URLhaus Database

You are currently viewing the URLhaus database entry for http://gnhtech.com/wp-includes/https:/eTrac/mtj4OpoDqrQ9QCIUdb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453445
URL: http://gnhtech.com/wp-includes/https:/eTrac/mtj4OpoDqrQ9QCIUdb/
URL Status:Offline
Host: gnhtech.com
Date added:2020-09-04 17:42:06 UTC
Last online:2020-09-07 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 17:44:02 UTC to irt{at}nic[dot]or[dot]kr)
Takedown time:2 days, 15 hours, 35 minutes Poor (down since 2020-09-07 09:19:42 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-05Attachments 59527.docdoc 4c3f9a91ab8bd67a7de8b61f6d5e49c34a0c3ded123f63205f02d17ff570c204Virustotal results 30.00%Heodo
2020-09-05rep_20200905.docdoc 8abd1fd956a522b05535b6b9ddb53a6c4353e20235979a9ed05679ac4f2a95caVirustotal results 29.31%Heodo
2020-09-05mes-712913.docdoc e598cf9a18d4db4fa8174ec8f921eb470f8b844063cec6fa35185f7f8f1d2b4bVirustotal results 30.00%Heodo
2020-09-05FILE-2020_09_05-X16872.docdoc a40dc3b53e82da4c96b2c8992f76d33a202fb13250e9864acb72d617aa2ea7e7n/aHeodo
2020-09-05UNTITLED-183.docdoc 36db57afc7d4faa57d7bbd559db7ca4ae2bd483caacaa9fba1a3cc6839b240a3n/aHeodo
2020-09-057601504 387223.docdoc c687016b2136760124efe54694e2980e93b56aa5278ec587b7290a01f02c93fdVirustotal results 30.51%Heodo
2020-09-05Attachment-2020_09_05-EID013.docdoc 54fac54bf401937afa1a48e9545b32e46ac8be7c543918e4a841177baf879ea3Virustotal results 30.51%Heodo
2020-09-05Dat-2020_09_05-COR036898.docdoc d4c076603f475a562c8771e360b65b734aba563731f4417b117ecfad4297d562Virustotal results 30.51%Heodo
2020-09-0598030110_20200905_XOF901101.docdoc 27ad65edce895a8ac105708b7510859313c9f88cec6a66611b581bc480ad6676n/aHeodo
2020-09-05file-2020_09_05-J2785.docdoc ca1ecf3a84713ebe3b95b15bb7e7d4fe779daa81b1a2879feb79423222472ec8n/aHeodo
2020-09-05FILE_2020_09_05_M773.docdoc dd845235b8dc3a025eea6b0904c7e90b610afc290c4b55a7921062ba9f33cddeVirustotal results 30.51%Heodo
2020-09-05doc-2020_09_05-4291066.docdoc 62cc3eedb06b43f8a3e286b0a9f04cbf36fe240a532b217d91950ea20fa0ba9cVirustotal results 28.33%Heodo
2020-09-05ARC-2020_09_05.docdoc a6861aa553541ef958ad8dbfff87e748c920813dd0b745d69787b2818357158aVirustotal results 30.00%Heodo
2020-09-05List 2020_09_05 O39979.docdoc eda41409cac593fa280357f888dfed9313d45a2523ff59de058f32b76478d925n/aHeodo
2020-09-05DAT_2020_09_05_56762.docdoc b647104789174776abced7dc5a7abaa47fa349c4b21749ca3b6634e4f039da4dVirustotal results 28.81%Heodo
2020-09-05LIST_20200905.docdoc 173c9cfe44cb721e3d1edede6afda3a107dd78b74c1adb41c19fae5ae6a382d7Virustotal results 28.33%Heodo
2020-09-05List-20200905-HXT793830.docdoc 206feb1d69aba0e52a7d33975a49cc2a9443deb7bcf9fb4f8a6428ffcd95c97bVirustotal results 28.81%Heodo
2020-09-05FILE_9096213.docdoc 0ca5df179f725a9c12ba1385711972c7e55bc02359435e954db6e65f1e2036fdVirustotal results 27.87%Heodo
2020-09-054434038-20200905-327.docdoc dcb081f33d098bd8befd0776a185a13823b7a4f29087f39cfb3b1cc9693722f9Virustotal results 26.67%Heodo
2020-09-05REP-20200905-0582017.docdoc 2ddd8ba7251afbeee6c41576c377265c1a2a9f5370cd66683c24db0c89a0062dVirustotal results 26.67%Heodo
2020-09-05Arc 2020_09_05 577.docdoc 4f193825cdb87bbefffaa5925f7b422f06f0add25d518ea4f874acc892641968Virustotal results 27.59%Heodo
2020-09-05list-20200905-LD272465.docdoc 0917f0cbca78c19301ba65aa799b29dcf90ee3666fc9f8b83f00c5ea34a0eba6Virustotal results 26.67%Heodo
2020-09-05ARC PQK702477.docdoc 6914af81ae643d0106a7cb16454991e2b4d29053551e92e659456ad592120f57Virustotal results 26.23%Heodo
2020-09-05File_2020_09_05_J00162.docdoc f3c01505f223d53a856b4cbb5201b5cbad5706145be5e214e266f4570491a8ccVirustotal results 26.67%Heodo
2020-09-05arc-20200905-UG0657.docdoc 83d89a6f47106112698cbbe3f9f407abbefeaa5304896f38e7bff037db8cf901Virustotal results 25.42%Heodo
2020-09-05950Y-64772.docdoc d933cd9a8fdaa58bf021074d4dcbca7f3fed26971db346a66f8b2435afb70b50Virustotal results 21.67%Heodo
2020-09-05Attachment_2020_09_05_3391.docdoc 92bc3c4ef5b89ad046cb64e9cd6ee2eb8d1053b1b07620f1a0aa6503912b05efVirustotal results 21.67%Heodo
2020-09-05inf-2020_09_05-YGB406.docdoc 08946ba696e1f6e1da7e3f5cc61273c6d9c2bc25f61ff89151213d62d4c8e625Virustotal results 21.67%Heodo
2020-09-05Attachments 20200905 ZT099.docdoc 2d5d1fe8c77135420414a5cef6384683cfbf59f04e7e9b03c909c2f4c3ec54e9Virustotal results 21.67%Heodo
2020-09-05LVN672.docdoc 3c51d26e98137dad5c907c872c1af3b0faea7094df4acb08d71d8873e8800a9dVirustotal results 21.31%Heodo
2020-09-05file 2020_09_05 7879.docdoc 22834da2a4895ae43256bc32fc3c6faa89ec4389406f7fd25032bedea74bda9fVirustotal results 21.67%Heodo
2020-09-05FILE_JK7363.docdoc e5b5640cb999ccd3a5fa07ef28ecdb37ea16dbe142bd3cec619837a9c0c3baddVirustotal results 21.31%Heodo
2020-09-05rep-2020_09_05-NAS9206.docdoc 4c30d9c7120c06908f0bfdea08c45fbef17a72793a4688a2aa236899c0aa8d2bVirustotal results 22.03%Heodo
2020-09-0571878 2020_09_05.docdoc ac03cec1ea7e2d4ba254b3225a617ff11bb93247cfd84340907d0533522327e4Virustotal results 22.03%Heodo
2020-09-04UNTITLED_20200905_XV935318.docdoc 4501204cd406a353ac88516bb9f133148c882ea030d84403dc54bd0297f68b6fn/aHeodo
2020-09-04Inf-20200905.docdoc be5a076cc07b81d54fda54ef3c56f2d60ee214c3d1fe46de3dc59a1df619dc29Virustotal results 21.67%Heodo
2020-09-04rep-9240436.docdoc 6d8bb4cc926450189c32b7634d2940fba6556c2865096d7ccafec6b4b6e0c396Virustotal results 21.31%Heodo
2020-09-04Attachments 20200905 TL22117.docdoc 88d669402f9cb6d3c39a7de76b5e16c45d5db2b7a4e5c5f2b9ec112d299f85d6Virustotal results 21.31%Heodo
2020-09-04doc_20200905_4201.docdoc 137b5a0cda220100df4caefac31efe6cc85c4bd72580fe2ce1987887901d3ed7Virustotal results 22.03%Heodo
2020-09-04doc-20200905-HC035.docdoc bb32a5e79b853e76e64596002da4cf3b42d9e2c10db3f2b7fc7fd805fa43ff71Virustotal results 23.73%Heodo
2020-09-04file 91495.docdoc a8e4d449c8018f90196d3de6e14d75cdca5c5f76b989880e012890f87d43f6c9Virustotal results 21.67%Heodo
2020-09-04MES_20200905_8680593.docdoc 50d0908dff351c8fcdfd307f4c93cad6065d4c10c2614fd4201209f862681cfdVirustotal results 20.00%Heodo
2020-09-04Untitled-20200905-989433.docdoc e3986d10ba408aefe9c0f44c298dafcd5501ea916fc093cbff42c479194a9309Virustotal results 20.00%Heodo
2020-09-04DAT-20200905-6780605.docdoc 17387deff7e3725fb0ae1aacebcb5e9be101e9ad64a337ce858202ef07458f1cVirustotal results 20.00%Heodo
2020-09-04Rep.docdoc 4833c57c4ff48c2720247aa3bc9c8d62222f9fe3d095924030c344bfa8673847Virustotal results 20.00%Heodo
2020-09-04list_20200905_593.docdoc b177d6304e1239837128c14fc3423ded464e3877b918bdf27db3d2f40375c398n/aHeodo
2020-09-04dat-49584.docdoc 924f9439383931103e48f1a8618e3b5b0dc6e56ba52261116659d5dd2bbc3050Virustotal results 20.00%Heodo
2020-09-04Rep-2020_09_04-3847956.docdoc 9c0798c3e8889889ef70b039545920afb91f1508144606704a1889286192bbf9Virustotal results 20.34%Heodo
2020-09-04Rep_20200904.docdoc aa3db031e17cd90af00951bc4d86c18c8e42328f47e9014b552993ff1b29c557Virustotal results 20.34%Heodo
2020-09-04list 20200904 X931735.docdoc 623ee20c1b2e5a53a0bbf6eb21f4b87cb0e6392e023f1e08267abc08c26e5bbfn/aHeodo
2020-09-04doc-2020_09_04-99425.docdoc eb98e413719e07262040b6d92f4ffbfd9cad979d4fd8e59932902374dd33cbd5n/aHeodo
2020-09-04Arc-20200904.docdoc 627615216c18d1e8f7e1fd2774e09f54950e8068ccf5712cf072d21fc266763fn/aHeodo
2020-09-0400107R 2020_09_04 59154.docdoc 1fc138a263ca0cdda8039fa91f48947af5bb017930a2671cedb5bb01118e0b02Virustotal results 36.21%Heodo
2020-09-04dat-2020_09_04-790250.docdoc 5c5c03f78f3f69a8a477e4f0ffc787397ac1b6a1993c519ab5c64d6c9d87f499n/aHeodo
2020-09-042738493-20200904-96124.docdoc c567ea1fcaf384bfd2ad39165ea9b07fc04bfcbd325f7b3ecbe8c7329e65611cn/aHeodo
2020-09-04Untitled-20200904-843695.docdoc 95718b95b1e8732ffb58a93557e44c7e7f99a0dec4ab200ad2ffa83e6b455780Virustotal results 36.21%Heodo
2020-09-04Attachments-2020_09_04-62177.docdoc 9990dcb5b87f13e2c03f32484faaa9cbd123c53c9de007a6f49e879459e2ef24n/aHeodo
2020-09-04file-20200904-DF87658.docdoc 6c877a456539164bd26f3616e98e39cc8ccf75c2003dec0016ec825d2d1902cbVirustotal results 35.00%Heodo
2020-09-04list_FSL322461.docdoc 8a87e7dcaf07545941e8f4859526c55f0b840dc1d051e86b09200a3a49ba5c01Virustotal results 35.00%Heodo
2020-09-04REP-20200904-D756433.docdoc 07499f73c1b2290d3f1628c566a91f8f3bda896e9c9774c4de22d614a8b1381en/aHeodo
2020-09-04arc_46640.docdoc ef5176343779eaa99518b910aea7bc09e3f3c68b84d581e4762ede0c68729a0cVirustotal results 36.21%Heodo