URLhaus Database

You are currently viewing the URLhaus database entry for http://gombui.net/www/multifunctional_zone/individual_profile/h5end900ug1ab_599822x099188/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435134
URL: http://gombui.net/www/multifunctional_zone/individual_profile/h5end900ug1ab_599822x099188/
URL Status:Offline
Host: gombui.net
Date added:2020-08-17 20:02:13 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):No
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-18inf 218969.docdoc fda68ab66880ec8154bdc1a9595ec1f34fbf612ed3e9c9d13c7424ca0df1a5f4Virustotal results 42.37%Heodo
2020-08-17REP_20200818_HW39984.docdoc ee73292346080c0aca419551f433cba7a1c7cc886a05835be10b51d6072c3f30Virustotal results 42.37%Heodo
2020-08-17File 2020_08_18 157.docdoc faffee3625908bf1e2cb82c961bd1d777beeff0f87166e3aedc6fa984834c42fVirustotal results 41.67% Heodo
2020-08-17Doc 20200818 L137.docdoc 5f0f7cccdbe15b26ad3d18fe0dc9c31aba891cea529b65e56c7dda35fa776c0cVirustotal results 42.37%Heodo
2020-08-17Rep 20200817 Y721.docdoc 3d22fec6c122302f98c08a308d62a7f52a75ee6d24311103ae0af25bb246d480Virustotal results 30.51%Heodo
2020-08-17Inf 20200817.docdoc 5393457e88e699e2db18ee5eff5f94350e4e6f640fcc1d34176cdf08bd1aefe4Virustotal results 30.51%Heodo