URLhaus Database

You are currently viewing the URLhaus database entry for http://gombui.net/bibliophilia/swift/5gzmh467btdw/795638541389992424j5ka2fhi41hj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422341
URL: http://gombui.net/bibliophilia/swift/5gzmh467btdw/795638541389992424j5ka2fhi41hj/
URL Status:Offline
Host: gombui.net
Date added:2020-07-30 19:25:43 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):No
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-01DOC_LQV_080120_LKU_080120.docdoc ef94f112784b83596fcc0ff3821d586cbc216cc3c4c8fbca25ada751d52531ceVirustotal results 48.28%Heodo
2020-07-31FILE_KGL_080120_UWR_080120.docdoc 3d313d6dc6fa20a7e7637af1c94de520d97a71eb8fb1e68a5f6f69054d801469Virustotal results 48.39% Heodo
2020-07-31PS_WCP_080120_XVP_080120.docdoc 33091d857d11e214a1b20764d0cc24a6a1abd2378b9b4e26884874ff24dc2a00Virustotal results 47.54%Heodo
2020-07-31INV_FV7793822486OP.docdoc 4834d43a503e5a10693dcc514692016c26b9084f17b258a3505a4e44ac893db7Virustotal results 47.54% Heodo
2020-07-31PO_08012020EX.docdoc 7b6a76a3a932265f067c2751c8bd6647327d0ec5bd95563dc3dc38d797a1469eVirustotal results 47.54%Heodo
2020-07-31INV_FXP_080120_UXI_080120.docdoc 1e4b706d611f935dd5aaac2b97e921c9c1df152d9dcf98127840b7c0e60348eeVirustotal results 47.54% Heodo
2020-07-31BAL_EQY_080120_MEU_080120.docdoc a6d50bad4a4674a49020c5172d75868fa86668a6a03c9c421ab1ff382c3bb596Virustotal results 48.33% Heodo
2020-07-31BAL_82881025.docdoc eb028d6cc2f640226ea486371a452928db1bc61e3a09dfedb3a4a6d213b4a661Virustotal results 46.77% Heodo
2020-07-31PO_07312020EX.docdoc d331563285211ef85352d9a878f710f4a08a7d694cb8ee0e3e3dff9c9bcf3d55Virustotal results 48.33% Heodo
2020-07-31FILE_7QQXMSYZ.docdoc 16fae461ff606c9272da9e1b49e527059fa868d3cb882b9cbfb201958608ec80Virustotal results 45.90% Heodo
2020-07-31BAL_VO0351975305NS.docdoc c99d29a720a02f4d759c1b02ad533deeddb74851d9703831b9ff236c9c87d21aVirustotal results 45.76% Heodo
2020-07-31INV_13009131.docdoc 66e9380acc03aa90e855320b6090e72cc9e0fd7c72f1fd005f08a0b3e5aeda0cn/a Heodo
2020-07-31INV_78528713.docdoc 29d891e740b344f9ec63299342ad3d46a3f4841be720defaebea50963c9aff13Virustotal results 44.83%Heodo
2020-07-31F_OYP_070120_VNK_073120.docdoc 79c176bbb127e50221aff1d14c8b4f8536dfe567f477e4608a526858824fcd26Virustotal results 43.33% Heodo
2020-07-31REP_86863451.docdoc 67eefdc61c4894365a14b80f30a06e1581213946458527b37964761cfae38cd0n/aHeodo
2020-07-3157825959.docdoc 6f6bff6803088908604240b57a6b45d3730b455d22f9db54d6c134d22a71a91eVirustotal results 41.38% Heodo
2020-07-31REP_2D2IMKJ0C5Z5.docdoc 728a0a1d8f9a71bd86dce389f0dd100a5abd819ea428304f97e35104903c0a28n/a Heodo
2020-07-31DOC_XM0564086679JD.docdoc 5e55aa28613770be2ebdf584ad12081c21c3029122a4d016325fe4c933a1fb68n/a Heodo
2020-07-31PO_07312020EX.docdoc e3ffa6100001a0b693fd8e169864c93f0a6fd4c1d3430e669cd053d7fd344c8bVirustotal results 40.98% Heodo
2020-07-31DBD_070120_MIR_073120.docdoc 819d91bf43d4c318008ef846e30372e2d6d30483faf960b16f2473b915b1b612Virustotal results 41.67%Heodo
2020-07-31INV_60008980.docdoc 7689cf53f260808946f1b53dd444210423a975b7fc7754c1fe6b04960286f9a3Virustotal results 48.33%Heodo
2020-07-31P9Q7NJJY.docdoc 322a7665dcf14c90511c88b7a62d6384296ae003dd2c586bda876768281e73f1Virustotal results 49.15% Heodo
2020-07-31DOC_46913590.docdoc 582a1cef0fa903d6e306172892c6ec7fc72bed9ac3fa49364da864273c260db1n/a Heodo
2020-07-30REP_PO_07312020EX.docdoc 1c9a402f03f531de1c9a3c3bfd29912daba7d791379b7788d23cbdcb7d99290an/a Heodo
2020-07-30WMFB_JRK_070120_TJW_073120.docdoc b920bae96043cfc55017d7a67bb6c5caac098cfce2620c6348e63cf4f7842378Virustotal results 50.00%Heodo
2020-07-30INV_TS2R2W0F9.docdoc b428976d96415b32efb7157b375160dd676b448e1566fad5dd8da634fac3cc64n/a Heodo
2020-07-30Z_57357534.docdoc f3ceae5781ace1e523935bb48baaf6484791c5cde8e95f8ce6db69f31b2917a4n/a Heodo