URLhaus Database

You are currently viewing the URLhaus database entry for https://ghltkd.000webhostapp.com/wp-admin/sites/5mohqk00/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:293201
URL: https://ghltkd.000webhostapp.com/wp-admin/sites/5mohqk00/
URL Status:Offline
Host: ghltkd.000webhostapp.com
Date added:2020-01-21 04:12:06 UTC
Last online:2020-01-25 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-21 04:14:03 UTC to abuse{at}hostinger[dot]com)
Takedown time:4 days, 3 hours, 39 minutes Bad (down since 2020-01-25 07:53:46 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-23PO_01232020EX.docdoc 91b43a10d55096d465d155a3e02a19afe445cee2649e7a9202a2ee2b54ecb45aVirustotal results 30.16% Heodo
2020-01-23NX2100865529WC.docdoc 9af2280771f435166b53ce4682f2cedf9072877a0fd338920e1a7ae4434c47caVirustotal results 30.16% Heodo
2020-01-23W_VN1045246321QC.docdoc a7da95cc5af2d5b4e1d2b4e16f96007855b5783f4383c199878f2230aaf11453Virustotal results 32.26% Heodo
2020-01-23BAL_PO_01232020EX.docdoc e63aa1c3401d847d86e7d7a0183b1b09932060991feb79d6e2b775a27f30c36bVirustotal results 30.65% 
2020-01-23DOC_1579136887403273532470.docdoc c902819826aded735fa4ea8025d726e7b868dbee374343fde8e6b5a3fe6733e0Virustotal results 28.57% Heodo
2020-01-23INV_GBK_010120_PPL_012320.docdoc 1fc298251ecbc967c1a852ae8549568c2d11d20ff8c2fe5795d71c0701dc0d1bVirustotal results 27.42% Heodo
2020-01-22SW_00760165.docdoc 29487cc347b96694240c5003b2fde7f8e509ac63ea9365249aa1a23c122502ceVirustotal results 27.42% 
2020-01-22FILE_2742698331190278250813923.docdoc 72bd6822c6587d7476c2bce9cbb767b7f392c8c960c6a5f08b75f5ef154f6a2aVirustotal results 27.42% Heodo
2020-01-22RP_AI3578513395JP.docdoc c551f97351c13e0f158f87d3c11bbdb5b9f2b2b10576509755d225e3f3bf46c7n/a Heodo
2020-01-22RP_28677310.docdoc 31e49b1899bba2d501d48db72766686f1c0d77627dd79e5585b8f5dcf1de7054Virustotal results 28.57% Heodo
2020-01-22KBA_010120_VWB_012220.docdoc 1edd209142cc223e891e8dd444c153f50de141b3239f20dfad8f44bf278752a9Virustotal results 28.57% Heodo
2020-01-22934289781386777.docdoc 1acea02225c6650692c85051717ea09e03791a57fe39ab10730263373f7fbde5Virustotal results 28.57% Heodo
2020-01-22SW_RLPTSMJUAL6Y5W.docdoc ab600b906dee873222585e34ad20f43a3eb8dbc281f88b10eac0e7ed4b8f6f8fVirustotal results 28.57% Heodo
2020-01-22ST_Y7Q097Y8GT02.docdoc 478f1dc50e192ecb20ebcdb9a37e7c312e9a8cc20766a5f86f95b3d9c09cc0b3n/a Heodo
2020-01-22INV_NZM3OPU9BHDVTI.docdoc 4c80edcbb0062e3b1f50fd07de05afa15805203131f6a34ae1dd4f4591dfcf20Virustotal results 30.65% 
2020-01-22PAY_PO_01222020EX.docdoc a8e86ce1edef7bad9f725d8f9b127d50d0a80a4e3477a2294f61bd2be001bfc7Virustotal results 31.75% Heodo
2020-01-22FILE_VMH_010120_LNU_012220.docdoc 2e5f9f296d5addeabf6f8caa5e1e989363265c1ca3cba2201a933e734bcf8635Virustotal results 29.03% Heodo
2020-01-22REP_BHMYY2OULGXZY.docdoc 8866f17525978f2cec2f21518499d6d84bd654adcc1bfc22f90d7fc47eddd406Virustotal results 29.03% Heodo
2020-01-2295966534.docdoc ae732e2481c442c721b9c70bbbafde35384fc2d9c8e8426e67eabd9863b3e009Virustotal results 26.23% 
2020-01-22PAY_WOC_010120_YKG_012220.docdoc 2060f7df174027271307cce5c7a8ec61c05546b084780a80186d00fc343a2b0fVirustotal results 27.87% Heodo
2020-01-22PO_01222020EX.docdoc a85351653bf9a0c8c76db9f4c1076418ba4fface5c3a7f373d29186bf46732e0Virustotal results 25.42% Heodo
2020-01-22REP_PXBJS4P8N.docdoc 6386c6fdd8a1eb4f6fc7bf14c51236c53a6d7dc8419ff7add51d3a75c46d3610Virustotal results 20.97% Heodo
2020-01-22PAY_VNZ8BFKBEK3NI.docdoc 8205eac5713b6e780f44ca0ead54f7b14258c7553e717184eee2ab927d901095Virustotal results 21.67% Heodo
2020-01-22NOF_010120_JTO_012220.docdoc a0855eab3940a455dc8d9abb41fe9a44d09eb1153e79da6e813565d5dac82f24Virustotal results 19.67% Heodo
2020-01-22ST_CB0022477931IW.docdoc 7a2981d0930261cea557f3e13fe0f3c8789b4c3d07ceecf861481ab926156b0dVirustotal results 21.31% Heodo
2020-01-22NDV_010120_DRH_012220.docdoc 6321d13c864a5af9a0a39e72120db0999714232489e7bf8461b8a795db19a222Virustotal results 19.67% Heodo
2020-01-22INV_482186279352128.docdoc 368d63a431bc9d979e6ad0775f7327956d973a19119aae25175bae3b42ce1c5dn/a Heodo
2020-01-21FILE_94560686638976811.docdoc afc71ff2f950fe201610ccb3658ecabd28277de445f299d235048e06bb3c02ben/a Heodo
2020-01-21E_69816231.docdoc f6bb39c8461a893a69f23d81190fcd6b5f19470c17632ca95cba8516acdcc20dVirustotal results 19.35% 
2020-01-21GTZ_010120_PMP_012220.docdoc 4a5b9b9742ab79ec97f03a713d79186193ea89fbdce64cc486bdfeb117c7e7bfVirustotal results 19.67% Heodo
2020-01-21PAY_03688201.docdoc 2b0dc7a3f1517e44bdc07ad1f4e244e973879e977697384256d409300c3d8396Virustotal results 19.35% 
2020-01-21REP_PO_01212020EX.docdoc f8b7610b7621a91b5d28857ea340a864fe7c4b11e544e0a8d55b06130078f520n/a Heodo
2020-01-21FILE_3D485H3X4V8IUEIF.docdoc 87f198aab109437e66b753398ed36d61115bcd349c900750ed31b89952b9f3bcVirustotal results 20.34% Heodo
2020-01-21PAY_37647705.docdoc 0ac7a98f0bbf451a51cb75aa5b065d00e46c0860c7cd1c90a194e8a40a56aa93Virustotal results 19.67% Heodo
2020-01-21INV_EUA_010120_STJ_012120.docdoc f8cd0ec825c89fdfbdcebefa1756132a3f4d14e798d4b8f1833de4b6db4eeb91n/a Heodo
2020-01-21PO_01212020EX.docdoc 8efb9bd8a23cc1688102e8bc9b1e436656af9e65c14951dd13b2b8e04aa9beb6Virustotal results 23.33% 
2020-01-21BAL_RY0081505932RH.docdoc b3027e1a517aecd6ce516879fe1f0b6ccb4565a07aedac1df279f168ab71abd4n/a Heodo
2020-01-21M_MW7555950624UW.docdoc d1117a28a75e18b39ecab237339947455fc2f362df875ff30e726b14dc16ee62Virustotal results 25.00% Heodo
2020-01-21FILE_0NNPDHZ8K.docdoc e4932995a94e0c841f96d023503d1a1bb8e8278fe5478a736b9a4cbc83283ab7Virustotal results 25.00% Heodo
2020-01-21INV_IPAY4X8UX1FQ7SU4.docdoc 0e9e43c0429b560afae123776797b95528cfb7b3564487c82a25a57c81570144Virustotal results 22.95% Heodo
2020-01-21RP_8C9LAU3AA6B.docdoc c5a685afc7986b2e868818c0a531726711bd19cb5e60ed99da8ccefce4cc95d3n/a Heodo
2020-01-21DOC_46356982.docdoc b8083992ca8cf08ef3353bdea04c93eaeb2c2d9a0840119f89868e27b2261a32n/a Heodo
2020-01-21RP_UWN_010120_WFJ_012120.docdoc a02cad1bc2e1e070005d123abd1ed33ef20a502d65d597145a77c7f1983a8888Virustotal results 37.10% 
2020-01-21D5UCCOJZ879U6FV.docdoc 771aeae2ed024260630905213e772b48fc8a0d525c1673edd92ca83a282b17c2Virustotal results 33.33%