URLhaus Database

You are currently viewing the URLhaus database entry for http://gooddogrescue.com/ww4w/4408657824-BRMsia8Tm-module/special-vo4rjk-xx8cn/S4QMguv-qzrdrkn1eia/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:426997
URL: http://gooddogrescue.com/ww4w/4408657824-BRMsia8Tm-module/special-vo4rjk-xx8cn/S4QMguv-qzrdrkn1eia/
URL Status:Offline
Host: gooddogrescue.com
Date added:2020-08-07 06:12:05 UTC
Last online:2020-08-07 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-07 06:14:02 UTC to abuse{at}worldspice[dot]net)
Takedown time:17 hours, 5 minutes Good (down since 2020-08-07 23:19:17 UTC)
Tags:doc emotet link epoch1 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-07dat_20200808_8468199.docdoc 46334d480ccb50aef34b546502fbe6e54c6da6395046fe6be6fc4e5c063adedeVirustotal results 33.87% QuakBot
2020-08-07Rep-2020_08_07-V02753.docdoc b73f780a433d41cd9d6d0046f85474514b51eb5471e34e530974673c6579eb1aVirustotal results 35.00% Heodo
2020-08-07rep.docdoc 646ccd64823cfa77dbb491953dde3333f48c8c19ac7a2753088a96dce8b0d397Virustotal results 33.90% Heodo
2020-08-07File_276377.docdoc 016ca89513a40f3189a3620d63b4ddeecb49bb57f1459ad75154e1ddd9f2370fVirustotal results 30.65% QuakBot
2020-08-07Mes_2020_08_07_576136.docdoc 9aac7ec20bb40421b838a9695b5b86221b6c348fb79cb6a6e1e4b5cbe3dd55b5Virustotal results 34.43% QuakBot
2020-08-07File-2020_08_07-0547.docdoc aaf9724d17a02da2ebb37c991ad51b1636ae22b4af318713bc3aa68538bb632cVirustotal results 25.00%Heodo
2020-08-07Mes-20200807-985494.docdoc 7b7b33a7dbd6566a73bbab5bdb8a4fb6f5aa2655095adc97b72e22b5f09a8f43Virustotal results 26.67%Heodo
2020-08-07mes 20200807.docdoc d05ae9b3e032aae65ae8881e365fc232885ff9c3b82ee8ee30dd212795203dd5Virustotal results 23.73% Heodo
2020-08-07Rep-2020_08_07-BM426816.docdoc 4105a7b924615ef7a3d142ec138f6a7340a715250f3e957c73a5c377c572ee7fVirustotal results 45.90% Heodo
2020-08-07File-20200807-57140.docdoc a6cf38618a58d0076e02ca5aa15020a6971e1367e0b8c00168775a31f8b92618Virustotal results 37.10%Heodo