URLhaus Database

You are currently viewing the URLhaus database entry for http://jointhegoodcampaign.com/QxvIEKBmi/report/wmebw0qyx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:426504
URL: http://jointhegoodcampaign.com/QxvIEKBmi/report/wmebw0qyx/
URL Status:Offline
Host: jointhegoodcampaign.com
Date added:2020-08-06 20:57:05 UTC
Last online:2020-08-07 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-06 20:58:02 UTC to abuse{at}gigenet[dot]com)
Takedown time:18 hours, 38 minutes Good (down since 2020-08-07 15:36:11 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-0793088528.docdoc 9f76d7029906d2253cc2cb93dd63a25923a2b2878c58c02c915cf9ca2d5b3ba6Virustotal results 24.19% Heodo
2020-08-07FILE_FWJ_080120_OMZ_080720.docdoc 8b8e47ea740122d956b050a9ae147e3fed0f577bb4807b577fc5e491a0d3a045n/a Heodo
2020-08-07INV_40681714.docdoc 83acfc01aed8937375c8bc98733684caaa595766301ca229d41af7b2c3966921n/a Heodo
2020-08-07REP_CT1EQJ4Q6EL.docdoc 22c64ac7a89ab8a195cf01ac7fe65b95cfb560eb85d98fe16f7b5b0e5db27538Virustotal results 24.59% Heodo
2020-08-07FILE_686157481264924.docdoc 56aea8dd28bb9f893ec49cf3e5bd73eb7dafad62fb12c5f1431b94e2bbd02986Virustotal results 22.58% Heodo
2020-08-07FILE_261797683.docdoc 4c70f0ff52d6a0016178754d0223340a2b83c622c1be0d1a49656b744b4775a4Virustotal results 24.59% Heodo
2020-08-07BAL_01962375549.docdoc 8ce364928dc868c937733a95a34e468073564c6cd0ba8210831635ed02af1694Virustotal results 22.95% Heodo
2020-08-07VB_LL6859865528FE.docdoc 9003022268d0174373813a27761795b85bdc4972564810056d592cb380ac81f5Virustotal results 22.95% Heodo
2020-08-07FILE_LXV_080120_HQY_080720.docdoc 848159e2d023ddbb3136a1a30ae91e9dad7900c86b3efd66d8670436e9bbea95Virustotal results 24.59% Heodo
2020-08-07PZ9SH6BOCCXLXZW4.docdoc 69cf12497af1ec0ca4f43e532290b155bb9ccce8026409b6f052af96d5e47317n/a Heodo
2020-08-07FILE_YAF_080120_BBJ_080720.docdoc 92b580f1a19c92e5f54c6a8e881f8b8694aab87b99e79990afba016e9a14dfe6Virustotal results 24.59% Heodo
2020-08-07BAL_48433081353.docdoc 14df5a4c49d31640d9608852d16eb2683e5d89fae28185fb7faf8eaf9c1eed54Virustotal results 29.51% Heodo
2020-08-07IJ_11UF81E23T.docdoc 4b4574331de7a4583c2a0d5eed8d114453c864e40643f51ed2a5f0547bb936a9Virustotal results 43.33% Heodo
2020-08-07PO_08072020EX.docdoc 406ba28d1bd67874bfadce37b6dd1d585a96e578e84886cf956e0e5fd241dab0n/a Heodo
2020-08-07A_HZ9526367016YP.docdoc 0c588b4ce891a265135141283b7fbdfa4f924dc8497c5762c47ab29594d3f662n/a Heodo
2020-08-07QT1640503356WJ.docdoc 2ee56c4e8d6634b957f41adcf4b67f3236267ee4fecd4a0a9262af3401bcc06eVirustotal results 37.29% Heodo
2020-08-07SK4147461705FA.docdoc 741bb5633c63b4509e3d9d2345a6f940680050d6b5cfa7593482322aa6d8f8b9Virustotal results 35.48% Heodo
2020-08-07DOC_UF5338872907XI.docdoc cc93f31c0d302e29add795820ac93373ebe03ec88d8bd1480afa134d76b5a0a5n/a Heodo
2020-08-07PO_08072020EX.docdoc 1f9e33a57b23fbd4e8d3247381170d6e5fffcd2e1da2d436898bd33877057d9en/a Heodo
2020-08-07QQW_080120_EHB_080720.docdoc 7c80a237b2801df78492bcf3d316c32159e095e648a81faaeb8fe75752a2af1en/a Heodo
2020-08-0796926152.docdoc 4b1b6f5ab3d49093211eab8cbec1b072cabe87aac46a3079e562b382bee3b7edVirustotal results 28.33% Heodo
2020-08-07HZ_SR5639053928JH.docdoc e302459e39df80f53582e6613f56b1157f8c198075ff65e2dfb5d69f336e5daeVirustotal results 25.42% Heodo
2020-08-07REP_XW6759837179SH.docdoc 70bdb576c61fd1465ac3a5c01025bd1c5bc89ac4054c7473b529da4b927c1142Virustotal results 27.42% Heodo
2020-08-07REP_KB03EDXFYX.docdoc 5a29439105e1b8230b665913a4b5de40622cfbbfbfde619777d996b4fb4d058dn/a Heodo
2020-08-07FILE_73615343.docdoc 4d0b28b1f18afa99d908f7a6d885da63d1b1177d75fe27f74fe36397f7b23a7bn/a Heodo
2020-08-07FILE_OP6694705542FR.docdoc d01c8f6276d006be38cb7a690d45041052dc157de49f18c0539bde4b53bd6a4eVirustotal results 27.42% Heodo
2020-08-07PO_08072020EX.docdoc 126ac0659681502d22c022b42a39e2cce1bf2cdf60549fe70db6f81d2cdf636bn/a Heodo
2020-08-07SLENFFL9NCVM.docdoc d1a9ffa1566f0dc17eaee7771d4b8a88af8c5d57481bdd3d57fc858cdb5faadcn/a Heodo
2020-08-07FILE_CF7230673336YO.docdoc 900718ee868a4b5cbd08d7ace9025a5fcb821139170628df57c44e739a01dad4n/a Heodo
2020-08-07BAL_21042829.docdoc afc5a12fb967ae15765a5cf5ea6b23346e63efa7ebf9ea95eb9d368a4d40234cn/a Heodo
2020-08-07WA0769751595JU.docdoc 899c39cce572efb68d609a270a70dd25f3e2ca25c21b41dcf5de57f4ed377fd5Virustotal results 27.87% Heodo
2020-08-06FILE_93327103.docdoc b2e1c3ec5988e1bff64d6dee4fbc7f379ef509842572cbd16087d6e68323d455n/a Heodo
2020-08-06DOC_XZI_080120_MRP_080720.docdoc 0f097be8beec4d73067d0d316876e2a2a733c369bc747831171968c5503a81abVirustotal results 27.42% Heodo
2020-08-06210591214395423626186020.docdoc 64dafb54d874fcf098a374328013c97ae0b1f78c8958e2865bb0d7e711db6edcVirustotal results 27.12% Heodo
2020-08-06INV_79830960.docdoc b50f11d3c9824d9d8e24907a06429c04aa7f976c1941d149665c477cf46b12cfn/a Heodo
2020-08-06INV_ZY327KPY8.docdoc 2ee0a294d681306e15289470a69d09210966baba4b985463131eaec15ea3cbcaVirustotal results 26.23% Heodo
2020-08-06FILE_PO_08072020EX.docdoc 2632f54ff03da6748cd94b4dfa7c750dcf28976dc3c60983e594c50cfd49496fn/a Heodo
2020-08-06FQW_080120_IDK_080620.docdoc f62e30784f368e990b361562f47ecfb977dcd40b625bd8bc23c74461b67c69ben/a Heodo