results 30.65% 
2019-12-20Bonus Payment Notification 98176.docdoc aa5dd888e705275c637ccbdb974ec8299eda718438a98b5e5885eb33dfc7ca74Virustotal results 29.03% Heodo
2019-12-20Bonus Payment G346361557.docdoc 3f4cb2656e251b3047fa24b117f63608b91f3d5870ec83485b1f23f4a8ee811dVirustotal results 28.33% Heodo
2019-12-20Bonus 60607502.docdoc eda3d8fc7385b9e02c996cc54836b47dd9674db4794d580d765afad139265c40Virustotal results 22.95% Heodo
2019-12-20Bonus Payment Notification 4836209.docdoc 4fbdc05906bcd987ac4c11cb94b360fec824b26560ee07a847f7cee086b6c80fVirustotal results 24.56% 
2019-12-20Bonus Payment Notification DB75244079.docdoc 14bf4c4d896c5b6ebbabc3d601a882c5d2193e674c52e9750e764aa22739bc77Virustotal results 25.00% Heodo
2019-12-20Bonus Payment Notification VRyg59.docdoc 4903616001af26a0df8c09fbf94cf5f5b8d76402d42379246df3b7524764d663Virustotal results 24.19% Heodo
2019-12-20Bonus Payment Notification xVA40134.docdoc e8f4adbc33575dfdc6cc8046ec0478baee34237bda285c3e9fd4798aea4ea516Virustotal results 37.10% 
2019-12-19Bonus t4559.docdoc 8d3e771513bc024e170ab926ed232211058a7255362ea6e7ffa389dae92b7fe6Virustotal results 36.67% Heodo
2019-12-19Pay 376146.docdoc 3d7ec36ef593059cb15482cb0c22135cf596659d76c1665a22f609788f33f3b3Virustotal results 27.87% 
2019-12-19Pay l1943.docdoc 6b817a391b0b9b60adb2382cfab72ee0ec73d24c0be867ce42cca557eea2b469Virustotal results 29.51% Heodo
2019-12-19Bonus Payment Notification g54002.docdoc c81fa6a0d384474c75454f40007dee1c7c00275f1e049246ba3025a46be69bcaVirustotal results 29.03% Heodo
2019-12-19Bonus Payment Notification 21.docdoc 60d9761ec33a814667a8a09a86ce91f7b3bef4d2591e58b59b5a8a5fd475aeecVirustotal results 30.65% Heodo
2019-12-19Pay 01137.docdoc 8eabac636c65cf97f66d75b737a3563e8a80fffce129742ecd595a1b5b07fb12Virustotal results 31.15% Heodo
2019-12-19Pay A48329.docdoc c0a0545beb2cb40bf661714b59697aaceefb7472dad692d1fc4fcbca11f17feaVirustotal results 26.23% Heodo
2019-12-19Bonus Payment Notification mlFH18058.docdoc 5056d7de897aec253441613685a0bee32f545314631166d0791f6febf4c41b1aVirustotal results 24.44% 
2019-12-19Bonus Payment Notification k4624723.docdoc 50502b1309e5510dc666c2dd81f978bacd097de74ad3839f00cf37bd162c193aVirustotal results 27.42% Heodo
2019-12-19Pay Payment 905.docdoc e71fff463f764b73ecad00e2e79a1bd24291b4cd50fac587caa21a991639b53dn/a Heodo
2019-12-19Pay Payment IJ874.docdoc 2b13889d5f4a071ba4f42e8afe9b791682ccda5750819138b8968b4416343fd2n/a 
2019-12-19Bonus Payment Notification A7931484.docdoc 1d9a2835541ba7470575df473b1d5a565ec98f7204173e5d2da011ca69e51e35n/a Heodo
2019-12-19Pay Payment G40655425.docdoc 90e77add8742b2df9bcf25655c2e021380497a54fe45511afc7a600aa72e1ea5Virustotal results 22.95% Heodo
2019-12-19Bonus Payment Notification A36.docdoc b10a94e113bb1f430e437f788a82ef32bbfa9f18f82a7dbe09f633298bfc7babVirustotal results 20.97% Heodo
2019-12-19Pay Payment fAzH3395.docdoc 89c3f11b51e8677ad318853298abf7ac9df38bac16509c58650f28be8386a996Virustotal results 27.42% 
2019-12-19Pay VogV71153531.docdoc 7670d15cab240a4ae8183f7253a1289186f6aae13f676581fb9b41e0659bb9dcVirustotal results 27.87% 
2019-12-19Bonus Payment Notification bH15483272.docdoc 126cec3feb653048275d4a88bf3ce13e845f4c26796d364b4a7f50dc070d3375n/a Heodo
2019-12-19Notify G5112928.docdoc 320e90e290901f78c4b9e8ea11988debf3c58e18cb1b0ac0a09873a9302d450en/a Heodo
2019-12-19Bonus Payment TxZT29322.docdoc 212ccdaeddbf0c436bb59d7d0ad672017bfe6e36c60b08bd48d4f3aaebf3db08n/a Heodo