URLhaus Database

You are currently viewing the URLhaus database entry for http://goftmanclinic.com/wp-content/https://paclm/zov62GSzbJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452853
URL: http://goftmanclinic.com/wp-content/https://paclm/zov62GSzbJ/
URL Status:Offline
Host: goftmanclinic.com
Date added:2020-09-03 22:41:02 UTC
Last online:2020-09-04 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 22:42:07 UTC to abuse{at}hetzner[dot]com)
Takedown time:10 hours, 2 minutes Good (down since 2020-09-04 08:44:16 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04doc OS241993.docdoc bfa8973f2e13b6e793f43e4c1d1b68e81e7928903e0f8edf9fd3b146ee1cb9f1n/aHeodo
2020-09-04Mes_2020_09_04_B5715.docdoc a44af5b41212998f1fbe2710a20194236275ea73fe20d136c36ab549738d00ean/aHeodo
2020-09-04Mes_2020_09_04_0198.docdoc bbb72c4df6c036dd3b187c18c6ba7bf547ed934e658bdcd5d3c23d14d244c2eaVirustotal results 23.33%Heodo
2020-09-04DAT 46221.docdoc cf9b7b986e763e7ed395622f0e81f3ae662f65397ca0717169ada8127afce47fVirustotal results 22.03%Heodo
2020-09-04REP 2020_09_04 3763125.docdoc dd4feaa43e89898264a8512b2339c67fb1207b97e5c6c216fe656ff6234c0098Virustotal results 21.31%Heodo
2020-09-04Attachments_20200904_8675.docdoc b4f22acb6197b89450a7b616c2611c5090939fb7e1e661b1b479048d34243901Virustotal results 21.31%Heodo
2020-09-04FILE 616489.docdoc b73bf6b8c71126f090ffbab7009d10d3841a42ef4ea96a8c2450a8179a8df736n/aHeodo
2020-09-04inf 20200904 417.docdoc 4e3917d545fe670b0ea8dd1cf91701595c3cbe5ab87b5c53a826514778bad6f6Virustotal results 43.33%Heodo
2020-09-04FILE 2020_09_04 3066.docdoc be658261ea85360800d4b052f23fd96dbadfe7171d308a38dba22b5fe4efadf0Virustotal results 41.67%Heodo
2020-09-04inf-20200904-YS4101.docdoc 4abe421f4bf82588ca7772c685416eab8133054e1ae9fcedc245167e272b6105n/aHeodo
2020-09-04REP-2020_09_04-USS190556.docdoc 933a5acf70c2c8f24a3d359a43ab898e556cdcae740ddcaf33acbc356ae1d9d5Virustotal results 37.50%Heodo
2020-09-04inf-20200904-MH82204.docdoc acb81dc6508ccc95393a57308575ed700b2dca51e4f0658f6ce9dacfd214dd3fVirustotal results 40.00%Heodo
2020-09-04inf-20200904-RC39658.docdoc 0ff1c95a7d850d74903fb10610c4d99e54fd900d51cad0f2deda82e1122f403cVirustotal results 40.00%Heodo
2020-09-04Attachments-2020_09_04-B15928.docdoc 2fcecf7ef769ae49ecdf3905e7c5e7aad9a7f0ac4279fe518ed0108f25a0ec79Virustotal results 40.00%Heodo
2020-09-04ARC_2020_09_04.docdoc 6bb0dcdffbd9df010a6d7951c4a8ecb8596b694a6b4f59c866f30a012bc325f5Virustotal results 40.00%Heodo
2020-09-04Attachment-20200904-9265.docdoc b928a4ea1aae65b1c3ee2634f0d4d3bba7d8f0d7bd647c3befb30ba0f8b6a1abVirustotal results 41.38%Heodo
2020-09-04Untitled 20200904.docdoc 027746c91762be2cd5ecdd301acedfce96399a7961478130a7c6e26d2e47ea3cn/aHeodo
2020-09-04UNTITLED-2020_09_04-SJK656011.docdoc f1d06faa66ff49136e73546caaa462dec1fc01c209288126d019c0c688f6f5d9Virustotal results 40.68%Heodo
2020-09-04Arc_2020_09_04_6016341.docdoc 9a9c96896e784dc4ac0ff44a3052d2ff2d7cb744fcf3255981f30894e95d6c42Virustotal results 40.00%Heodo
2020-09-04REP-2020_09_04-70599.docdoc b25414b4b759b6517cfc1ce36e58d10a5aac59912adc8230095f50f6659af778Virustotal results 40.00%Heodo
2020-09-04file 2020_09_04 J33669.docdoc 90d7013803edb798ee2da7fcf3de07420ccd536dd01c96d0c787a80c0923f08dVirustotal results 38.98%Heodo
2020-09-04mes_2020_09_04_F667772.docdoc 113f271d566b508aed976158e057211703fe30c314960665466fe58d9e08e50bVirustotal results 40.00%Heodo
2020-09-04INF 2020_09_04 9832550.docdoc 2f40ae83dd7e6ea630b731213a7f9629565af65eca2bf9990d77114dc2b441e5n/aHeodo
2020-09-04dat-2020_09_04-9296.docdoc 1fa1544383bbda2ef984f9c0a8a1e3ec9c37ede4a0e897d8177d7e92d3809ea1n/aHeodo
2020-09-04Inf-20200904-47657.docdoc 595e8a24f2e5e51e56138296f7c6cd58e709e8f532dbacc38ae66f462e0e071dVirustotal results 40.68%Heodo
2020-09-04file-2020_09_04-WR797380.docdoc 9cf29b7fcce905e807fd1e4493af36f7f0e8618912601f1a85cf52af6d38d6b8Virustotal results 40.00%Heodo
2020-09-04rep 20200904.docdoc 41b51c9c72e134b6a5183ee31357d58d19e875c56db068adc0b5f8a3d12bdc3en/aHeodo
2020-09-04EOF961-X74372.docdoc 6300e903bf3720bb91e4db31ad186d98f0b8307f0abd3b785145f72f0a89edefVirustotal results 40.00%Heodo
2020-09-04Attachments_2020_09_04_VTR416.docdoc daa812c082d4d470cfad19c540bfc6ea7adbcd3859273af885dda81d2722e1e1Virustotal results 40.35%Heodo
2020-09-04LIST_20200904_OMJ529.docdoc ee7586771fa02df0ef18b9f88c3bb45135371e5f7a16f6304b1b500a99a0ca6eVirustotal results 40.98%Heodo
2020-09-04FILE 20200904 2801.docdoc 69e91274a22bb98b54013be9509ad757c17fd9ab44d80c5a8585ec639ea6f04bVirustotal results 40.68%Heodo
2020-09-04inf 20200904 05015.docdoc d6da8adc7df4680bdfe56aded8385d20e63b8af6ac83ff2abdccf2910232809bVirustotal results 40.00%Heodo
2020-09-04list-2020_09_04-EMK23271.docdoc f5ace8d328883020ed6b37dfb50687886670fba064afbbbbf6e9e695ce35e490n/aHeodo
2020-09-04list-20200904-4707766.docdoc 479a6416cfb665d2d0f0b6e39d11282a0d31d799d87898d50f066e8d564808f6Virustotal results 36.67%Heodo
2020-09-03Arc-20200904-Y631.docdoc 62f2e2f1e282bf930eaf8a31d9904112fa33e4c5bcb2d14f0efc91df5351ae54Virustotal results 35.00%Heodo
2020-09-03REP 2020_09_04 555.docdoc d313ce8483aa86f33b4fb8f8eaf32cc9162fea1ecd980baf5fb9ae5ba1e2024cn/aHeodo
2020-09-03file-2020_09_04-BW546.docdoc 5870705910f4290f13346efd3c9113483974723cc840cd330844efa6f5b3be19Virustotal results 33.90%Heodo
2020-09-03DAT_20200904_OPP139184.docdoc 939b166130d34042d2f4e49e43067b7670e409ae8dfe5e7d675160a838878230Virustotal results 31.67%Heodo
2020-09-03File 2020_09_04 ZO5996.docdoc 1665a376712705dfdb732a6d623d3e5802e79b68082691dbab100757b018cb8eVirustotal results 32.20%Heodo