URLhaus Database

You are currently viewing the URLhaus database entry for https://growncarbon.com/wordpress/attachments/umlsgo3w5ir1/gzc2x11120092854048252f91vb4hpocu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435583
URL: https://growncarbon.com/wordpress/attachments/umlsgo3w5ir1/gzc2x11120092854048252f91vb4hpocu/
URL Status:Offline
Host: growncarbon.com
Date added:2020-08-18 11:26:06 UTC
Last online:2020-08-25 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-18 11:28:02 UTC to abuse{at}contabo[dot]de)
Takedown time:6 days, 20 hours, 13 minutes Bad (down since 2020-08-25 07:41:53 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19FILE_03536560.docdoc dac9381a81d9d239f2a341b839cdcd469921f650f74da24535abe92d78951118Virustotal results 43.86%Heodo
2020-08-19INV_PO_08192020EX.docdoc a1b39bb8e04288328a8785f48219abb0b12a2a6330e2192973405a2bf6682644Virustotal results 46.67%Heodo
2020-08-19INV_64218793.docdoc a3773aee947b0fdf4bb4d2a48777f6e8e4a83beb62f033efffbb0b487bef2e8fVirustotal results 48.28%Heodo
2020-08-19BAL_680202808331770662191097.docdoc 9300711f5a35bc33dab0314d010f858ea9385b9b41b60e8db605a367ee901d57Virustotal results 48.21%Heodo
2020-08-19INV_PO_08192020EX.docdoc 882600fee7e0ea4b30699f07b2c5237c9cb80b2ed0bdd471d055f7b450565272Virustotal results 46.67%Heodo
2020-08-19REP_022HWJLXK.docdoc a7fff8bf3bbff829f3388723e5da242e32d59f0b648925cb3ad55dc7db5697eaVirustotal results 46.67%Heodo
2020-08-19INV_53131846.docdoc 6ad811a3072f008affd2450407d0a37d9d45166d41c8fedc1d1e0ae2b61c77e9Virustotal results 46.67%Heodo
2020-08-19DOC_WEH_080120_KUK_081920.docdoc 4fafaff4c35c7050da039eba46004fb4df1789b0f4cb103ecaf05d4fcf0834beVirustotal results 47.46%Heodo
2020-08-19DOC_RZW_080120_TDS_081920.docdoc ade0c61c5a90ff1c6aa1b54b0f5d9e29382b98feb206f3b170724aa6e34cb389Virustotal results 46.67%Heodo
2020-08-19REP_78487445057792.docdoc 77da6b15c6aba0dd430e50f7372588fa39691b2cdd9f90f3d71a36445b59f30cVirustotal results 44.07%Heodo
2020-08-19UMG_080120_YRJ_081920.docdoc fbf8375b991d64aa1173b7a2d5792b19bdc39b63df4d483e9ac99f47157f3446Virustotal results 48.21%Heodo
2020-08-19FILE_XC7976800381LT.docdoc 13ecb0280410d83e2d67d9f049fe85af186a0c9959c316c90f3ec327a9ab244dVirustotal results 46.67%Heodo
2020-08-19FILE_PO_08192020EX.docdoc 9cbc258b5f93fe39609cced6c936d4529b4b3ba671125e8ad51eba9085dbd3a5Virustotal results 45.76%Heodo
2020-08-19FILE_PO_08192020EX.docdoc 546326b982f8d4e1c2af1b80d268127974403aae48e453ff6d8f1820120a8d0fVirustotal results 45.76%Heodo
2020-08-19PO_08192020EX.docdoc 94fe6d0cc1723a60d8965c606027ad0283a60c1f4677cf33c8cb85fd202bbc60Virustotal results 46.67%Heodo
2020-08-19BAL_71046069.docdoc fededa8f56c791fe22493104398edd8f25c5b47a5668857fbbe72e6ee16ede93Virustotal results 45.00%Heodo
2020-08-18PO_08192020EX.docdoc db2013508bc3e41f1f93da8cc42b9edcae448ab5eefe05b364e1ce01247dd763n/aHeodo
2020-08-1881833731.docdoc 6c9d3d58e28a1e8bbf0d1c77a0bbb7f6c71a55ac204041c9f1f8e372b19df91eVirustotal results 45.76%Heodo
2020-08-18NYRM_AM7280723540CW.docdoc b3c49f6fc4bccfb7209cc9da0e7092c623b21c438cf4ba36d18d3473015ca2aan/aHeodo
2020-08-18FILE_RDO4P7Q0N2.docdoc 7f32822db30d0d6ab9d5ef5dd261b4629d251e40b69b860a30fa476c0e7b8d0fVirustotal results 40.00%Heodo
2020-08-18SLS_080120_WCJ_081920.docdoc 35e9740b20a2893c8d20a705afd0fea0ec6d9293bb4b67d0446012a36e6a72d0Virustotal results 40.68%Heodo
2020-08-18INV_8947709164.docdoc 385433701c68cc76403d2a484e7795863e21238a11d5892af2e910b2a5c309b5Virustotal results 40.00%Heodo
2020-08-18ALK_080120_QZL_081820.docdoc 6a3681023971a36a433c4b9af945711a183d10d9739bde0201540c199c5256b6n/aHeodo
2020-08-18INV_PO_08182020EX.docdoc cab6349ac0df4084c7ff95a5e68f961048537236c2602cd3aff11482fb0d0af0Virustotal results 40.00%Heodo
2020-08-18BAL_949952195217969954.docdoc 460a8e4f639b96c10e0094ce3aceeb1f60278284a1d7b27e3b16fd4b76744636Virustotal results 40.98%Heodo
2020-08-18T_66427380509628.docdoc 801bc5af1dd1dcee180728a22dc08e6a43622b62fdd21c4d95b06895b62bebbcn/aHeodo
2020-08-18A_OKZ_080120_KGD_081820.docdoc 455f2ce2d5b18bbce7c1ff8a8eec0e143f98fe0c1e0a4d289aee56f5f8e33e4bn/aHeodo
2020-08-18VL6682402079TQ.docdoc 2e671edf471827a78f9327e215f9bcf6dda0f639706319263dfe9cb37d0241a2n/aHeodo
2020-08-18BAL_GG8916063800EO.docdoc 4b7f1d4444db5d249123e54f4b583946c8c0db484f2c8ce65ef0bb922e96c4c8n/aHeodo
2020-08-18REP_20213193.docdoc 9c44c80515e97bcea6d0ecb7465ea920e4515d1c244dee409b2a3467b6815a50n/aHeodo
2020-08-18WSPSE79TEO.docdoc 4d8e7cfda1c0e9d03775d5858d97345d0a2ebd918a721a33ab2b2225e594711fVirustotal results 37.93%Heodo
2020-08-1892607666587.docdoc 010999a8438ea40d8012240b03d2ced196d695c0e6ddcdb43bca7d28693c16dfVirustotal results 35.59%Heodo
2020-08-18Q_745219013646343856902507.docdoc 0a41f0b1fa2d723ed6b405e7f8ec27f3a38956badc1df3350a581e21c8c9d203n/aHeodo
2020-08-18BAL_PO_08182020EX.docdoc 0cef6300d4ff34161fe15685c7de03dd6663177b6ca1d87df136eb05e9daf650Virustotal results 28.81%Heodo
2020-08-18INV_3IOIW6W.docdoc 77300670b06067855e3c1d1b58df8a505ec1598099aa1a03970407a2798336c7Virustotal results 22.03%Heodo
2020-08-18O_DEB7CVQ8H8ZHAML9.docdoc c6313b13d24c46970563fd973b3b8b40ffd67b9270160ba475ba43994c824d8eVirustotal results 22.41%Heodo
2020-08-18FILE_MFN8N21I.docdoc 40adc356165aeb925dcc32c72e98d5d0a548f3f5ca83cd3f932792c081bcc106Virustotal results 23.08%Heodo
2020-08-1898223334.docdoc 09904d529c1234df3f3e0b318aaf40b31cd8c353cc884a2310d328af4675fd09Virustotal results 22.03%Heodo