URLhaus Database

You are currently viewing the URLhaus database entry for http://graphicom.it/cgi-bin/LLC/vpgiw3xgz/kn6u825561263670nh5ck6bz6n4uesv2p07d/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:546791
URL: http://graphicom.it/cgi-bin/LLC/vpgiw3xgz/kn6u825561263670nh5ck6bz6n4uesv2p07d/
URL Status:Offline
Host: graphicom.it
Date added:2020-09-17 17:23:03 UTC
Last online:2020-09-18 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-17 17:24:04 UTC to abuse{at}register[dot]it)
Takedown time:19 hours, 11 minutes Good (down since 2020-09-18 12:35:41 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-18D_96892478.docdoc 7b8485c7067c35f26898e3b893e3f3832bedbe6002242a18835c42a78f48f581Virustotal results 23.73%Heodo
2020-09-18BAL_21860760955137.docdoc 6abcae841dce14d172e12d2c27729756c194836844ccbba13a69617a31dbdd07Virustotal results 23.73%Heodo
2020-09-18S_SVX_090120_WXB_091820.docdoc 83676faad35894bb04262d898f1279995a52ca4f91f343223e0403b6c915311eVirustotal results 50.85% Heodo
2020-09-18INV_DN2041551212WF.docdoc efa82129d7abf7ede76e162844581a869016b5bcf76e6dd7443e2caf1f4a73b2Virustotal results 49.15%Heodo
2020-09-18PO_09182020EX.docdoc 8f433669bafea35f75ac63a4e6aba4cb6345029b4f5d32f42c177071467f9623Virustotal results 41.38%Heodo
2020-09-1886340506.docdoc 7a087796ba52981da1f8e06f79b5bd1bdebeb961afe1f01af7864edfe071712eVirustotal results 42.37%Heodo
2020-09-18V_PO_09182020EX.docdoc 7c59a227af18d0ce74f71bcd465aeb811332968c24b837a6d9761a61bf0b2abdVirustotal results 42.37%Heodo
2020-09-18PO_09182020EX.docdoc 3c04b25b3db13173771d70f4aa9fd25006b34fc0c02f707f2dbd8f9b15938720n/aHeodo
2020-09-18PO_09182020EX.docdoc c77851ba151f09f555db36179250d20da6817e32999215d3ba13dd47898e8fa5n/aHeodo
2020-09-18REP_PO_09182020EX.docdoc 4b9a2688db3fd6465d84ee5baf9fbdf6c50772a16d3e7c265c758ae284e8a63dVirustotal results 37.93%Heodo
2020-09-18RBK_090120_DVQ_091820.docdoc fd659c59f931854b96e0428e622a370da964253713c66c1b28343011322629daVirustotal results 36.21%Heodo
2020-09-18FILE_PO_09182020EX.docdoc 6e221be1094865f6f92e91e222da06c0cfb67ce691d0bd25afb4b4324bb05714Virustotal results 36.21%Heodo
2020-09-18INV_LYO_090120_ZCF_091820.docdoc 4a6e1fd8e8858273824ae02adbef685cf16079c6baa36e1ff244a6b93db151b8Virustotal results 35.00%Heodo
2020-09-18INV_29275392.docdoc fa5d401c1fa37a461f925c0ac23b8d1864c0081416c0b6494f9ba40ad25851eeVirustotal results 34.48%Heodo
2020-09-18Q_QN1145440904TJ.docdoc d95aeafb85cdd18684d7a50288bd895c7549455d652bc1997dc4b27c26788c92n/aHeodo
2020-09-18INV_883244674125736155065.docdoc 6098ea8b508e01b7b777f7e9ae9b62e69f4e95a1bf8342c4d7ad98e5559d70d1n/aHeodo
2020-09-18SF9037273986JI.docdoc c63f6783c00a837e235c2c2405fccfe135bf4358704dad7525b4660588e6ed3aVirustotal results 33.90%Heodo
2020-09-17DOC_6488595160404105471.docdoc 074d30932dc73bf17312105a7a4a157bd6cd44f75ce2cd67026282c6bdb3b21bVirustotal results 34.55%Heodo
2020-09-17D_PO_09182020EX.docdoc edee77f468412b29903ec095de648b2214e471174deffc438b41cb18fed1058bVirustotal results 33.90%Heodo
2020-09-17BAL_G889ZAD.docdoc 24b4b9f235edf4c63faa8b1722508868d0727dd455e4abcbdaf1ac38eb379dfen/aHeodo
2020-09-17DOC_CZX670LEQ7SBHP1C.docdoc 18921283b9df87bfd574d3b19108c1b987dc19729196d6d54235ec8c102b4e1fn/aHeodo
2020-09-17Q_BP5513265341CR.docdoc 12d6b38f752ecea5e77fa8c3623f322427bd77fbe3070efe165d432a739f4bd1Virustotal results 33.90%Heodo
2020-09-17INV_BOI_090120_UWT_091720.docdoc 794d05a964943c6e59eef584b6bd5ee060dec7907a990ec1a0d71260e641c74dVirustotal results 47.46%Heodo