URLhaus Database

You are currently viewing the URLhaus database entry for http://g4osj.co.uk/cgi-bin/tyq3p-hz2ky-63/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:426810
URL: http://g4osj.co.uk/cgi-bin/tyq3p-hz2ky-63/
URL Status:Offline
Host: g4osj.co.uk
Date added:2020-08-06 23:11:05 UTC
Last online:2020-08-07 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-06 23:12:03 UTC to abuse{at}aptum[dot]com)
Takedown time:20 hours, 14 minutes Good (down since 2020-08-07 19:26:45 UTC)
Tags:doc emotet link epoch3 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-07InvoiceJLR6225121445.docdoc ebdda6969778acca315a17e1505c60c3ebbf9c13ca2b43a5092c7a32341f06acVirustotal results 29.51% Heodo
2020-08-07INVOICE 495 1553461.docdoc 737d96d343a18d4739a12d2b949eb31e758fb5e24c17b0c706997154731ac07fVirustotal results 30.65% Heodo
2020-08-07Invoice-BT99-209585.docdoc d5bff5a6b9e1f13e2206aadbb6ff705b7eb29882299b70d8f97205264cb1c04eVirustotal results 27.42% QuakBot
2020-08-07invoice-8-93053597.docdoc 3a7e162433ba4372c7e49ee5cb6bd4afb23cde7bc0f19d39edc30aa22473994en/a Heodo
2020-08-07invoice_V3_5269553.docdoc c2ecd3419f71d51acb56c7f02e685cdd46ec96514b459545a931768e2141ae58Virustotal results 27.42% Heodo
2020-08-07Invoice QYCJ3862 69795540.docdoc ab1f576293cc70428b0adcadcbb453c1525ff8bf2fa71d650e52b83ff4092f81Virustotal results 26.67% Heodo
2020-08-07Invoice-CLB34-7854313.docdoc 7dfeb76423513a843de1ab53a195cf8bad200aa2d3ee6ce674c7d01b6ab688b7Virustotal results 25.81% Heodo
2020-08-07INVOICE-QMF86-03536931.docdoc 67067a83cf054c8deccf1e31d09a2d8ed82469b2e27884e87aefef248019b89aVirustotal results 26.67% Heodo
2020-08-07Invoice-ZEEB34-192233550.docdoc 0a4b53e2bf7608fe93c60618cf50a657598aa4fc95b947cc7fa7b8fb0331d561Virustotal results 25.81% Heodo
2020-08-07INVOICE51152012.docdoc d3c7b17eb10b73fa3e2c519f2e78fbf3d2fc0ceca12fa1eb7b6d2f2b550ee3ecVirustotal results 25.81% Heodo
2020-08-07INVOICEXCU16620139.docdoc 969a99e247a7799ab5d43893d9ba53bc202dea27b3246da220b250308ea060d4Virustotal results 24.59% Heodo
2020-08-07INVOICE-2-950575051.docdoc f3d9f7cc7e604de1c96321d3ceb0e2d2099aa4bdf9e36bdc861bda08c76601b1Virustotal results 26.23%Heodo
2020-08-07Invoice-F77-49882949.docdoc ad8fc14787b10f1dd4473d7b7ec98565f64ee0493926368426c7ed261339666fVirustotal results 26.23% Heodo
2020-08-07INVOICE-703-8944139.docdoc 47293fdf01c1220f6d7faf575876adcda9a6d4c0db38242aa4fc83c1b83b8c66Virustotal results 24.59% Heodo
2020-08-07INVOICE 8 65873439.docdoc 2ddc70a408dce3808ac0e0e755aadde3d96c6db0b98b012ba7c7f1da7d3d1238Virustotal results 24.59% Heodo
2020-08-07Invoice_ZE36_0893752.docdoc 9b9f5fd8b1aebc0d02b4c27b686b3c15e170c3f2cfcb9ac0640cd337cb339b12n/a Heodo
2020-08-07invoice-45-3578587.docdoc f0f5f013ab26d3b00b287eaa4f95787de6f79f1655fdaba066db4dff469588dfVirustotal results 34.43%Heodo
2020-08-07invoiceBA82086214510.docdoc 541b63c2ab13054f7115d4b65a2a960000cad86e64e288324f1451b59513e499Virustotal results 36.07% Heodo
2020-08-07Inv-9214-4990087.docdoc de93a0a27c259f2d8f7dc6f4485190c9c1b9b7e79fd09db2824521bfa33da96aVirustotal results 33.87% Heodo
2020-08-07Inv-AYD02-274380.docdoc 3dbd6983aefc42a5197e52a2463a24ae5d94ecab6a499a4c0607773944c3bbdeVirustotal results 29.03% Heodo
2020-08-07Invoice-DDUS7-62835455.docdoc 263d34349b13ba141b0aef5c120274133751b6f0afa7dcdd02ed9f7a55abe16dVirustotal results 29.51% Heodo
2020-08-07invoice_OF110_3975584.docdoc f9557268094814b01a5017b9a241fe81a0174907f442a3881ecafb336d9a020an/a Heodo
2020-08-07InvoiceVC884366219484.docdoc 1c024255eecede738af23041dce02427bf7d670769be308c2982406778aaa045Virustotal results 27.87% Heodo
2020-08-07Inv-YWND4-96437064.docdoc f94c382237fdd1f354ceed254e116dee88ee47953587127353cce17a20d31f77n/a Heodo
2020-08-07invoice 611 993644319.docdoc 7114fa97be84770acda36b612f99c302ed013153b77ed3a067d02d76094c96e7Virustotal results 27.87% Heodo
2020-08-07invoice LMS707 093336165.docdoc 031e43825f2b7871a3f99e55db0e9cfba4045a7a22a45d283d9783e1b2590e09Virustotal results 29.82% Heodo
2020-08-07Inv-MCJ0-526736210.docdoc 4c73682d1d156486045b1316034798b9010f98354c76f7060157835326e17254n/a Heodo
2020-08-07INVOICE-QUO4581-90486973.docdoc a8585830fa13dad333bb6013a31fbd091a1bdf83f13eee388f27e3aab345fbefVirustotal results 27.87% Heodo
2020-08-07invoice_OAL6631_95936711.docdoc f68a95058791371da84307efc3d64dbb3a7f2dcf120ae133f5b375a6089f1e5cVirustotal results 27.87% Heodo
2020-08-07Inv 477 50253121.docdoc 635ee74a309d9f1f7b4d0096a218aaf10f90d115c83ce91dd0ebf02199b4d84bVirustotal results 27.87% Heodo
2020-08-06INVOICE-EVKR133-4795310.docdoc c9ce39498cdb7fb2227bd9ba2986cca4864f406c8afec758ad67bdee7c1f735bVirustotal results 27.42% Heodo
2020-08-06INVOICE-2-81110017.docdoc 2aaa85dd9ac60aea2f5746aaa7b925bdf4453f69fdf378f446da71cb35378c9aVirustotal results 27.42% Heodo
2020-08-06INVOICE32336418759.docdoc 61407a2bb77dfa22827b5735f1e9ea42fe52799d2d5c0e1c2ac85290efbe9579Virustotal results 27.87% Heodo
2020-08-06Invoice-451-51765620.docdoc 65c0489bb8f8e8e17eb934952b1b47f5012c5e59c25294da25db30a47339b146Virustotal results 26.23% Heodo