URLhaus Database

You are currently viewing the URLhaus database entry for http://givingthanksdaily.com/OCT/lm/rJIuu7qfdLavw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:610717
URL: http://givingthanksdaily.com/OCT/lm/rJIuu7qfdLavw/
URL Status:Offline
Host: givingthanksdaily.com
Date added:2020-09-24 21:27:33 UTC
Last online:2020-09-25 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 21:28:02 UTC to abuse{at}servercentral[dot]com)
Takedown time:4 hours, 43 minutes Good (down since 2020-09-25 02:11:16 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-25Arc 604.docdoc b3e2591fc238e7efeffc513b0f9c09b0e4c54864942c923903ee278cdd673aeaVirustotal results 30.65%Heodo
2020-09-25REP-20200925-PF17225.docdoc b4da5a271c46eb9d526edea40d4f641a1a0da3dc6048ffc493b8fece7044022bn/aHeodo
2020-09-25doc_822988.docdoc cf6220f85629ed88cd425df3df4dabb7f8a4f4cfabacf433947df4382d5731e8n/aHeodo
2020-09-25Rep 20200925 NOC0756.docdoc cebd7c93a666d0a79cff9edb88403e8a8318dcaf5cc86c52c65fe834fc87e995Virustotal results 30.65%Heodo
2020-09-25REP 2020_09_25 PFL8750.docdoc 56449c1547f4f8c26d45ff0c90715b0174ee6d994f9818886dd1e4b392d63615Virustotal results 30.65% Heodo
2020-09-25MES 738.docdoc bd497f91d1b3471692be59bc55fb9a4bcd885d680ba65087f99431f0be67d62fVirustotal results 31.15%Heodo
2020-09-25ARC-INV6192.docdoc 30764cdbbf01f356c76a2a12d07a2790ddfc8b485fb87998f945cd77ab79ff3dVirustotal results 31.15%Heodo
2020-09-24Q273 2020_09_25 7695.docdoc a7bf6cee3dca01f25d30af7e184981a1d239058da20311b95129408827f2d98bVirustotal results 30.65%Heodo
2020-09-24Arc_20200925_5135428.docdoc c8e79fc0288a89ec2d815e21d6d7f396bdbd52530a889df128b23b14a212f602Virustotal results 29.51%Heodo
2020-09-24ARC 018495.docdoc 55c07a85acf2783c3aedcea2b6d5b549b5410eb30b725b6751cd4b77faea914cVirustotal results 27.42%Heodo
2020-09-24doc 20200925 T163088.docdoc 1632ea7fdf8e7ab955b1357fe5640e06aadcfb91202f35eba24bcff15b298b3dVirustotal results 27.42%Heodo
2020-09-24Attachment-20200925-HQQ42673.docdoc 0dfd7348c12f85a4b7b71a09910827abde365fa4ce39d433074932e2df13c5f4n/aHeodo
2020-09-24rep 2020_09_25 9279261.docdoc 9c110a7d6411d6083aaf8b1342c7eeb9e42d0065ce10ea3b464f442aefb301e1n/aHeodo
2020-09-24arc.docdoc d01c0581ba66c774c00a1cb25f37587e3fe65779511a052b3cad52a6cf4329b9n/aHeodo
2020-09-24doc 2020_09_25 524609.docdoc 2c6d5d8658794ab29bd0a4855dc9d7a05858fdc4f986c0949570dccb299a2e9cn/aHeodo
2020-09-2443595OY-DZS04206.docdoc b8ea1fffcb486edb0dc9103f8558138cd3af6dfc0ec110dea350bead36bd6d9an/a Heodo
2020-09-24043545 20200925 SF623667.docdoc 71830393dfbcf6aa54817c645aa34fda5360ed92f5ab1407d9a952d0a06325bbn/aHeodo