URLhaus Database

You are currently viewing the URLhaus database entry for http://gbbulls.co.uk/video/OWfEVwiqJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:433546
URL: http://gbbulls.co.uk/video/OWfEVwiqJ/
URL Status:Offline
Host: gbbulls.co.uk
Date added:2020-08-14 20:05:03 UTC
Last online:2021-04-24 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Spammer domain
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-14 20:06:14 UTC to abuse{at}eukhost[dot]com)
Takedown time:8 months, 12 days, 9 hours, 43 minutes Bad (down since 2021-04-24 05:49:37 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15invoice-G0-16018947.docdoc b9d2bc9624f1e81b007fd1d89170294eb6eb29c779f83f4e75576a0fa3fa421aVirustotal results 45.45%Heodo
2020-08-15INVOICE 8 41703860.docdoc 509ee5a5b60fc1722c36b7285771bd5efbad237f9ca4101fdd4a982b5a3f86e6Virustotal results 40.68%Heodo
2020-08-15INVOICE-10-844351924.docdoc 903b4b0dbf79ba01b1c8a324c887cf2e6e7ddff21d2cb2091ab77cbc6c13b467Virustotal results 41.38%Heodo
2020-08-15invoice EXQ9 1834226.docdoc 1fc2a5a85e81f16a544f41141eb6609caacee1f79acb843c42f94dacb68ef8d2Virustotal results 40.68%Heodo
2020-08-14Inv-R9-159604.docdoc 95cc5ce9259454f349e823d4c1e4c546a303dacfd17dd01c60af5f9dfb171cb6Virustotal results 38.98%Heodo