URLhaus Database

You are currently viewing the URLhaus database entry for https://gaanda.com/wp-includes/OCT/4f79WRMKbVWJwvBXXjU/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:624367
URL: https://gaanda.com/wp-includes/OCT/4f79WRMKbVWJwvBXXjU/
URL Status:Offline
Host: gaanda.com
Date added:2020-09-29 18:12:34 UTC
Last online:2020-10-02 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 18:14:04 UTC to abuse{at}wholesaleinternet[dot]net)
Takedown time:2 days, 15 hours, 54 minutes Poor (down since 2020-10-02 10:08:49 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-0137874453.docdoc bca937c5b07cf43a6469fae63640f655c5bbdacff9c671b53965974a5203c262Virustotal results 37.10%Heodo
2020-10-01Attachments_2020_10_01_JY0654.docdoc b2af72414cca6a559fbc5e9254b6080ce9d292ef4b2a37d8973118f7fffca277n/aHeodo
2020-09-30list 20200930 ZKL927656.docdoc 90de4105fc91aa76e474d5d94fe9fd26b8d6983986653c2d8592f39376ba5652Virustotal results 23.73%Heodo
2020-09-30HR61615-20200930-2553006.docdoc f6ed8a2b25a6f8f693aa0aa17e1a77c02888113452cbbb4efae319131fd375ffn/aHeodo
2020-09-30List-2020_09_30-LV645078.docdoc 2fbc53c50b9b33c49311e11a41aa64660b305c9c7d4a4db3986c59a1a77696a8Virustotal results 22.95%Heodo
2020-09-30Attachment_20200930_HB37448.docdoc 6332f6b0886bc926911339247b72278894fc0667a705e120fa356efd3691962bn/aHeodo
2020-09-30FILE-20200930-PPF6114.docdoc 30a7ad680eae9fb430a78853e35fd6cb80bdae54566ed12b89279174f8a26f7fn/aHeodo
2020-09-30List_20200930_55875.docdoc ce1d7fe9a715dbd5b408b17ff12010a67d3d1d002a9484370931304e35254f12Virustotal results 22.95%Heodo
2020-09-30Dat.docdoc 2bc311aff7d90ac42c818d1850c8eff0fca326e6c334899f8041c63a59753465n/aHeodo
2020-09-30ARC-Z03940.docdoc fce9dd88327154889e459164ac4d29d0063315340b5ffd9690868ad5e46c352fn/aHeodo
2020-09-30ARC_2020_09_30.docdoc 5dc39fed6361864ebfcfe504125bbc05e085ad4f1fb6c92a3367bcad83b695cbn/aHeodo
2020-09-30LIST 20200930 40919.docdoc 4c25015ae6e259e42564c6b03066111433ae12f8488364a45ab1e6680d708350n/aHeodo
2020-09-30FILE 32336.docdoc 25b7f727f0f1e44dc0b90a12f28264418053fc308ea16c0050ae887a1db7d5abn/aHeodo
2020-09-30Doc-20200930-3006.docdoc ae08f6ca3d49c7a6f89007400a01827f8fa1e32ea4d88e4e38ff705f70c810ffVirustotal results 20.97%Heodo
2020-09-3067277-2020_09_30.docdoc a3f7b976b0c108284bf0de59187798f84d509ad7182c92761cedbb9b35ba4a3dn/aHeodo
2020-09-30Inf-DS009.docdoc 848472a593e725755e8a0b52a61189cab28bedfa9f8d62a7a528790838e7d9acn/aHeodo
2020-09-30list-2385.docdoc e750318c6f5ae04efc1b912fd250a9bdf7c83ce3289a31f303d03bc0e9e4b11cn/aHeodo
2020-09-30FILE-20200930-MQP5985.docdoc 464e4eb4c4d1fe1f13e2d9a96e6ebbb73ccc5f8dc2bd333a286f1e07d85899b8n/aHeodo
2020-09-30ARC.docdoc e4c0e12e6e90cabe22fab698bc2684a13e9719668942b682bfaa1ea0bd3336a4Virustotal results 20.97%Heodo
2020-09-30691 56033.docdoc 4b795f3870e608b6c61e4a7757d87deb5525949aadeb15393e2b83cb4b34e618n/aHeodo
2020-09-30Doc-2020_09_30-83779.docdoc 6203971a2e4b246318cba558f864664aacc3cc5dae07aa3b8ce1fa6fb17d590dn/aHeodo
2020-09-30Dat-20200930.docdoc 3bdee9fdd814363fa073be396eda19d9242d4bfd82702110dff7564d61ef4a8eVirustotal results 46.67%Heodo
2020-09-30LIST_2020_09_30.docdoc 869911e995bc11a3a2e87a02de6611b59d26ddd5b21c6c77e72f327620f526c2n/aHeodo
2020-09-30DAT 2020_09_30 5748.docdoc b91cb11be0bd9f80cec08a069751a27ef60de586e87e2ba9f8d2a4dc266f879fn/aHeodo
2020-09-30File_2020_09_30_OHE084.docdoc 89512a4396d991ea5a6384037a7418d9f30bfe1d444f2fbef7a0c0b5f2f421d4Virustotal results 45.90%Heodo
2020-09-30FILE 20200930 S050.docdoc 6dcb7e9d3ef574e032cf8d4f7da8e1ddefaea58991677a7e53be13723839e09dn/aHeodo
2020-09-30LIST_20200930_05623.docdoc c5fb0bf46e7abc0dc192a51dc5e8c8f05df4c91bd08dc53d536cd4ffbf09f89dVirustotal results 41.94%Heodo
2020-09-30Attachment QUL268.docdoc d21a659e131509501f27e12765fa2f8ea25eeed319cd31587ba7457738e3f06cn/aHeodo
2020-09-30MES 7257.docdoc 67d283b362bfdbb0db8f7a103bd5c1c3c7fadbb22b0cccc5b0cea1b48d1bcd16Virustotal results 40.00%Heodo
2020-09-30dat_655.docdoc 3e16472eff5bf2937b0f1833264ef998b9f6339e36a135499b25cfa8e794b33cVirustotal results 37.10%Heodo
2020-09-30Attachment 20200930 P5556.docdoc 329d9911d2004877126f938ba6875d9f348d33b31e1ccd880a2a62adb461d1a9Virustotal results 32.26%Heodo
2020-09-30Doc_20200930_GSN2039.docdoc 1b7ae75c0843e24188c16e98283ae53b2d5d441a3149a30eae0eda9db7781220Virustotal results 32.26%Heodo
2020-09-30Doc-2020_09_30-344313.docdoc 07f05248ebd561f95c8b5988fddd0396c6d3c0a61015e3cf154e1e97f2af015aVirustotal results 32.26%Heodo
2020-09-30DAT_2020_09_30_5807785.docdoc 10f4a118d75e59c1f0ae83e7e44c9553fd6925a4bcf21a4cb62559c38c550147Virustotal results 31.15%Heodo
2020-09-30Dat_2020_09_30_1899284.docdoc 9d6a2742e7b189220132964cb3ecc21eb2bf93bf90143787ab21937cbb1b2e5fVirustotal results 32.26%Heodo
2020-09-30FILE_S1700.docdoc 1d5392f655dcdc6f812366e57505b4f345c53a8c5ede33a7f7b9d6e05c3deaefn/aHeodo
2020-09-29doc.docdoc 98c87f2f2e124f5e8444896304f556a844430d6543223343abc894702abf99e3n/aHeodo
2020-09-29list.docdoc 9a24d61f24a1211065b986def505c02b66a94f2b1cbde8fc6ef868391c24d4f3n/aHeodo
2020-09-29FILE 2020_09_30.docdoc 1d742e585ed7b4c237726a945da11795c46da01716e9da561d98fff100ee938fn/aHeodo
2020-09-29rep-20200930.docdoc 08c3a51969b9ccfcd46ad14ef1a7599a798c21e693a582ac6d8f449f77f4fc09Virustotal results 29.03%Heodo
2020-09-29REP-3041.docdoc 32a76ed8013dd82d6e6063013236d7fb37bb205dbd6ff84ab785e5af12e6b3f0n/a Heodo
2020-09-29Dat 20200930 1530982.docdoc 004d7159e2360d1569de7849fbd5ffa3e63968d011834c565255ade18fcd54cbVirustotal results 19.35%Heodo
2020-09-29MG1874_2020_09_29_V0174.docdoc 32049385466cefdb6902bff7a1c1c93274f20eb51842f1dc68a84e5de14716d1Virustotal results 17.74%Heodo
2020-09-29file YY749948.docdoc 275a46a9c86fcb536d7dee38a273fadc27066204b68ef852423568f9f925ae81Virustotal results 18.03% Heodo
2020-09-29inf-7759614.docdoc f363539a468889742abe35748f7f351c58d42294cf01ec320abf7642d5bed79bn/aHeodo