URLhaus Database

You are currently viewing the URLhaus database entry for http://preview.go3studio.com/testMenuApi/closed-zone/ZCU8-PQjioJ08QGG-2zrIe4-TuIrVsAFe1REki/50456384273095-4gJmQvJg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:301853
URL: http://preview.go3studio.com/testMenuApi/closed-zone/ZCU8-PQjioJ08QGG-2zrIe4-TuIrVsAFe1REki/50456384273095-4gJmQvJg/
URL Status:Offline
Host: preview.go3studio.com
Date added:2020-01-29 20:20:07 UTC
Last online:2020-04-11 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-29 20:22:03 UTC to abuse{at}lightower[dot]com)
Takedown time:2 months, 12 days, 19 hours, 34 minutes Bad (down since 2020-04-11 15:56:55 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31FILE_EU478315.docdoc 35399aa0198e6eaa75c1067a65180500ac022d96f6bbf51a27b2c626e65ffcc9Virustotal results 32.81% Heodo
2020-01-31List.docdoc 2c1c2bc7043d0a9e19f8082f74edb7fe6701df464a66a408969bd9825c11d16aVirustotal results 21.31% 
2020-01-31Inf-788106.docdoc 7884d18f3f7b03d25b2c27be59e9f7369250602af759ff10c9ee06c0671cf445Virustotal results 33.87% Heodo
2020-01-31file 8758451.docdoc 8ac6cda8c7b4094b736c508bc231f782f410a72cecec097edb943014ce610585Virustotal results 33.87% 
2020-01-30Dat 20200131 1569855.docdoc 239a763f4135daa2e85134d1c508ae4cbb93080fd2d98822477b7c7fdbc5c4a1Virustotal results 34.38% Heodo
2020-01-30list-2020_01_31.docdoc 78af768890683c9271a83b8fa61ac0743bbf82ff74a00a23e8b36e1cc539b664Virustotal results 34.92% Heodo
2020-01-30doc-51549.docdoc 1402be5f0bc6be6eae1ac0b206fb7faa21f605c344d9c65227326fab9fe06ec3Virustotal results 30.16% 
2020-01-30file-0437.docdoc 3e732049fca2f78ad71831abd9af6f18e3918d86239a6a91aca5f8ad2afdd386Virustotal results 29.03% Heodo
2020-01-30file-20200130-0842146.docdoc 428ec1b17869ba070cb0a44697b062e85a10d799919459fdb931a7a382596a7fVirustotal results 24.59% Heodo
2020-01-29REP 2020_01_29 0871.docdoc ff03bf7f9376aeaf634321eda33cdb1c854770422c5c08b7997dcf6d93b8febaVirustotal results 32.79% Heodo
2020-01-29INF-20200129-Q089740.docdoc ba3a6794ab4e62d08251930651695bfe9b96bfd10ee76355cdfe05349f0ececaVirustotal results 30.65% Heodo