URLhaus Database

You are currently viewing the URLhaus database entry for http://gabeclogston.com/gkw/EfDwgF/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308965
URL: http://gabeclogston.com/gkw/EfDwgF/
URL Status:Offline
Host: gabeclogston.com
Date added:2020-02-05 11:40:08 UTC
Last online:2020-02-10 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-05 11:42:03 UTC to postmaster{at}myhostcenter[dot]com)
Takedown time:5 days, 0 hours, 14 minutes Bad (down since 2020-02-10 11:56:39 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-07Invoice-RFV500_86534715.docdoc 06d87508fcdcf413a4b6e102327dc07384be53016d108b445368d47061e25b2bn/a Heodo
2020-02-07Inv 585_965517.docdoc 3078e9310437cd53e82bb9cc5679dcb71bb06e07a0113039114b9fb017590cf7n/a Heodo
2020-02-07Inv U273_050962.docdoc 00b524435a1e4b70e1783600f6ba01545628bacd15c00154b232bd464f1de19an/a 
2020-02-07Invoice_SONT9603_533372329.docdoc 3a4cf3a7eff72f050b4414552de262c441eadb589af485908e301bf678534c9en/a 
2020-02-07INVOICE-VI1_12281283.docdoc da55d54edd3021ebaf41530e1ec8dd18fb5541bb09c3cc9d10c88e9da0351409Virustotal results 32.79% 
2020-02-07INVOICE 543_65764123.docdoc 77815318e9f6226ad493ae32d374b61c54aee323314b8bca1d0caa7ed864e56bVirustotal results 30.65% Heodo
2020-02-06Inv-NJZD989_453866.docdoc 092cafc5eaeb0e2d80004cf333e8e2d5898f25562f86323a3b31cbc1ec7b5d7aVirustotal results 29.51% Heodo
2020-02-06Inv-6_66676821.docdoc 0d52884323396c99de2994a867ebe7ccb325a7a33a6ae3317f4290517232a3edVirustotal results 29.03% Heodo
2020-02-06Invoice-496_0064949.docdoc fbccd622c1dd3d84621bbdc63975f6a57fd06bb79c310e15b469beed436acb64n/a Heodo
2020-02-06Inv-58_6966142.docdoc af68f95640411edf06350ddc5f697fa63501dad1a427026652ba7a411e87c258n/a Heodo
2020-02-06Invoice_PFS0_474412.docdoc 08a17a2ca774e5d63d00d6347ab8569354e6fc33b9e65cd55db64f088125e77fn/a Heodo
2020-02-06invoice-R480_3577473.docdoc 72cf0e1c89a577b94531a7723c3d176dfd37839c0b19bc7878c49945f7dd7339n/a Heodo
2020-02-06invoice-E76_1758998.docdoc b61644b4d4ea1d8856ff589c7017a16c5cb48d63a54cb1aa69aa19bfafc4dfb4n/a Heodo
2020-02-06Invoice_PTI576_5141958.docdoc 515c3515f3728002f957e469f6d30be479f3db347968856134e1f0287ad0438eVirustotal results 24.19% Heodo
2020-02-06Invoice CD89_770776822.docdoc be66dbd0df63fc5a8674655349f37bec9c2b0f5299fe8227dfae94c86d2ebcffn/a Heodo
2020-02-06Invoice FEER0778_2007689.docdoc d8a98e712d6775091bbcdbe1e2b1ed30135d7fcb59a9ec4ce71bd80823438c5aVirustotal results 23.33% 
2020-02-06INVOICE_8581_26308330.docdoc a8c18ebbebf32d827afe272c7dea149e8ae38cfe2ff94043e2af6e82cad5a396Virustotal results 21.31% Heodo
2020-02-06invoice_01_1981232.docdoc 67617db60beb8c4cce54db289e3d3a8406049516de95ccc8940b0d1735caa144Virustotal results 20.97% Heodo
2020-02-06INVOICE-I6515_13778737.docdoc 12368c93f93b5feac92d01c7f620337dcbaab18dc50b27dfe2a50ebae513d355n/a 
2020-02-06invoice Z55_28864074.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06invoice_YPR86_10936972.docdoc 4a620a4453c5b138b1c90c5bb3db067135faef7ad7106666379edaa77f38ae06n/a Heodo
2020-02-06invoice-155_82371510.docdoc 9eca08bea00fec73f8bdc769abf28f857d39de7d922c4d0dfd4017dc5981d2b0Virustotal results 33.33% Heodo
2020-02-06Invoice-AO8_233803062.docdoc f64c7b18189347af96b402b6f3cb3294d4dbbc7cad63748805727ac4d2a83997Virustotal results 32.79% Heodo
2020-02-06invoice-8002_708942.docdoc 7eac21ec4810b17ae186a7cb7619660833006d22ffdd25ffa44769a9474a13b9Virustotal results 31.15% Heodo
2020-02-05Invoice_RFW8222_86705479.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05Invoice-KHMJ2_10794799.docdoc 4c81ae4043b5ebb941a22c4511a4757a6a0ca5a842660b5c1ea31c57955800c5Virustotal results 26.23% Heodo
2020-02-05invoice-64_973335453.docdoc a16654e08b49b688aab6f059ee1349cdaa217e2a9035b9971ad725e145df3b57n/a Heodo
2020-02-05invoice-XPC2_312651.docdoc 0730eae02471503c7ab9c5f470a916f7f1578c78676c2c401ecd562214e25d37n/a Heodo
2020-02-05invoice_XHS9909_474751.docdoc bac64a981e3fddb119868ac4b6c14005db9b3c64f608849911d6c08947267dcan/a Heodo
2020-02-05Invoice RF6_91987419.docdoc 86dcab95611cd3f691824d94d3910ca546323de58d60f9b04d0b7959d2759a75n/a Heodo
2020-02-05invoice-CCKJ182_081644140.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05Inv 860_23329767.docdoc 6c2096cac174db584cb7ca993e635a23398f21b6513b2e690c2281f9d404f29dVirustotal results 24.59%