URLhaus Database

You are currently viewing the URLhaus database entry for http://globdesign.com/KI9/attachments/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435646
URL: http://globdesign.com/KI9/attachments/
URL Status:Offline
Host: globdesign.com
Date added:2020-08-18 13:10:13 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?):No
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-20BAL_PO_08202020EX.docdoc 7accb2b3c3c3e895843299dd9501472eba59554dec726ccdabc379b0c78b618fVirustotal results 20.34%Heodo
2020-08-20REP_SA7484788605VB.docdoc 90e72768a9fcbfdf46cda083bc9c9b52c6c6426dded0da95654dda7f429df2e3Virustotal results 20.34%Heodo
2020-08-20A_BP7784795237HK.docdoc 3adba5d0d3b9f8425b3f663d9a4e49ea5d5effd605916f354e932e1fae4486e4Virustotal results 41.67%Heodo
2020-08-20DOC_PXJ_080120_OGK_082020.docdoc 66a403efd8393bccf77c5569e565832eff2be778707554b35b78be859b2af41eVirustotal results 42.37%Heodo
2020-08-19FILE_1812913599.docdoc 06212a633940e412d08fe257dc44e835d74a44b32a8792643dbc963f5002005aVirustotal results 30.00%Heodo
2020-08-19FILE_PO_08192020EX.docdoc 1714cec2ab4f18617debde539893ee139cecd7dc387542884dd3d95c3d0ad583Virustotal results 23.73%Heodo
2020-08-19FILE_PO_08192020EX.docdoc 90499b6cd235fd63115a4d18f0989f842252935038f4cadec17f85a2081b1cfdVirustotal results 23.33%Heodo
2020-08-19909586160077919880257.docdoc 783974bc2743d417a2df0a73eaf9e83ebf04435f67741f711a498effe3997894Virustotal results 22.03%Heodo
2020-08-19QXO1HTLHZ6.docdoc 01904ce332b0495cab01f41e3742febdd74e840052009501262bee8ec8528a76Virustotal results 16.67%Heodo
2020-08-19INV_42939520937993.docdoc e10fd6b719ccb741ff632f1141214caa698376417f9615419d85d200cff1bf6fVirustotal results 16.67%Heodo
2020-08-19BAL_ON49MW48.docdoc de249d474e6a0f561bce039f85d2341fd1599729f4a7150d6e9545753288f8b2Virustotal results 18.64%Heodo
2020-08-19JGW_080120_IXP_081920.docdoc bb8612a686ae9c12046192e2792a6ee1841b6c6ec871d1112fef955888458a34Virustotal results 18.64%Heodo
2020-08-19OZI_080120_PSX_081920.docdoc 9f7d78ffd5db86fd09de12a598cee46f2a1fa635d4b808708df8edcc7a9d8002Virustotal results 47.46%Heodo
2020-08-18INV_8631517104768.docdoc 6e7bc5b464486368fc64b81be80628536390d77832adc42ae658a9ec6642f2b4Virustotal results 45.90%Heodo
2020-08-18FR1334058278HO.docdoc 6132d38c562ce3fd2f815bb85f961fe7be3153f058d6b86f366c69a51f65bbf8Virustotal results 42.37%Heodo
2020-08-18INV_245344534275.docdoc fe26e82cbd2b5d6687f5b9793748e9e53f958a4c71decf035c8630a50cc24fe7Virustotal results 40.00%Heodo
2020-08-18GX3890907994QP.docdoc 58f54242a517952baf0ab77f9eba354e7f6299fc66a0a2ef3eddfbc9def3870aVirustotal results 40.00%Heodo
2020-08-18REP_83129453.docdoc 455f2ce2d5b18bbce7c1ff8a8eec0e143f98fe0c1e0a4d289aee56f5f8e33e4bn/aHeodo
2020-08-18INV_PO_08182020EX.docdoc da237c6410295bccf15c5ae7a39cf56b4b7d46ccbeb39e9b1ae4d8c6eca20c41Virustotal results 38.98%Heodo
2020-08-18521562308664545418.docdoc c77483f0eb72573fa65dcdcf2c9f443e031bccbeeebbfab901c18a75a69c0f60Virustotal results 28.81%Heodo
2020-08-18468455828434670843597694.docdoc 77300670b06067855e3c1d1b58df8a505ec1598099aa1a03970407a2798336c7Virustotal results 22.03%Heodo
2020-08-18FILE_01847137394427506612.docdoc d71c86b140001cea79329f1330c1fc73471adbf305e5f06928aead9f2e01ac30Virustotal results 22.03%Heodo