URLhaus Database

You are currently viewing the URLhaus database entry for http://gsproductsindia.com/revolution/paclm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:441160
URL: http://gsproductsindia.com/revolution/paclm/
URL Status:Offline
Host: gsproductsindia.com
Date added:2020-08-25 18:18:06 UTC
Last online:2020-08-26 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-25 18:20:08 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:22 hours, 57 minutes Good (down since 2020-08-26 17:17:59 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-26DOC_19309510.docdoc 71a9af3c869b41333224d9d53eae47aba49f7c8512250f3286ef22680bf6ef9dn/aHeodo
2020-08-2656164057.docdoc f704c7aea8849d0ae729aa1436b9590e92291e62204821e5d7550db4c49b2c1dVirustotal results 32.76%Heodo
2020-08-26BAL_2FFDQEKRBB3KH.docdoc 09e6e19b4d2f660e0c19d8409c453f633dee0d483be92c0d795d00c6ed0f1cf0Virustotal results 32.76%Heodo
2020-08-2685476321.docdoc 73bd8ccbf6c6ab32472c5784a7979a150437174459c01a7398945c2867eea506n/aHeodo
2020-08-26BAL_2FJERZ18G.docdoc af5e077f1915828d85cb8b2e854ac2c634e10cd249bc9ca36bfdce6210a78289Virustotal results 30.00%Heodo
2020-08-26BAL_94242937.docdoc 230ab4fa2ef9855a13c29c152fc59b6de56233f75e523a408a709175c7b68953Virustotal results 29.82%Heodo
2020-08-26FILE_02893979.docdoc 14d43c503a1c9c5f61bcfd706d421ffca90c3f85c85dd05adc435c623d8fb46fVirustotal results 29.31%Heodo
2020-08-26INV_10191671.docdoc a431f7a715ae2294f803abd31c677aceded29507e07a580ed361bdb73c8ebf3fn/aHeodo
2020-08-26FILE_PO_08262020EX.docdoc 690b7078636392724c3d0facd5199e05ec56585148bbcda6aa7f2c64f597635eVirustotal results 28.33%Heodo
2020-08-26REP_ZN2806870886XB.docdoc 6dd3e6bbc0eea4a8b5a155e9c5ecf6731f98e487ce6ac53020fed4afb8363f7bn/aHeodo
2020-08-26L_5SLLYQ11.docdoc 19ca8c91cd538e5f8391aa3c2aedcf6269da71895ee8746d43258bd2a8b960ean/aHeodo
2020-08-2681998148.docdoc 43b33fc5852e71888cd1482bebdb418167ded93b6c98c1c46892a0559ad53345Virustotal results 29.31%Heodo
2020-08-26BMY_12871925.docdoc 3ec2a6e6f9b780a7d77f938844d012780d79fcbad1fd593da0a9924c624fd778Virustotal results 29.31%Heodo
2020-08-26U_00193596.docdoc 0c22f0ad057fa28d31a047a34391f1275438a034d1c42d951637ee89c5252d24Virustotal results 28.57%Heodo
2020-08-26DOC_PO_08262020EX.docdoc dc167ca9c82110cbd8c275bde50770d2cda4d232986e4018107994b92009862cVirustotal results 27.59%Heodo
2020-08-26BAL_DLJ_080120_BSL_082620.docdoc 92ec3d4c98f50093628224f537985cfb37e32143818fed1d9f96aead95d6bf61Virustotal results 28.07%Heodo
2020-08-26M_3FYC7UNDAJL.docdoc 0322eae38619df582bc680d8fbde3a8a8f4b9e2c02b689db2d863c62f88c559aVirustotal results 26.32%Heodo
2020-08-26G_IOXPX8W0.docdoc dea98698a907a95e646de347286e7bc23d8d095022a89d3e4dc22b1652eaabadn/aHeodo
2020-08-26BAL_UKU3W09CHFIR9.docdoc 300cf0fd3de72ba9c28fc5428b8fac05aa455c7d7ffffbf3ae72db863f7fec1eVirustotal results 29.82%Heodo
2020-08-26QBD_080120_LLL_082620.docdoc ddf500146efb671da13e611911185a3e2e1bdb538e7f41ae0eb759a38adebfdan/aHeodo
2020-08-260045713613559540505.docdoc a4b0033aace38e2c6d2dfadfe6776527459551c761c232558d3c573220f5c15fn/aHeodo
2020-08-26INV_88756094.docdoc 4014edeacef628a8e6b950feaa547a482a43162461571eb152266564c38c619dn/aHeodo
2020-08-25BAL_0YYHSEHDJJICDXPD.docdoc 69c3e163903f4fcf7f5a52ccc3ba9d74d72c246208f4850abffd01971a51e795n/aHeodo
2020-08-2528538004.docdoc 966e05abf8db8638c7e4ca88db7b7943092c05b18f44597801128b6f7ba41254Virustotal results 29.31% Heodo
2020-08-25INV_YYO_080120_XFU_082620.docdoc b1e3c18649bc4cbed912ce7f0087cdba73298204214713ad1038375ad055142bn/a Heodo
2020-08-25FILE_2Y8MSWOZPJTPBJV.docdoc a60bfe31dcab8ba0730c4edb7de14a10147c618560d09a6137b8e7bb6209dbc1n/aHeodo
2020-08-25510490607467.docdoc 1cfa8b0347632b49a79619381b1d4e69a627df9cc64c67f825d774937ccb28b9Virustotal results 29.82% Heodo
2020-08-25REP_NHS_080120_UTW_082620.docdoc edc3477618d76e98889e1be29182a8db3e21ff561eaea309e12070219788bab4n/aHeodo
2020-08-25K_69954865373286656098783.docdoc 2eeec2892926e686de8fcc29fc57c57b10a4f37e49cee06ec4b5c864dcf5cfben/aHeodo
2020-08-25DOC_QF0426379932TV.docdoc c0bc03edcf17373ca7bcc145fddea1578f8998fb6f1d400d3701ebbe4ac1c833Virustotal results 29.31%Heodo
2020-08-25BAL_CFW_080120_QXB_082620.docdoc 454cc9bc1c0fa7bf6dbce349641296e8a5b5e6d7c935d1804eff6759fd0373e5Virustotal results 31.03%Heodo
2020-08-25VWO_080120_JWM_082620.docdoc 52d5f65c1708917e116f0217caac8d2a8ebdc93b3b349f9f42b7d7c1b13d69d6n/aHeodo
2020-08-25DOC_LIH_080120_QKK_082520.docdoc 5e8bd78307f84ea522b74ddc97c714880550136515711fdf54075c8a673cf263n/a Heodo
2020-08-25544489412.docdoc c83c6353d36706d9ede8b73d387db5ea74ea2977900f849d802d7cf17669c266n/aHeodo
2020-08-25REP_71707408.docdoc ebf572465108b8645ca9637d9c17b4fe717d4d99f3d4dd29046a22a8f608bcebn/a Heodo
2020-08-25UY3PWUANU36YZ.docdoc 263db302489a8ee87cd55bc7cdcd6853b02d39b711ec9a671afef6737154e2a3n/aHeodo
2020-08-25BAL_J4LKO4J2UV4GPIVS.docdoc 2005da08cf5f5e5489e2eee91a32b61ee7c2da83fcbd47f566eb7a3a29388151Virustotal results 41.38%Heodo
2020-08-25FILE_PO_08252020EX.docdoc cd5de7d65b2e9b1096050ce5dc17eab61c74558a8570d384af33e78dd2d9b025Virustotal results 41.38%Heodo
2020-08-25INV_QS7623070515VJ.docdoc 671eb437230d3a779fdd43549113542c76054cf1440e7d527886077a236775fcn/aHeodo