URLhaus Database

You are currently viewing the URLhaus database entry for http://preview.go3studio.com/testMenuApi/7t1mcx899kgi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:304432
URL: http://preview.go3studio.com/testMenuApi/7t1mcx899kgi/
URL Status:Offline
Host: preview.go3studio.com
Date added:2020-01-31 22:11:09 UTC
Last online:2020-04-11 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-31 22:12:12 UTC to abuse{at}lightower[dot]com)
Takedown time:2 months, 10 days, 17 hours, 44 minutes Bad (down since 2020-04-11 15:56:57 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01INV_WZY5RRE69.docmdocx 8ef3a86989c9654cd7b0914ab743459ad98702ea960612c66e331f858a791eb0Virustotal results 45.31%
2020-02-01YB_52H4OZVXYNNDV3F.rtfdocx f63851bafa8cd5965f68266232fd81bd91e82f6af4313b73ca2a24c0897eea9bVirustotal results 37.50% 
2020-02-01INV_PO_02012020EX.docdoc c117593f754a9dafdfb9c3bcaf46d70eda6bedf7ee811038f00aad85aa541355Virustotal results 37.50% Heodo
2020-02-0115953786.rtfdocx c28e49241a60da95ef55d89ceb6b7617908683847895c6b29aaa3a16a01e81d1Virustotal results 36.07% Heodo
2020-01-31KVM_020120_PXL_020120.rtfdocx 6c30f2c3483bdcdb6544377812c9a3188ebba7111f6c59b5f2c2bcee90a0cdf3Virustotal results 37.10% Heodo
2020-01-31EC_FN5141361964SP.docmdocx 34fa1227f7140a4738f187b9e0a6d1eb440f57b91eafa01c146f3200287b075dVirustotal results 34.38% Heodo
2020-01-31BAL_PO_02012020EX.rtfdocx 546bd7aa4c29034b9a990363b9f75d92cc2e869e0c02198307e03a821014c630Virustotal results 31.75% Heodo