URLhaus Database

You are currently viewing the URLhaus database entry for http://www.galvensecurity.co.za/language/vanjq7-05392879-5865239-vxx9fcxk2t-knknc1axx9q/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:295263
URL: http://www.galvensecurity.co.za/language/vanjq7-05392879-5865239-vxx9fcxk2t-knknc1axx9q/
URL Status:Offline
Host: www.galvensecurity.co.za
Date added:2020-01-22 22:47:09 UTC
Last online:2020-01-25 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-22 22:48:02 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:2 days, 3 hours, 40 minutes Poor (down since 2020-01-25 02:28:41 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24R_BGS_010120_LGN_012520.docdoc 77a6062cd36b8820274aed8fbcc37f7964c2f2d40cbd50aa7254f997553cf6d9Virustotal results 36.07%Heodo
2020-01-24DOC_ZLM05OBOZRE0.docdoc 8fdf03b30cc2c9defc6420c8be22ae8d39d650d05fd6049ba7bb2433befa8266Virustotal results 35.48% 
2020-01-24REP_BMA_010120_ODG_012420.docdoc c2cfa510e4a7f3dadf221aae350a035e4dfb095dd22c45dc489f9f8a83b883cdVirustotal results 30.16%Heodo
2020-01-24MP5759995895EP.docdoc 449eec3362b0e15a7cd00d2853d95be962bbb0a5f1b285f96164f4515275c18bVirustotal results 31.75% Heodo
2020-01-24I_99531183.docdoc 03523a72a1baf447cbfd05847eae4a01759ab28ea97d963d99486cb70768a299Virustotal results 26.56% Heodo
2020-01-24QP6788744619SB.docdoc d1ce33fa24c35c0d836fed807b804f901f3a90d80da0bb29588eaa9945795324Virustotal results 26.56% Heodo
2020-01-24CYT_010120_OWP_012420.docdoc b451ca27de63453de948c2bff97c43cfca5cd6c2f080aa4f260cb5c313b38db0Virustotal results 27.42% Heodo
2020-01-24ST_PO_01242020EX.docdoc 17d0af0278265e68fc7bd551aea53ca47aea8455884650d045407cbddf0d0b96Virustotal results 26.98% Heodo
2020-01-24LBR_LS8269947172DI.docdoc e848ede38876ef2dedf485fe2818f53dcfc4a4cdd21062ce8ff7a53d2f8e32b1Virustotal results 26.56% Heodo
2020-01-24ST_366507139.docdoc 059d70cb9f95a63944ca0932ea90cec44e20bdd60b0ed2717eb60f69cebcf3a0Virustotal results 27.42% Heodo
2020-01-24I_PO_01242020EX.docdoc 4dacc05974d23254cf831f04198add8f854504208e61ccc5df0ab3239b5eddb3Virustotal results 25.00% Heodo
2020-01-24PO_01242020EX.docdoc 1d68cbe62d70c5b7fbe6734d44843756b6bd6b439dbcceb32ec02b1c31a9e0d6Virustotal results 25.40% Heodo
2020-01-24RP_005743083987313065777.docdoc bc8bc48482786ef3eaf2ec81adf2abd9ce68aa9f1776d2dff6990e4631d62d10Virustotal results 45.31% Heodo
2020-01-24UWT_DJ7698551202JW.docdoc bedffe567bdec300da442d0c24e30f94beca6e30401410ac906a60946b63fe9bVirustotal results 46.03% Heodo
2020-01-24REP_H1GF5SVPW61GDAR.docdoc 2c4b0f8d4c1eaa6adbac77b21a05ff32242cab116fc252c21c67fc0ab51ba110Virustotal results 46.77% Heodo
2020-01-24SW_IA7593580606CS.docdoc 73da5cdf0f98ea4dbedb8219ddd051b4d7a04c9750fc4b1d6f9c8e4f9e218c53n/a Heodo
2020-01-24RP_819836393599339572.docdoc 2caa93025cda12c41ce7d3ac89a2e81c7db0a40a6571fb3cb406c98e2ec71097Virustotal results 44.44% 
2020-01-24FILE_NGL_010120_ZTY_012420.docdoc ec1da54265100311f4df396c8990940f8a6ff623eb2544ebb860e0283a23b36dVirustotal results 41.94% Heodo
2020-01-23DOC_PO_01242020EX.docdoc b4b863bb79c7f22ebbc9bd5183fd67c6b9e020e15eb75d24fbb6179a57e16125Virustotal results 38.33% Heodo
2020-01-23PAY_RNA_010120_HLK_012420.docdoc 44383ba280209b37ce51bd1acbbedeb0ce8a381c7df3cae05f3a624b75bad529Virustotal results 38.71% Heodo
2020-01-23PO_01242020EX.docdoc 3f8d87927f59ea59b6d236b51de0c82949aba563a480f7f4af2998d001bb9b87Virustotal results 33.33% Heodo
2020-01-23N_2845685546335181181114.docdoc fc252e63169ae12bd304670fd8a56a969b89a721a64477c2f5095e9c453dc9f1Virustotal results 32.81% Heodo
2020-01-2393487606.docdoc 1a8f402887a84a260d9e95bf23a2862212a8a358390d810e04c581f7790bae58Virustotal results 31.75% Heodo
2020-01-23RUG_M5TQYQUA.docdoc e0e3cdf9e4170877354366d8cdc73b61a15fd748d0ec89e122f711185207fcdeVirustotal results 30.65% Heodo
2020-01-23VEI_OT4440332250MW.docdoc 03975584dfaf6b80fcf9852d8d6ba600c00c3df57f762ead0f0f754cf5044cd8Virustotal results 30.65% Heodo
2020-01-23PO_01232020EX.docdoc 483ef4ce0441ee67ebba0abef39db9f75d667a9e8fae0012eab7a642a993ba0eVirustotal results 29.51% Heodo
2020-01-23REP_PO_01232020EX.docdoc a4c0577378d402ac5f86199f8f56fae0155148be1ee3e0cd88bcc3dad348604bVirustotal results 27.42% Heodo
2020-01-234779161716656225318140.docdoc e81dc8d25679f4fea9a21338bd9612d079418003d3304029950f146696624ff7Virustotal results 28.33% Heodo
2020-01-23RP_69634555.docdoc 667a70d5b2b7840b6e7668f011e10182bbd2103b7885111ed07392813d2af6d4Virustotal results 31.75% 
2020-01-23PO_01232020EX.docdoc d04b22b5e4cbcf06261ded472aa57757057ac06395640fee8f32412a892bda48n/a Heodo
2020-01-23ST_EUR_010120_RBZ_012320.docdoc a340d8ba5f7367085e1773a5d0349ecadd71bd43d775d96d697126bf76b76d4cn/a Heodo
2020-01-23REP_PO_01232020EX.docdoc b72512ff4a24eb8b09ee53a152d32058ce1323bb3c767647cd3d120361a21748n/a Heodo
2020-01-23ST_TU7088624986SA.docdoc e0d5b5e788d2707e296ecee76f68c8c2ec1d9df9115ebabe6f14a1251cb9dbc6Virustotal results 20.97% Heodo
2020-01-23RP_PO_01232020EX.docdoc 260b5a47eceb11eaeaddda02644c85294da44e3eaca951d45152e1db6b9f1c79n/a Heodo
2020-01-23PAY_42556826.docdoc 9cd39ce28644fb0f4e0e7dad49fed36f777b06e6950bcd98c30eb410e42cfc5bVirustotal results 20.63% Heodo
2020-01-23FILE_PO_01232020EX.docdoc 05e162a0d24bd68b78e4294e1c15207b011c962fe78edc0513b77b7cc37a9091n/a Heodo
2020-01-23R_YY8738535670MJ.docdoc b81a60006f912bcf5104d693656d3f0fbba61317a80e61acfcb081eb86db1fbdVirustotal results 31.75% Heodo
2020-01-23ST_27FVDCM.docdoc 2d73bb5f63736ac8e96883c99545a14b73653318cc7df72423fc817579e539f2Virustotal results 31.25% Heodo
2020-01-23ST_AZY_010120_TRI_012320.docdoc 9af2280771f435166b53ce4682f2cedf9072877a0fd338920e1a7ae4434c47caVirustotal results 30.16% Heodo
2020-01-23INV_2589110252123998500.docdoc e63aa1c3401d847d86e7d7a0183b1b09932060991feb79d6e2b775a27f30c36bVirustotal results 30.65% 
2020-01-23REP_SFY_010120_KLZ_012320.docdoc c78e3b88c08a9425cc9d6043a9d20e85c160e556a37f57f3f2515cb894c33316n/a Heodo
2020-01-22FNIB_PNQ1Q2C7.docdoc 29487cc347b96694240c5003b2fde7f8e509ac63ea9365249aa1a23c122502ceVirustotal results 27.42% 
2020-01-2259NOZNZ9.docdoc 2283fcb7e382a23499f2c6f7fe9242ea357669d7719bbb09cf06fbfa0f6439dbVirustotal results 28.12% Heodo