🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://gemapower.com/wp-content/geschutzt-Zone/xe25r3zuyrj-pafzglnxg1-Raum/SsGSo6t-h8Hfxk4h/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:273797
URL: http://gemapower.com/wp-content/geschutzt-Zone/xe25r3zuyrj-pafzglnxg1-Raum/SsGSo6t-h8Hfxk4h/
URL Status:Offline
Host: gemapower.com
Date added:2019-12-20 08:12:04 UTC
Last online:2019-12-21 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-20 08:14:02 UTC to abuse{at}cyberdata[dot]co[dot]id)
Takedown time:18 hours, 59 minutes Good (down since 2019-12-21 03:13:53 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-21finale_84479.docdoc f7fd13cb45859219db5620e417e137b99ddeb61ad442e902ae0ec30e81dbc704n/a Heodo
2019-12-20einheit 12212019.docdoc 06e964cd2981bc6abea29dd680ea91ffff97629d97d557f306066da6c354c5c1Virustotal results 32.26% 
2019-12-20zuletzt V84154006_88461737.docdoc 399194bf5a65f66bf7d130c1b73d5c5fd4cac3743ceb388986e338a04725bceaVirustotal results 27.87% Heodo
2019-12-20neueste_teil_0347292mn2oo123.docdoc 0e2f92e673a24cd047d183ebcc0fdaca842dbd2d0f32b7ddf18eab3ce91a571aVirustotal results 27.42% Heodo
2019-12-20teil_325694.docdoc 9e8e6471cccc7b739425937c4cb05ba396ab46c51968183b2f650f98efab87fcVirustotal results 32.79% Heodo
2019-12-20datei 737721908.docdoc 115088a6fc23e09b797f8256fd67ee60eae48df940103b7607f7d171523dd47eVirustotal results 29.51% Heodo
2019-12-20einstellung_793m2173992.docdoc e10256aa8460c9c6df046fee0c72c6d41130ea4ff241d3f85eb707d89b812225Virustotal results 28.33% 
2019-12-20genehmigt erklarung WKU1392868048.docdoc f1dc527a12949a0fd551074f73929a39a7381a9cd15d4d7fe80e8afb4c273501Virustotal results 26.23% 
2019-12-20relevant_veroffentlichung 12_20_2019-427348915.docdoc 7341e01ed1a97d33041a38384c431e41b85a74bb4aae8340902df81ae75ba543Virustotal results 25.00% 
2019-12-20genehmigt teil_12_20_2019_BG3198355.docdoc dc98644b4039cf69b3aeca3e755ea9380f66cc906fe23126044154fd4655be53Virustotal results 23.33% Heodo
2019-12-20liste_CVI985084965-550245.docdoc 4fa69a6e2bd147fed055ce29ac3da808c8b02490daedce960863bf3bb908105eVirustotal results 23.33% 
2019-12-20finale beachten_3841302810.docdoc d4e3d681d03d1cd5656f2357b747b972e0c96ed59dc1842c47b57809c6e42c3an/a Heodo