URLhaus Database

You are currently viewing the URLhaus database entry for http://gforcems.it/modules/D/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:509378
URL: http://gforcems.it/modules/D/
URL Status:Offline
Host: gforcems.it
Date added:2020-09-15 05:48:05 UTC
Last online:2020-09-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-15 05:50:47 UTC to abuse{at}register[dot]it)
Takedown time:9 hours, 34 minutes Good (down since 2020-09-15 15:25:39 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-153K7PEKjeJ23.exeexe 021ac3f50ff3b6829b4f5fca1ca1fbf6fb714bf7aa9a65524b7d6a22386518d4Virustotal results 10.29% Heodo
2020-09-158CMPk3QwRPkeEE5Fm2.exeexe c9a8a5311a790d667dac11b9b650efb5ac325942399047e5f3760b58c0c67fccVirustotal results 7.46% Heodo
2020-09-157Z84CrwbuC8pmT.exeexe ee0bfe1f301243ecab7dd9953993bccd4a89ca6055a9ea77db0503d3bf2b3058n/a Heodo
2020-09-15NSPnCOarNp.exeexe fd9b0c1431068bc0a176f5fc2b8c1f450e96f3b2fe80fa83a41ae2af67cf232dn/a Heodo
2020-09-15qA8Ppx2s.exeexe 6e96ecdc9c0c90fb61424c12ff445ac6c6fffe774f7510d154a21cf386ccc4aan/a Heodo
2020-09-15mbDrD5ZdeAKA.exeexe 635c57719f481055d1e3da415437d9e751d0bda50e285f6bda7085a96669b9a0n/a Heodo
2020-09-15sI5.exeexe c6e102fdf7df2fb136f4b0ea3c989aa80bbde8a66cd643cf3b5929c0b3bba4b1n/a Heodo
2020-09-15UMkq7G3rKsx7Jr.exeexe efc01288f37584ceddef4c13d22f9e51383ffe8c1c261dc3568665db36aecf10n/a Heodo
2020-09-15o.exeexe 9d26ce2cd6032b5dcf288e117ee45c04d9fc72f642b7e1701093140fe3f8035an/a Heodo
2020-09-15R1fYwGHbN.exeexe d02744aa4b1e97d2f1bc5dd0eb93e4585aca98244673f0171cb52ecff278e73fn/a Heodo
2020-09-15CzzWvxvWQnt.exeexe bb016db5ca0d53fbe4c464e4718bef90e4cf46f930d06b7869c94278c279c9b4n/a Heodo
2020-09-15GJaQbtTLSHdkrLGq.exeexe b00452e5a2f5944327f150f62dd0bb2050e52af4721803f2aca36321242acfb7Virustotal results 15.62%Heodo
2020-09-150BB60BPvvkvRv3J60w7V.exeexe 5be7a56599e1da2758bd361a5126bcccd7d66e8c8f2532879475f47e46022bf5Virustotal results 9.23%Heodo
2020-09-15EhbI0jLYOZwY9.exeexe 8b53378aa6f2c8087c388c6f1ac9e269afeb18a569305879a688dde94011e980Virustotal results 15.15%Heodo
2020-09-15Z.exeexe 11e8ce4e1abf9d994bf74af6160856b76c2a1b62bd620cde2445db0851efcdc5Virustotal results 22.39%Heodo