URLhaus Database

You are currently viewing the URLhaus database entry for http://globdesign.com/cgi-bin/rHfvyiy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422103
URL: http://globdesign.com/cgi-bin/rHfvyiy/
URL Status:Offline
Host: globdesign.com
Date added:2020-07-30 17:36:07 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):No
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-01Inv 7 602140328.docdoc 56916942bc59a1ae0cc030beaf907b54631390e0a5fa7d75bce1f120df88d843Virustotal results 52.46%Heodo
2020-07-30INVOICE_EAOQ5167 217345032.docdoc 4bae1b817b5f647d1da6fa839d95dc1a747069f8cb885d0a402df30d268b6b5cVirustotal results 48.33% Heodo
2020-07-30invoice-ACY5495_5691458.docdoc c26948855f4ff48cabef919e4728ee8fee5fed3d1c0a191b3bfcf7607a57e820Virustotal results 48.33% Heodo
2020-07-30invoice-6-58820035.docdoc 2c12a7e0edad866945a8690d526d40e53fb973708e021efcd252bd1178c14544n/a Heodo
2020-07-30INVOICE-UT0 37452442.docdoc cc06acb431a4a55c35a64b9125b3b8637e155d4685b1e3f1593df6729c84560dVirustotal results 48.33% Heodo
2020-07-30InvoiceDP4084{:REGEX:.docdoc 8bfad89deb0c7bc99a6838342f6f6044ecf0031ea21397874c52b3b2a616786eVirustotal results 47.54% Heodo
2020-07-30invoice-KP4 993948871.docdoc cafd2c780bab54f0e196d1960af4f5ea207d883461efe818b373828eb21e92dfVirustotal results 47.54% Heodo
2020-07-30invoice ERCM3_186441.docdoc 796909dd292cb26f7fd13c689c83321159681e5900bd3ffc094363465611696cVirustotal results 48.33% Heodo