URLhaus Database

You are currently viewing the URLhaus database entry for http://chuguadventures.co.tz/wp-includes/public/GC2AL6gmwpkwgHQz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:586076
URL: http://chuguadventures.co.tz/wp-includes/public/GC2AL6gmwpkwgHQz/
URL Status:Offline
Host: chuguadventures.co.tz
Date added:2020-09-21 12:51:35 UTC
Last online:2020-09-21 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 12:52:02 UTC to noc{at}psychz[dot]net)
Takedown time:5 hours, 17 minutes Good (down since 2020-09-21 18:09:16 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-21ARC_1212.docdoc a437e2c0bdceb42fa9b6d14a398043dcb832abaed3357f649ae4bd1756802dd0Virustotal results 24.14%Heodo
2020-09-21YW03376_FAO824.docdoc 70dbc4cb021488253faec5d8447c680d8bf7285fe74e0728c0c8051719877104n/a Heodo
2020-09-21Untitled ORB322808.docdoc f2047aa88b10b376fa4c25df0838bdd2e523b1e7593ef46bd6b460604d5c9505n/aHeodo
2020-09-21Doc-20200921-GCC475187.docdoc 356b82eeebe4eebc57579bc3932589783542b3b169a2f2c85dfa0c78fddb7ac1Virustotal results 23.73%Heodo
2020-09-21inf-20200921-IYB2768.docdoc 8624b86a85ad6c756c26034225f489ef15aa8cfcfdf0dafb529ab9a1718e075bVirustotal results 22.03%Heodo
2020-09-21INF 20200921.docdoc 42f29aa41b1f7d9de698db6b2a4512a76e4c54af72ab7ce26542fc3666438084n/a Heodo
2020-09-21arc_2020_09_21_V2591.docdoc 5a4026c992939e304da0cb25bcf181141d3875dec80db0003434902ca37ec64en/a Heodo
2020-09-21Dat_20200921_429084.docdoc c38007baa464dfca54ee9305c00ba166951dc23b5b4acf9fd9d28ae1ca04ca8dn/aHeodo
2020-09-21Doc 15090.docdoc d514c46c30e752ee22291f4cfce174467d0b7c6ee1506f12d854a4090fb65ef0n/aHeodo