URLhaus Database

You are currently viewing the URLhaus database entry for http://adv-garant.ru/cgi-bin/https:/Overview/Ed2cmEiUnnd6Hd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452809
URL: http://adv-garant.ru/cgi-bin/https:/Overview/Ed2cmEiUnnd6Hd/
URL Status:Offline
Host: adv-garant.ru
Date added:2020-09-03 21:41:07 UTC
Last online:2020-09-04 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 21:42:15 UTC to support{at}mizapro[dot]com)
Takedown time:8 hours, 30 minutes Good (down since 2020-09-04 06:13:00 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04dat_20200904_581049.docdoc 03cb9a738ad3ba7f5744d092532b2e578e9ade9b376af945fca5faf115b06c4bn/aHeodo
2020-09-04Untitled-20200904-014399.docdoc a7f7db7e743de3993fe73005b54d739c61d8b922446cf434ecedcca82c63e922Virustotal results 40.00%Heodo
2020-09-04ARC-3556.docdoc 05558fbc6250f15d45880b5ebfb3798d415fad3e982b503fd6b61e658d902aaeVirustotal results 40.68%Heodo
2020-09-04mes_968.docdoc b928a4ea1aae65b1c3ee2634f0d4d3bba7d8f0d7bd647c3befb30ba0f8b6a1abVirustotal results 40.68%Heodo
2020-09-04REP RN35102.docdoc 6c3530951ad2bde0a96b5bda4698fb3638e360f5176d3f6aa4f9ea0570a3f45dVirustotal results 40.00%Heodo
2020-09-04363_20200904_7303603.docdoc f1d06faa66ff49136e73546caaa462dec1fc01c209288126d019c0c688f6f5d9Virustotal results 40.68%Heodo
2020-09-04dat-20200904-YQ560.docdoc 886d63b614006458acc2c30f3864476e896c318a90248243fabf63f0e992f712n/aHeodo
2020-09-04Dat-20200904.docdoc 6333175d3560cf42c1b0b3631cfe1302ce937aa2b85c3ecc3407cfde4c9cf37aVirustotal results 40.00%Heodo
2020-09-04Inf 2020_09_04 IFO315323.docdoc 90d7013803edb798ee2da7fcf3de07420ccd536dd01c96d0c787a80c0923f08dVirustotal results 40.00%Heodo
2020-09-04Untitled-2020_09_04-2378.docdoc 113f271d566b508aed976158e057211703fe30c314960665466fe58d9e08e50bVirustotal results 40.00%Heodo
2020-09-04Rep 2020_09_04 LXH17664.docdoc cbf75dba4c6b4f8cbcfb647112f9a0a4f8efb293526aea73ffebcd800379e08fVirustotal results 40.00%Heodo
2020-09-04Arc-17664.docdoc 595e8a24f2e5e51e56138296f7c6cd58e709e8f532dbacc38ae66f462e0e071dVirustotal results 40.68%Heodo
2020-09-04Attachment 20200904 I297291.docdoc f9cb536060fce2bb170aa95f67947db48d9b7e43e2095dad2337eda509017040Virustotal results 40.00%Heodo
2020-09-04LIST 2020_09_04 VI207979.docdoc 9cf29b7fcce905e807fd1e4493af36f7f0e8618912601f1a85cf52af6d38d6b8Virustotal results 40.00%Heodo
2020-09-04REP-2020_09_04-156882.docdoc eaab7e71c3da44a79d28d2bef0582eeadb430df7d20febba2eed46323d6dd3eeVirustotal results 40.00%Heodo
2020-09-04MES 8235784.docdoc 6300e903bf3720bb91e4db31ad186d98f0b8307f0abd3b785145f72f0a89edefVirustotal results 40.00%Heodo
2020-09-04REP-20200904-B5041.docdoc ee7586771fa02df0ef18b9f88c3bb45135371e5f7a16f6304b1b500a99a0ca6eVirustotal results 40.98%Heodo
2020-09-04dat 9331.docdoc 0bed9ceb6c02ac01c38804705e397d72379abfba81c416c2deca29e08e32bd54Virustotal results 40.00%Heodo
2020-09-04arc_20200904_825053.docdoc 69e91274a22bb98b54013be9509ad757c17fd9ab44d80c5a8585ec639ea6f04bVirustotal results 40.68%Heodo
2020-09-04inf 2020_09_04 3206.docdoc d6da8adc7df4680bdfe56aded8385d20e63b8af6ac83ff2abdccf2910232809bVirustotal results 40.00%Heodo
2020-09-04HZ873 20200904 425907.docdoc 945f9c6c84eff86e098fcb02268e716fb80f5c6fa8a5e64e08175a306d3c0a2bVirustotal results 40.68%Heodo
2020-09-04Attachments.docdoc 39f12f314a1431044af9b7061ac6b7b2d68e29927ba8650ecfd4a5a41337922cVirustotal results 36.67%Heodo
2020-09-03File_8087.docdoc 5b1c5637bea570eeef52ff79044a41de92de4e33ddffcde3b3611bee6fc8e5b1Virustotal results 36.67%Heodo
2020-09-03U991-KG07952.docdoc d313ce8483aa86f33b4fb8f8eaf32cc9162fea1ecd980baf5fb9ae5ba1e2024cVirustotal results 33.33%Heodo
2020-09-03doc_20200904.docdoc 9e3d362ff8dc1daec89813f11f73bac91ac2ee3f97f803fd413522874432ebb4Virustotal results 32.79%Heodo
2020-09-03Attachment 20200904 BM827067.docdoc bf1b9f0a76233f9cc5983b3b48fad1f4edff9c94e363dbab7f91cb8050ab315fn/aHeodo
2020-09-03MES 20200904 BWQ014241.docdoc 10d9f95cbaae87c8e1ee5a2d4ed21022d9a419859eb29f5cb055497a345006a1Virustotal results 30.00%Heodo
2020-09-03inf 553.docdoc eb96e6409fa3b1e2510201d45d3a629be387c1d50ca84645b13d0614702d7c62Virustotal results 29.82%Heodo
2020-09-03rep-O0061.docdoc 184ba331ed727480fd65743bfe0cf1489eca3b4d49b68a31b970ee96288c9484Virustotal results 30.00%Heodo
2020-09-03File 2020_09_04 QFH20219.docdoc 657e6e8ae1d0a5dd81e22e4c5966596510d091f0621e520d9f85c46ddad6f3b2Virustotal results 30.51%Heodo
2020-09-03Rep-20200904-247.docdoc eff6ba195fc7d083d41cc3c5d0bf90588ba4de22599bc9adeb053e04f0f4d55cVirustotal results 30.51%Heodo