URLhaus Database

You are currently viewing the URLhaus database entry for http://www.giffa.ru/wp-content/closed-mrQD7d-KOkXdW7nFhEHVy/6940522-ZwjsURRL-profile/501868-9wG4bryRuxn9jwJ9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299747
URL: http://www.giffa.ru/wp-content/closed-mrQD7d-KOkXdW7nFhEHVy/6940522-ZwjsURRL-profile/501868-9wG4bryRuxn9jwJ9/
URL Status:Offline
Host: www.giffa.ru
Date added:2020-01-28 10:03:10 UTC
Last online:2020-01-30 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 10:04:03 UTC to abusencc{at}interserver[dot]net)
Takedown time:1 day, 21 hours, 58 minutes Poor (down since 2020-01-30 08:02:03 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29List_NZ972666.docdoc 0c899fbd963450fdf0d3d487fd91c0ef00e8c4191115d99d58a6b75476b06254Virustotal results 22.58%Heodo
2020-01-29list_2020_01_30_8231459.docdoc 4e2697404537ce6a8ec19caeb51f6ab87704a57dde37bc9814ed69ace7328995Virustotal results 41.27% 
2020-01-29MES FUJ132.docdoc de39c0b0ba341eb6a6c1cc3bff5a3dede93907976a77563396df5165f422ac7fVirustotal results 33.33% Heodo
2020-01-29dat_20200129_SJ6191.docdoc c5bee30abc8770da84f8bbd7f058c8345679dc510a04e67ae7a663820250019dVirustotal results 32.26% Heodo
2020-01-29file.docdoc 49725f6641477d5fcdc1933e66eb652922a1e1264277a6aef8069967eb0084f0Virustotal results 30.16% Heodo
2020-01-29mes 2020_01_29.docdoc b09c8d39fe17d600ac2beffd9540076f55d944b41ae3c11b26600252a272b3ecVirustotal results 26.98% Heodo
2020-01-29list S485.docdoc 5ae7e30b55476614975a3dcc125e78cc5e84eb3a8c413ce9a42be9d99ed7150fVirustotal results 24.59% Heodo
2020-01-29rep 482498.docdoc ec9b05ca4512e2e594339751e698ee57b1373c749a8c8b26cbe5c79dc1e978ccVirustotal results 26.98% Heodo
2020-01-29rep_J37520.docdoc 7fe7d585439b5c35ae237be440c87a62cc89bfb0bb98bceb800b85b6aefc7ce6Virustotal results 27.42% Heodo
2020-01-29LIST.docdoc 681cf7e6e085dfaeabad5bbaf2adc9194fff19044df752c7adbfd19077ace1e2Virustotal results 26.98% Heodo
2020-01-29Doc-YMI2536.docdoc 8c178af12cf53e214a99e4c9125f73724ad6029bfb2e095b3c6257cb3a25109cVirustotal results 26.56% Heodo
2020-01-29Arc-GTN020796.docdoc 9e66ad03e7885710b534addc2f0c5637987970b3c6185b27cb42a4fcfa06dfc9Virustotal results 24.19% 
2020-01-29List-2020_01_29-2049.docdoc 44a4ef90160d6dbd60b003ccbce9172073b7b939f37503efc4fc431e906010d8Virustotal results 23.81% Heodo
2020-01-29list_2020_01_29_ZE1176.docdoc c2b2cd3b90f72db2fc325fdac1161626765153b7cb874ee42bea9fe3caf0eb6cVirustotal results 25.81% Heodo
2020-01-29Mes-20200129-08420.docdoc fb8b1e69574f8ec2121b612f1339a516d01536a2174f432585e94c98fba7ab8bVirustotal results 44.44% 
2020-01-29arc_20200129_7865.docdoc 085777a85dd9b9d62ecf918d0cda586ecae8d0b32af5aa6182d85c77a8a571fdVirustotal results 42.86% Heodo
2020-01-29Doc_2020_01_29_VOC1118.docdoc d7bcb9c0a8ff27400a3e2a846976dd062129a404c432e34e4fd885f734300144Virustotal results 44.26% 
2020-01-29LIST-2020_01_29-3591.docdoc d0587297f7b5699b364592f59c0d93057b42defb42c714d6381d54a6142953edVirustotal results 44.44% Heodo
2020-01-29DAT_20200129_UVR676.docdoc 623303d6b597c92e43276ac21c6338a64cb078760e9a74bd08050666a3aeca13Virustotal results 43.55% Heodo
2020-01-29Dat-14984.docdoc 85359d87138be58de0c049e5c520f4de37adde9310893971769a0c640ba0a0fdVirustotal results 44.44% Heodo
2020-01-29MES-GZX494.docdoc 99f4cbe6a9549c0dd8d99cdbee3c8ffe2c85d61f8a3cc94d1e57a962e4497be1Virustotal results 41.94% Heodo
2020-01-28Dat_SRQ608.docdoc a5b8d8907e0cf3e09b5a2e7bd993dca67975830d84b0ff832334fdafe4f656d3Virustotal results 39.06% Heodo
2020-01-28rep.docdoc f2a6a0283ff20ad3d0855ce7825d84920a0a27c55825a5a5b9ba91408388a402Virustotal results 41.94% Heodo
2020-01-28file-20200128-R123610.docdoc d92bc4efa28b232e6331a4e9b5f75992659ad3e64268f5adac60ea14f9932f5dVirustotal results 36.51% Heodo
2020-01-28file 2020_01_28 WF1565.docdoc e6384df1ef6040795e8d6521f54723cd118a6b6cd4a007f0ca96e3558f55b81bVirustotal results 35.48% Heodo
2020-01-28list.docdoc 8bdb7e87fcf964c2eb8aece266a77d744adbde96cfb76da2e22822dff63e0ee4n/a Heodo
2020-01-28arc_20200128_TCW531181.docdoc 905563c6be86ed6e853e1f2bc9f4cdffa60c74647a96e1fe871a53a585ae3a10Virustotal results 23.44% Heodo
2020-01-28List A740448.docdoc 7d66af4b1a956e0ddf0d0eb592a01b7506541b769b54272d7882c872b2019922Virustotal results 25.40% 
2020-01-28arc-54144.docdoc 2fac5572f786da32ea0810309138075fa6d25b8fae0f0f92a0c7e539353ca05eVirustotal results 23.81% Heodo
2020-01-28arc 2020_01_28.docdoc 45f4837dd3c4164db2df0fc600696eb225eff9a66e0dadffa9ff07c9f797a8e6Virustotal results 22.58% Heodo
2020-01-28LIST-553.docdoc e3ba2559956e5915407cc1fb85cbb6d4a50bfb9d028a5ba9dd33505953aa5ddbVirustotal results 29.03% Heodo
2020-01-28File_2020_01_28_P18413.docdoc 1ac8d894b4e2be7cb2d7fc3dee2346677c5fdc5871be74589848518155c5ff8cVirustotal results 25.40% Heodo
2020-01-28MES-2020_01_28-3705.docdoc ef8c80e3aa87638499e2d08d35b90a6e18b330d7993044c080c7c54a9e4953caVirustotal results 22.58% Heodo