URLhaus Database

You are currently viewing the URLhaus database entry for http://galdonia.com/js/mr95555r0anx-brpn2-zone/verified-space/xrbo-twwt28w35/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435129
URL: http://galdonia.com/js/mr95555r0anx-brpn2-zone/verified-space/xrbo-twwt28w35/
URL Status:Offline
Host: galdonia.com
Date added:2020-08-17 19:46:33 UTC
Last online:2020-08-17 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-17 19:48:02 UTC to abuse{at}gruposys4net[dot]com)
Takedown time:2 hours, 47 minutes Good (down since 2020-08-17 22:35:17 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-17LIST_ATF36741.docdoc 47b3fee25d6683706ef483aa30125377edf7bb21dd17638c81c52fa7e64966f7Virustotal results 34.48%Heodo
2020-08-17Rep_20200817_SY406.docdoc b5ba2a25b6b78baed8f427232afed8841e367725d1fb05bb47b5ec863dcfcf7aVirustotal results 35.00%Heodo
2020-08-17DAT 2020_08_17 004.docdoc 3c021a95e5f5b22f4efc9f3fc678defdb4c50196549ba03786c0aa2bfead670eVirustotal results 35.59%Heodo
2020-08-17mes XFZ43617.docdoc 348368dc3b9ba59325226c159fd0b695e4256ad96894a3f58d3b97297a87a1b0Virustotal results 33.33%Heodo
2020-08-17rep_20200817_8566.docdoc 068447c2fb052258a7ea0ba47b2fa89cd69bb3a9bc9457e394de0a70a1277da4Virustotal results 33.33%Heodo
2020-08-17arc 2020_08_17 044002.docdoc 4e222c92dce7f604bdab06a48a8b26d08c4c3ff4e455795f8024e98823f1c13eVirustotal results 32.20%Heodo
2020-08-17FILE 20200817 5219.docdoc da10e987e0f17cdbf08a4c765e272d4feb929d329ba74d4fb5d1d27c36c1ed38n/aHeodo