URLhaus Database

You are currently viewing the URLhaus database entry for https://www.gothamsoccer.com/assets/private-zone/3NWP4-00rBdn0BzS7-area/VGdkuPsID-pgqgapz8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438282
URL: https://www.gothamsoccer.com/assets/private-zone/3NWP4-00rBdn0BzS7-area/VGdkuPsID-pgqgapz8/
URL Status:Offline
Host: www.gothamsoccer.com
Date added:2020-08-21 14:47:04 UTC
Last online:2020-08-21 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-21 14:48:05 UTC to abuse{at}liquidweb[dot]com)
Takedown time:5 hours, 2 minutes Good (down since 2020-08-21 19:50:20 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21Dat-2020_08_21.docdoc afae193e15a1015938b4d38c1c3a60e066a7de17e27e599fb8afe90d97dcf749Virustotal results 27.59%Heodo
2020-08-21LIST_20200821_QR77719.docdoc 98b205aa6d8a1013d8472dadcbb5f479d702e147bb4a044ccd20fa494cee86ccVirustotal results 27.12%Heodo
2020-08-21mes-TD76007.docdoc c4525d8d12b2ae0b6f7695fee8ce9fd554341878ff6ead657048680e50beefccn/aHeodo
2020-08-21DAT_20200821_ZMO8571.docdoc c22cd3fcf4f9698404855a85f7bfcd785d3742f4aee5ff514f4005afa77fc3e0Virustotal results 28.07%Heodo
2020-08-21Mes 2020_08_21 2976291.docdoc bb5ea6401f31e4c9a16297546ea7dc58a1b86dec75837de0e5ce9e9709a53919n/aHeodo
2020-08-21Arc 20200821 19861.docdoc 3b17e737a54751a71b9d73e78868fe24f0033eac1b31dd744fcbc169eab139beVirustotal results 27.59%Heodo
2020-08-21dat-2020_08_21-506.docdoc 6d50456c3290a78c53c586ad8eee0f6156fe29bcbf3e0af00e3646bb85dec3d2Virustotal results 26.32%Heodo
2020-08-21LIST-216423.docdoc 06731292da769a21d7cd5e4226b873134f18d1bcac76f39efd3a9cac90c47758n/aHeodo
2020-08-21REP 2020_08_21 DDM5600.docdoc da91e88f34f8d7627c0ec63afa1e9e52ccdc02f005e4ac73eb581513a70969faVirustotal results 27.12%Heodo