URLhaus Database

You are currently viewing the URLhaus database entry for http://gsx.life/wp-includes/9jsd-lb2-09/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:295821
URL: http://gsx.life/wp-includes/9jsd-lb2-09/
URL Status:Offline
Host: gsx.life
Date added:2020-01-23 10:48:14 UTC
Last online:2021-01-17 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-23 10:50:03 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:1 year, 0 month, 0 days, 2 hours, 59 minutes Bad (down since 2021-01-17 13:49:32 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-17invoice_BXMJ7601_5497359.docdoc 61174da5eeb4a6cf230ca57c3c77a258fe8259edcedb6566fadb3a8de4f47eb2n/a Heodo
2020-06-17invoice_BXMJ7601_5497359.docdoc 0db7f4e0e5583cb3a13ce0452d4461f9d993207fdf0e03d0b828cc15c8d7dd4cn/a 
2020-06-17invoice_BXMJ7601_5497359.docdoc cbea13d411b05950b4b21a2c2135506dae3c82ff30af3965d4cc32371079d102n/a 
2020-03-19invoice_BXMJ7601_5497359.docdoc f46b9272a5cbff9ab0cc989bce4f6113a9e270c6b6bf9efd201f26ad657f9388n/a 
2020-01-26invoice_BXMJ7601_5497359.docdoc 983ddd1518361a6f16f1b4f4980f9f8e195ab46794ddb14935f83c5a93781f17Virustotal results 60.32%Heodo
2020-01-23invoice-66_64049793.docdoc 4d510b0eee8d7f749ded15111532566dea606d52e90b905dbb5d67d8282e2231Virustotal results 31.25% Heodo
2020-01-23INVOICE KI6452_555363184.docdoc d36e75fa61fbc43888ece86dae242e0123a0047b493fcf7e19a77659e8e7c952Virustotal results 30.65% Heodo
2020-01-23INVOICE TX729_518264260.docdoc 15b199f8ba35174c6082d599128c694edaf953347bc41c55212437e09f16f741Virustotal results 32.26% Heodo
2020-01-23INVOICE 4436_91418268.docdoc f1d7ec05895eaeda241064ec4901d67a5372659817cab6154477a414177feca1n/a 
2020-01-23invoice_C2_4395480.docdoc d0ac8ecbb19ac38fad42155fd608a1d725a6b9e1a38e653be9b73711c920d788Virustotal results 33.87% 
2020-01-23invoice_T3_09824398.docdoc 62b81000c333c1537dc9c8324e3f259b77c07479f39f0542e88c4349797fbf57n/a Heodo
2020-01-23invoice-4_8918613.docdoc 9a2c55b454275e9bc8438979a830af3f17f4fbf87c418b5e4405d154686e2beeVirustotal results 30.16% Heodo
2020-01-23invoice VGR2_131136812.docdoc 89d74bab511baa47fe6842a7ba93a2f93e543cb1246f0339d55added41938077Virustotal results 25.81% Heodo
2020-01-23invoice-HC675_0201642.docdoc f8a99bfbf6c324f6f76f07ae81630edabaf926a75bc2bc290abeb01d910b9a67Virustotal results 27.42% Heodo
2020-01-23INVOICE_V0766_931540138.docdoc 4b1fc8d62a7e490364bf85388322e779c0ff8a7adb39bfff5b386d7ba08eda1dn/a Heodo
2020-01-23invoice_NQF255_46049985.docdoc d91ee6af9a42e6c4c90bcc0602f6ca687bf444b88a183867d943b365bf8a7db2Virustotal results 33.33% Heodo
2020-01-23INVOICE_RM0_2896929.docdoc 3c8f1b91ec9081fe9a7f3a148e86f65019a450a87c13110116b93cfab2bd72efn/a Heodo
2020-01-23invoice_MN201_80617278.docdoc 9f60f90c850b731fbe9b9939142a6fa7f4d34243ae46124bfaceb8bd29ca97f1Virustotal results 26.98% Heodo