URLhaus Database

You are currently viewing the URLhaus database entry for http://gbbulls.co.uk/video/open_resource/316004_ICYWHBNt3r9_forum/hil9woxpil_ut9356278u08/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438456
URL: http://gbbulls.co.uk/video/open_resource/316004_ICYWHBNt3r9_forum/hil9woxpil_ut9356278u08/
URL Status:Offline
Host: gbbulls.co.uk
Date added:2020-08-21 18:52:33 UTC
Last online:2020-08-22 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Spammer domain
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-21 18:54:02 UTC to abuse{at}eukhost[dot]com)
Takedown time:6 hours, 2 minutes Good (down since 2020-08-22 00:56:34 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-22Arc_2020_08_22_0815.docdoc 17d1a183b329a542e212c99216bfbc17c5abd835093634f262e79e38dbb61be8Virustotal results 35.00%Heodo
2020-08-22file 2020_08_22 24218.docdoc f3910c447952615a78e47e19bb4d3f313f015a74e603c83b15fbe812d5437d4cVirustotal results 34.48%Heodo
2020-08-21INF 752.docdoc 42cd1526e8dc5c2eb9e1cd5aa13c9dd5068358c7f29defbac1a97b67f59b36bbVirustotal results 35.71%Heodo
2020-08-21Mes 2020_08_21 590.docdoc 72b2921e88aeb838b4567932faa2cb3e87eaf3119d6a9dd409e8bbf575f0f708Virustotal results 34.48%Heodo
2020-08-21Dat_2020_08_21_4230960.docdoc 08d428fd87f7866db66965b1283f47ae55c36beaf19603971b5db2154c6faab0Virustotal results 31.03%Heodo