URLhaus Database

You are currently viewing the URLhaus database entry for http://www.gozowindmill.com/meteo/docs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:420767
URL: http://www.gozowindmill.com/meteo/docs/
URL Status:Offline
Host: www.gozowindmill.com
Date added:2020-07-28 16:02:34 UTC
Last online:2020-07-28 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-28 16:04:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:4 hours, 4 minutes Good (down since 2020-07-28 20:08:42 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-28DOC_HJW_070120_FLI_072820.docdoc a103dc583f29fa071262c2feb288b6b97f617c75199c576f034a0502c31c6491Virustotal results 38.71% Heodo
2020-07-28W_64474882.docdoc f80814e2042798f384044b4dd4222a9ed5775d8959d2e74c496b8265c4b66bb2n/a Heodo
2020-07-28RJ_JEA_070120_KQO_072820.docdoc c2dd657c048f69cc272050ec717b2c8d31cb310b02e2fc5bd920783a0cab340an/a Heodo
2020-07-28FILE_PO_07282020EX.docdoc 3615380736188fe0625c45df6c98b644a1958e722b1ba3baf0ef861c09ae4efbVirustotal results 44.26% Heodo
2020-07-28C_HYQ_070120_VPR_072820.docdoc 6594efee92704a0033126231a20cb2f665237f4dbee03f8eb23c37419a0351fan/a Heodo
2020-07-28DOC_MSAM3K2RHP8VI0S.docdoc d487cc38c856d2cb27368dde0ffc7fcd18f4c32ad9e19e44422e98d3e36d3e58n/a Heodo
2020-07-28INV_FU5263539703IM.docdoc fcfd596870c7e340769b6aa6d4da2a22786263874a73ac84df1974ecab783ec9Virustotal results 43.55% Heodo
2020-07-28PO_07282020EX.docdoc a44f6b82eb6565507c10805b73d3bee4da269d02c659532abe1f4a278c9446a4Virustotal results 42.62% Heodo
2020-07-28RR5114408286NY.docdoc 4d904aa0bdf9fdf5bcda9bac7ea6d7a0e9c1fb9a377ade0bba7b8af2db55aa1fVirustotal results 43.33% Heodo
2020-07-28BAL_IYO_070120_FGZ_072820.docdoc a40b3fcbaff7650f8e39a72f18d9b67c93a53a4adfcb8baed026d8a4a317b93bVirustotal results 45.00% Heodo