URLhaus Database

You are currently viewing the URLhaus database entry for https://gtdesign.ch/cut_r_37ul9/payment/i9k97o/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421461
URL: https://gtdesign.ch/cut_r_37ul9/payment/i9k97o/
URL Status:Offline
Host: gtdesign.ch
Date added:2020-07-29 14:16:05 UTC
Last online:2020-07-30 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-29 14:18:02 UTC to abuse{at}hostfactory[dot]ch)
Takedown time:22 hours, 9 minutes Good (down since 2020-07-30 12:27:51 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30MVVA_9PPBS8E0M6XTT.docdoc 18190f715f0c05ac6e28e0fa78c58fe7a1f6a0733be72ea6494e4340611c2194Virustotal results 40.00%Heodo
2020-07-30PL9HO32DWCJ.docdoc 839a966436672446a68fede0e400e5e124c90bae0e6166de896bcc790899a376Virustotal results 41.38%Heodo
2020-07-30V_PO_07302020EX.docdoc f69221bcda2041011a5346b30da22aac2af5ed52c961455f6529339faa519dbcVirustotal results 40.98% Heodo
2020-07-30RP1YUM1IZ.docdoc ede4d3f3f62948285291afc16d31abd1c17c5f9db3ceb0e376151913977749cen/aHeodo
2020-07-30NBZ_070120_VKR_073020.docdoc 44e198d158e76b7f97f737aa5b74de20f159ad7f13b41608d7ef9b793201cb62Virustotal results 40.00%Heodo
2020-07-30DOC_91369082.docdoc fd2c870bab01edcb6af885cc070a9ededf595bb1b3613b83fb9313a3caf5e014Virustotal results 40.98% Heodo
2020-07-30FILE_YSN_070120_JKW_073020.docdoc 47c48111a87bb2eaa02eeea65c8d80648d437d73124be5135ae75b968b0ee41aVirustotal results 46.77% Heodo
2020-07-30PO_07302020EX.docdoc babf9bbe00be892ecb7b1d8774cc33a3bae77c5b3d414f640c3f136365acea11Virustotal results 44.26% Heodo
2020-07-30X_90037860.docdoc bc06aea71e46ed5e64ca7cf24f3b794f46b9371d1df13696a3dfe4096a3bb6acn/a Heodo
2020-07-30BAL_WLB_070120_CCH_073020.docdoc 7b459b39196f8a02d1d76081fd57227679c791e3cefa667a2264e36cb79230aaVirustotal results 45.00% Heodo
2020-07-29FILE_PO_07302020EX.docdoc 0bb41da3d7f6f972f06276bd500f8c8c520928871f48a3751835a23497658939Virustotal results 44.26% Heodo
2020-07-29FILE_PO_07302020EX.docdoc 247650d657b93cdc868b938cf09c549175ede9f04050b49bf731bf4187040030Virustotal results 44.26% Heodo
2020-07-29Y_9188497750227416504068338.docdoc ea1d07ae55467195b610358c91f9d4cb4f280d055e9a86158339ca3bdba8ca15Virustotal results 38.71%Heodo
2020-07-29PO_07292020EX.docdoc 018beffb57923eb38dac054bea5fce0c4e9aca87f1971e226c7a7bacad5606b7Virustotal results 36.67% Heodo
2020-07-29FILE_PJ4359434713HV.docdoc de8f1977525fb3ecc4525e54abda09a1e03d7adeaa92d60616d631ebc3bf604aVirustotal results 34.43% Heodo
2020-07-29BAL_KPKZ4OI8LT1.docdoc 9e9bcedb989bda32fb610816c436af0667eb5c22bb6a3d20fb4bd426dbee88adn/a Heodo
2020-07-29R_PO_07292020EX.docdoc d92e4dd34381a1b20f114dc122c6f542aebe6d7633579c8b6f1d934f25666201Virustotal results 34.43% Heodo
2020-07-29PO_07292020EX.docdoc 0cbadb841dc2c7d6152c653d711cd5ac8ca759142231e728789ff256b2d9a7e4n/aHeodo
2020-07-2941494021.docdoc 9c24d6fd85470958aea67d26f6293c5d8cb091ccac7299fcc6c243ff90382cben/a Heodo
2020-07-29FILE_YU5653062939YK.docdoc d32b9efd8f82427e98069b5a06bcde907a9f906406d27e85ff7741cc7d338febn/a Heodo
2020-07-29AED_070120_UTX_072920.docdoc 3681daa87fcd7273080d8c9943be0e8f549075f23e2ceef7e89875649ad5a0efVirustotal results 27.87%Heodo
2020-07-29PO_07292020EX.docdoc 3c74f7013284b63dde1a5ab03d7b238ca960e7be7847fe31b343b04030d1c029Virustotal results 28.33% Heodo