URLhaus Database

You are currently viewing the URLhaus database entry for https://fabfamtrips.com/vrgcy/GWDGFXSSMDON/zi26rih0sl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:565594
URL: https://fabfamtrips.com/vrgcy/GWDGFXSSMDON/zi26rih0sl/
URL Status:Offline
Host: fabfamtrips.com
Date added:2020-09-19 09:34:08 UTC
Last online:2020-09-23 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-19 09:36:24 UTC to abuse{at}digitalocean[dot]com)
Takedown time:4 days, 1 hours, 40 minutes Bad (down since 2020-09-23 11:16:32 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-19931390108587485.docdoc e9325a711e0f6f605b85898c5b507d4320e1f1dc672c68172b06cda359b5107en/aHeodo
2020-09-197574937536009743693089747.docdoc f4914cbba852a170c0da8d021e223ecd72be23357cf6dfaaac21d926ab043885Virustotal results 35.59%Heodo
2020-09-19DOC_914186283119630746312.docdoc 9f77870d3740686f81155c4cca802ccb196cdd875714ed8e25d9a920d2d2adb4n/aHeodo
2020-09-1980413501.docdoc 336faca574dbafcf9eb66a5499f5b37d83a6ad046b7a8a7db5636040fa605429Virustotal results 35.59%Heodo
2020-09-1939013956.docdoc 48516090408f4d8cfbed9330748f7647d9e7c7d03fc6845dff52b900751f2c3aVirustotal results 42.37%Heodo
2020-09-19E_WP6043350248XY.docdoc fbe339f0f024e007aa6965b220a545dcdbe63fc8c877adfa47c8ba137b8c94een/aHeodo
2020-09-19DOC_PO_09192020EX.docdoc 1d1abdd47fc063e3d5a2ae7655ac0b570b3e34e2109a2154825ce1b59686b6a6n/aHeodo
2020-09-19INV_11963239.docdoc 1c8b7f12a321e7774f3fc6ef4a68c8ab12b525d9639168bbd5ec3b67ad260c05Virustotal results 40.68%Heodo
2020-09-19INV_PO_09192020EX.docdoc 7a015b6833969e6837d78d58ac9b507cdf02d2272798f7cef35fdf534b58b52aVirustotal results 40.68%Heodo
2020-09-19INV_CR7533794289TL.docdoc 6da6b99d1e7334c2df666c15e596c4fb9cca58c3f3891e9cc6676580e5b1dcbfVirustotal results 35.09%Heodo