URLhaus Database

You are currently viewing the URLhaus database entry for http://goharm.com/wp-content/disponible-sector/bwn-lf2m4s2j-bwn-lf2m4s2j/v3oSv-3pj20N6968Gnd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308941
URL: http://goharm.com/wp-content/disponible-sector/bwn-lf2m4s2j-bwn-lf2m4s2j/v3oSv-3pj20N6968Gnd/
URL Status:Offline
Host: goharm.com
Date added:2020-02-05 11:11:04 UTC
Last online:2020-04-17 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-05 11:12:06 UTC to irt{at}nic[dot]or[dot]kr)
Takedown time:2 months, 11 days, 21 hours, 35 minutes Bad (down since 2020-04-17 08:47:57 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-07CONTRAT-p54pom7q23.rtfdoc bdf5c8be5ef48385c71f424c912523c3cfe6ffa0215d080cd8464821aa66fef9Virustotal results 24.19%
2020-02-07OFERTA o43m2q2408p7p5.rtfdoc 9f2b441a576b8b1d1a2af975d5d53633a4000ab8ca1f6df2e88312e175a47595n/a Heodo
2020-02-07OFRT ZZ860765329240.docdoc 43f5a651e8c734d8fe1d40aaac30af8bdbac2fb7b25fb416531ce7f95e056037n/a Heodo
2020-02-07CONTRATO_665806.rtfdoc 8f3a0e19e00397efb39708dacfd129d2722146fa6d169e6a7c601c0cc02a1359Virustotal results 24.19% Heodo
2020-02-07Oferta 02_07_2020 F278525.docdoc 5480139ad1a7d156879a92736b3feda1f6e9bb49c6b7bd8b92471e76e92fa60fVirustotal results 43.55% Heodo
2020-02-07oferta_p4m7959216m928.docdoc 45460794b9f09c81f86ec924d5e4d685810a07f8536e4984b02ab6cb86557b19Virustotal results 44.26% 
2020-02-07OFERTA-DF6730701284.rtfdoc 60a2db35f6a200f89387811492bf70f40551c72578c80be36bc21dc7abbcce67Virustotal results 43.55% 
2020-02-07contrato_02_07_2020 C2288.rtfdoc 98fcf05bd2eb83cb52ad5e78c3328ed32c5de84400c6e2f2dff66dfed49a01eeVirustotal results 41.94% Heodo
2020-02-07OFERTA_89573.rtfdoc dda86e610dc7cd7c6dc32877c7933dc7c341e6e57f35219c82c674fb4f85f7b4Virustotal results 35.48% Heodo
2020-02-07Contrato_0169.docdoc 4de743bb5a807944570907fec4e4ca12efe2016c5c50e04f718ed117b26a76eeVirustotal results 32.79% 
2020-02-07oferta I201759320266 76543.rtfdoc 4ea3c2e1f6d051de33d5c37e2dc88e621ad3ce6404691932b5787393c76fe8a6Virustotal results 30.65% Heodo
2020-02-06CONTRATO-02072020.docdoc 4810daa4ccbb49abbb0e59e495561bb59b892d44fdb400afd61c2b9b78e047deVirustotal results 29.03% 
2020-02-06oferta-02_07_2020_CDD87987.rtfdoc 76ed65f4166ab70a504fa0c58b5fa4d5afbbdf92c3b7770185b137ac87aa37edVirustotal results 29.03% 
2020-02-06OFERTA-727404639892521_18758.docdoc 0f9546ef0fe98af36e43a06ae58080335e7051c19f85fa72157d75d7e85f12c1Virustotal results 26.23% Heodo
2020-02-06OFERTA-02_06_2020_F355480.docmdoc 903eadc1bcff1ede5e8a4887d539b907837b35b6ae79a1b7cd200ec455cee00fVirustotal results 27.42% Heodo
2020-02-06Contrato 9n9375oo1.docmdoc 0395137796e0f9fe7c273562138c7e5f0c988214841e6ed4cda2e3978a98f1bbVirustotal results 29.03% Heodo
2020-02-06Oferta oop16152p.rtfdoc cddfbd7b249d0e0ebb3f68697690544c6abb69af1cb46f3b74c24cae2d3e528bVirustotal results 29.03% Heodo
2020-02-06oferta_I8388518 4688.docdoc a1669f5f97291a5acd8d21be96ed7cfd97c28979e0e6bba5a111c21c657b6c71Virustotal results 29.51% 
2020-02-06Contrato 46nm0oq21002.docmdoc 33b5e2a31a3000b7a3251be5436e451986568c1a93ace24fab40817786f5a2e5Virustotal results 27.12% 
2020-02-06OFERTA XV575513_901654.rtfdoc 9d589a2e6c2556df3dabf97bfb5d53fbf92b2303d2b44b92b864eea6df244f80Virustotal results 26.23% 
2020-02-06Oferta-811310.docmdoc 65f576b0c1da324a19bbebf66196d8600be044aed153c7d74c6df1ccee6296f3Virustotal results 22.95% 
2020-02-06oferta Y8832820 0243419.docmdoc b99125a74c2d36d2875478ee03096a69ad74f272c1ced98d2e22ea0f2a3d3191Virustotal results 22.95% 
2020-02-06Contrato_q704po8p350.rtfdoc 6b1d90ff1212f95e6fb72180e90a64d316ee24b22f2803c46dedaca64ca09914Virustotal results 22.95% 
2020-02-06oferta 23563254.docdoc 413a1918fa059d5be9e47bd9fb404c1f58c2c5262e3c2f4371a88f4cab9a9c93n/a Heodo
2020-02-06Oferta-T24973673.docmdoc 54d44a585a5b93e5478ad5ec770d9c665bee492e4f228946b91312637444ded4Virustotal results 22.58% 
2020-02-06CONTRATO 179554727586-35368318.docmdoc 27a76dcb201fe799d3a072e18e4fd972ce044a7c3cd53dea83b8215ce7fe22dbVirustotal results 21.67% 
2020-02-06contrato_NZ178035.rtfdoc 5c3ce056d5c4c031e62f29306f27698d258d673ab890eaf2c2bd06487933aa00n/a Heodo
2020-02-06Oferta 863461_0160126.docmdoc 9bf2c6a167cdca17cacba485a4e8dbbc600518a91fb3286401f7b387123b2944Virustotal results 32.79% 
2020-02-06CONTRATO_o20305649m8m31.docmdoc c7662c41a76803dcb646c8d920e316033baf7eaeda42b42305d4bab1a3a49fbeVirustotal results 33.33% Heodo
2020-02-06CONTRATO_L160720-6959071419.docmdoc 43e38902740c39567550fd0e4c87c00947c5fe577765eb00051f0212c05d7cabVirustotal results 33.33% 
2020-02-06contrato 02_06_2020-03408973254.rtfdoc 00788bb2b24d0e0cb6eb61a72e29440b474f722cd5c10a79b29d02bae8319929Virustotal results 32.79% 
2020-02-06Oferta-96907016467.docdoc 74491fc6dd7ba85729f150a091baf5019a4a9cfcfa8e7bb6d450c9edf7762fb3Virustotal results 32.79% 
2020-02-06Oferta_1H0302197 25369744.docmdoc 77016ff9da8e219908f060ccb135597a6d365ce13a53cb4f40e13ec91bbc37b3Virustotal results 32.20% 
2020-02-05CONTRAT-6A282695377573 0741377.docdoc 061b77c1354bff1d5cafa4e10d903ee5feb16bb91c295298444e056ffefd1370Virustotal results 26.23% Heodo
2020-02-05contrato HT758362.docdoc 85d825b74358c12b84824b2d46cf048e3dfe836a8c320d88d301331a46e62ec2Virustotal results 27.12% Heodo
2020-02-05OFRT 7078.rtfdoc 1566745273aeac5249400c456f82b70e870825a50ee2457479f734c7686dfb54Virustotal results 26.23% 
2020-02-05CONTRAT-02_05_2020-4B09196.docmdoc 79b3a51440b181671112045cb234739a360169bc4c6ccdb30a3907a50a055963Virustotal results 26.67% 
2020-02-05OFERTA_02052020.docdoc b03e332d75fae1c213d41742abe758225f46a5ae68755f6d57dd3cb44326312fVirustotal results 26.23% 
2020-02-05CONTRATO-02506837529.docdoc da0b1e331a89bd28e4338a886d224c01e9194a764a6ded30bac8b16670a589b3Virustotal results 26.67% Heodo
2020-02-05CONTRAT-515n0702o.docmdoc 20b603562ad65e466c27733e3ba8368c3ed83caeec165555f4a935ed0cc6d4b1Virustotal results 26.67% Heodo
2020-02-05CONTRAT 02_05_2020 B37752.docmdoc f4dbeab20387f793a3dd0b39d717b27c6787e02951aa4ef7cfeb0d156b75697cVirustotal results 25.00% 
2020-02-05Oferta q5o67n74o508.docmdoc 6228be42f808ff1c2d59dc6df839b24c07a9e9640fffea33d21e69f3b2765a69n/a Heodo
2020-02-05OFERTA-02_05_2020 EG7340314.docmdoc e017e89646b0d091bc67504f4318ea078b5a279edd898f418ff735e40c432e28Virustotal results 25.00% Heodo
2020-02-05OFRT-02052020.docdoc 4d87879312946df36ab67edcf0f7a77c8cb8051a479d2639049760e4df5a22bcn/a