URLhaus Database

You are currently viewing the URLhaus database entry for https://geo-foundation.vg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3795984
URL: https://geo-foundation.vg/
URL Status:flame Online (spreading malware for 4 days, 13 hours, 50 minutes)
Host: geo-foundation.vg
Date added:2026-03-14 16:11:14 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-03-14 16:12:11 UTC to abuse{at}cloudbackbone[dot]net)
Tags:ascii CountLoader ua-mshta

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-19Sydney_Config_Beta_34.jsjs c423b5364c81a476aacb0b9cb75c90b2f7762ac8578f344c8e45f3c8b4e3476cn/a 
2026-03-18Security_Release_New_7579.jsjs e712aaf403d47df55bc87d0e298efe256902990a9c1f225ca5e36a061eade395n/a 
2026-03-18DevOps_Quantum_Record_139.jsjs f09c11ada12b8bfabf76c9c48ee8cf15a4a7af848fbc99ecfbbf351764eb9373n/a 
2026-03-18DevOps_Gamma_Report_151.htmlhta 5790c9545a9e42588063c2f309dc710957efdda8ba05858f7b33d23101763ac1n/a
2026-03-18Z_Template_London_7218.htmlhta c511fc7f9049646a189c0989e1b355fb29adf4fd476e284e47f04d660a60c324n/a
2026-03-18Record_Main_v6.3.htahta 964676e342c14571397111d8916f3fc8e810c9fa0234c5e27b9dfa02f43aeb8bn/aCountLoader
2026-03-18Audio_Backup_v7.2.txthta 93eb1e8c168b57103e3511b3b3700f28a5e2b3ff62208cf84c3d5f49f86b7865n/a 
2026-03-17User_Notes_Draft_9112.htahta 691a6e46a7c0e2f2a0a5ae4e7d5c64deb03e230d0202cb4bed82e27188c485d2n/aCountLoader
2026-03-17Canada_Invoice_Beta_305.htahta 9f12096d9dac3217a38d6e93d207e2b4afaa6f08437d56547befeb517f83feaan/aCountLoader
2026-03-17Neon_Video_Berlin_880.txthta 5f585180c375d3aceb3c6e9f51d8dc2ddeedd0647c5603ca1b4f93265bea0ffen/aCountLoader
2026-03-16Dataset_School__50.txthta eaf30f74d02afd9c49791d101edec792d84db4c3623b14ab68cee84c9db07f8cn/aCountLoader
2026-03-16Nova_Images_London_5795.cfghta bb7141c427671b8df3e3678c2427d1f7547d668a324bcdb5f04607f6cb02c44en/aCountLoader
2026-03-16Notes_Alpha_v5.2.csvhta 1cc3b919978866d0a2f4d0f504914e8fd6e50bec4acea4c298ee554d51a04a74n/aCountLoader
2026-03-16Core_Document_School_7622.bakhta 0a9eef7efa92b0d9d10aaf03061969c932867848ceceb380624847a20a41d22bn/aCountLoader
2026-03-16UK_Report_Primary_451.mp4hta c9ea5f5273e8d4855c6f32fe105a4583b360e055b9ef333ed5fe9a50247d4874n/aCountLoader
2026-03-15Family_Project_Clean_8489.dathta ce96aca71f071a1c4f688b4503ebe04b53fc75bc91252e0aded2255b4a1b13aen/aCountLoader
2026-03-15Notes_Updated_v9.2.inihta 6caefde626311178946e86ebb0df91359834b3c993a8920eff5a35307421ad92n/aCountLoader
2026-03-15External_Report_Updated_1913.jpghta 2c98a7452c49ccd942303624fc9bc279711a8bba0d0a65675a3b103d9ab157f8n/aCountLoader
2026-03-15Data_Germany__13.inihta cbbd13986ddd2c3703e666e027a0c7dfb310d54299a6527212e836393e1bcd07n/aCountLoader
2026-03-15Z_Config_Germany_2846.loghta 6af3457051330059b04eea8a42d1ed8f08bf92a29ea981cd5e94b71c2f25c493n/aCountLoader
2026-03-14Project_Stable_v8.5.rarhta 8f8e3dbbdab719fad3f6748bde5301b9b3e35aea0ba58407a8e785bcfc6e9f14n/aCountLoader
2026-03-14Local_Y_Release_558.txthta 6370b0bf653168199cd75957cc1cb02a9f50871882c87a31ba091de6ba4a0d49n/aCountLoader
2026-03-14Marketing_Core_Report_295.mp3hta 36cd729674787b8d7fc0830779afc98eb5958c3e07d4cbad0d0dee5c50f70a56n/aCountLoader