URLhaus Database

You are currently viewing the URLhaus database entry for https://www.forerunnershealthcare.com/videos/sk9dxgun/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:437905
URL: https://www.forerunnershealthcare.com/videos/sk9dxgun/
URL Status:Offline
Host: www.forerunnershealthcare.com
Date added:2020-08-21 04:57:04 UTC
Last online:2020-08-22 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-21 04:58:02 UTC to netops{at}singlehop[dot]com)
Takedown time:22 hours, 51 minutes Good (down since 2020-08-22 03:49:03 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21FILE_02647366.docdoc c64bc08e778f84f8cb265924403179568dc55e40be4d9e2da918278f72743276Virustotal results 23.73%Heodo
2020-08-21381753666510977.docdoc 6eb69e6bf953f664d116b1f723231c894c54ff4b2482e3f9d1120b10fc541bd5n/aHeodo
2020-08-21REP_CFF_080120_HVI_082120.docdoc 6d41dda6d8f84da740366a301d3a7e30f305bbd2935b6b609341c5558cb47b28n/aHeodo
2020-08-21JFQQ_60093530849.docdoc 8a887dca0fea26577923cdf9c4985eac7870541eacebc98ac38b51a4bda04ab7n/aHeodo
2020-08-21INV_MRU_080120_CIG_082120.docdoc 6da5305c5476e37418039466c6809a7b54104ba1e58a922c6383a74d7fb2517an/aHeodo
2020-08-21BH2613610797LY.docdoc 83912e356ffc063006637864e3ceed204efd7141ac92b7ff91fc4e3372c2552cn/aHeodo
2020-08-212126936317120820008812.docdoc e0edc38058ce9b689134aaa2fde3ffec05c36a32a51eb58932d313160434ec50n/aHeodo
2020-08-21DOC_SL2776423630GS.docdoc 10b6f0f265e6ffee5f3f24d1719593a94876a740dccbeb6f319bdf53a44a72d8n/aHeodo
2020-08-21FILE_RK8597082168BI.docdoc dd3afacc150ce99efa0843ef4211a83be23385d9f1d8661b1fd04f45975323e0Virustotal results 20.69%Heodo
2020-08-21REP_BJ7445433762GF.docdoc 28f2d62905428be69bb94405cef4459871fb4d34be7d8e1cd99be4088802ce60n/aHeodo
2020-08-21DOC_352618396499.docdoc dfa53b1ba591b08dacd3b798dedee90d559b092102517b46cd1a04bccf51e386n/aHeodo
2020-08-21DOC_PO_08212020EX.docdoc f4cf506743474d0a3cd6642db40bb54301ec4a84e38d41782b1199600b16df5dVirustotal results 30.00%Heodo
2020-08-21DOC_DG9921949405ET.docdoc c6fbe26a69de6c684e24b5438000839980b291ba697b3749c226ee5871517433n/aHeodo
2020-08-21008122755216672828.docdoc fd2732589c07dc97af78689360772ace939ebdbf5c47132f7df607d9e24a267dVirustotal results 29.31%Heodo
2020-08-21167002105.docdoc 0566ee320bea900383d9ca704bf88d12efbcb69e6eed4b55d1e904ced4c6af2an/aHeodo
2020-08-21DOC_95692881.docdoc af3988b7856704b5467030ee792d90beff86f1f453c3280c8d0f822b2dc9898fn/aHeodo
2020-08-21W_6414538259400316056.docdoc 29489d8ec25a46a76a0bb977cba3d4260eef3e2520e1b060a323df2c5f8cd8fbn/aHeodo
2020-08-21BAL_PV5720676793QI.docdoc 10eb0c89bd6a8c392938b290e5362220dbfcd7a518c8b29de8fc693813b0d919n/aHeodo