URLhaus Database

You are currently viewing the URLhaus database entry for http://gts-center.tj/wp-admin./kuVwZZu2x-6JUqgbXz-disk/external-xgjK882-nCWP6m7KAjZTq/3487038-Cvfhkget00Lrk41a/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428615
URL: http://gts-center.tj/wp-admin./kuVwZZu2x-6JUqgbXz-disk/external-xgjK882-nCWP6m7KAjZTq/3487038-Cvfhkget00Lrk41a/
URL Status:Offline
Host: gts-center.tj
Date added:2020-08-10 18:08:06 UTC
Last online:2020-08-11 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-10 18:10:04 UTC to info{at}tarena[dot]tj)
Takedown time:11 hours, 48 minutes Good (down since 2020-08-11 05:58:16 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-11FILE_20200811_I2706.docdoc fce0f3d055c058d10eaff76ccd0a00bc87a7fb733b1ce6894e486b39ebf6793fVirustotal results 42.37% Heodo
2020-08-11DAT 20200811 ESK62422.docdoc cae649fa4834fbe773a6759d1c55036ab5a152fa90aa2f64b7751e50b3e7deebVirustotal results 43.33% Heodo
2020-08-11Arc-2020_08_11.docdoc 353b24cd1dbb7be15133b64495afbbd1846a83e775870f07cef1efc21c411ddfVirustotal results 44.26% Heodo
2020-08-11file 3047.docdoc bd21c54cff53a13d78966917cf55e87135e7020967d2416f6a0b259beba63dbaVirustotal results 44.07% Heodo
2020-08-11Mes-20200811-VZT6066.docdoc ee1ee54baff4c78ecda5e4b6ff18630ad8152cabe662ac370b7d814ee6d457e4Virustotal results 44.07% Heodo
2020-08-11Mes 2020_08_11 DRK4804.docdoc 980c5eb49f054079a587ddcfe2c193c45a1a6be41100c5f1179df24c87986712Virustotal results 42.62% Heodo
2020-08-11INF_20200811_155.docdoc 92f8226b4916acee5abadfd888bd396b2979be223db46252b4decde8b4b3667cVirustotal results 45.00% Heodo
2020-08-11File 20200811 677008.docdoc e4790d41e27c6978baf5ccf9461b74b1e9606fdc7edcb4d2022edafc3d8a6fd6Virustotal results 41.38% Heodo
2020-08-11file_2020_08_11.docdoc 13c77da9bbdaea66303dfe4cfcb8b5a9f8eae8d46f1e710ab6574c73b2c1d91eVirustotal results 44.07%Heodo
2020-08-11Dat 2020_08_11 VS488750.docdoc 3b8c4e97505c638f5483d32e67e05043b3f245cb397a0069370eec83299bb2deVirustotal results 43.33% Heodo
2020-08-11REP 2020_08_11 RVW915.docdoc bda55acb649535e7d61133cf076b1604f3da829aa4d7b45a7bf3ba27466d9c3aVirustotal results 45.76% Heodo
2020-08-10mes_20200811.docdoc 1ff50f088800028624af3ad83890529e6cd409d4c797d27b35f77e33fe36793eVirustotal results 40.00% Heodo
2020-08-10doc 091.docdoc a685d179f34dc5fcb9fdb968d93826a1931f9e729bd7fa6491dc6cacf4ca0c68Virustotal results 40.00% Heodo
2020-08-10DAT_UD396907.docdoc 1ceffcd16d5774ac5d4cbf896be5a34a1255b59ecb1ab8c609cfef7e151c739fVirustotal results 42.37% Heodo
2020-08-10inf-2020_08_11-99477.docdoc 6c9c1e35a22b32ad9722b917f0562f65ec1e6f847bcbd63e4b5ca9a09738f860n/a Heodo
2020-08-10Rep-44886.docdoc d1995ed56b0d8d1b1696cf696e047d70dd9f86f9ba8dfeb1903fa84aa82f3e94Virustotal results 41.67% Heodo
2020-08-10arc_2020_08_11.docdoc 3b59369e3166425caaacc1f0c00428539ecec010f83337e7af44a660bc6c7735Virustotal results 40.00% Heodo
2020-08-10FILE.docdoc 8bac60fe9c581db6206a5ca49fc3fc76df934a47006c8effcd145a6ab3c70cc8Virustotal results 40.98% Heodo
2020-08-10doc_2020_08_11_TJ72256.docdoc 69a6b1c09608f190a59315faa99814cad90c3eda1f938f379415adb9ce80d7fdVirustotal results 40.68% Heodo
2020-08-10Arc-2020_08_11-YRQ5504.docdoc 3708962d8333f33b8ca2229ccdf932d5f06c2e380b5634afb33c2b29e209e269Virustotal results 41.67% Heodo
2020-08-10Arc_20200811.docdoc 8f9e5cbc1eaf541061e1c1fd545d23d12c9af3e75781e353cb46b9de8dfd728eVirustotal results 41.67% Heodo
2020-08-10INF 20200811.docdoc 6fdba2a3c021e527cc4d508e143f075fee286280cbb58cc759f2c7968248b1c6Virustotal results 41.67% Heodo
2020-08-10Mes-20200811-BT6745.docdoc 9b16a279970535f938fcae16c2df00eaf040804d5eb740193210aced906a8e2dVirustotal results 40.00% Heodo
2020-08-10INF 633358.docdoc bcb9d74a9abe1771e3619aaff40ab73fb482a38cdfcf9d24a78fff78a635deecVirustotal results 40.98% Heodo
2020-08-10doc_20200810_A601.docdoc b5184411717b5186e80a521f6b70c47091f21c4e9c586d2f565438dfaba70d7dVirustotal results 40.98% Heodo
2020-08-10Mes 2020_08_10.docdoc 21d305c97502379abad7f15c44454ff18239806f9839d1e72f83028893df2fa4n/a Heodo
2020-08-10ARC_789091.docdoc d486a449b6d68310c6965a1dc538a48d27ca880c9a33ad021ad7a4bdf7c0430bVirustotal results 41.38% Heodo
2020-08-10LIST_2020_08_10_415.docdoc 5ea2c7eaaa0d780bcd7f74643ef0b499dfc1cab011f0f5b10290771e8de625cfVirustotal results 40.00% Heodo