URLhaus Database

You are currently viewing the URLhaus database entry for https://hrtgatlanta.com/a1vsem/Document/eJnwLiY1WuMZI4rK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:629949
URL: https://hrtgatlanta.com/a1vsem/Document/eJnwLiY1WuMZI4rK/
URL Status:Offline
Host: hrtgatlanta.com
Date added:2020-09-30 13:00:05 UTC
Last online:2020-10-12 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-30 13:02:04 UTC to abuse{at}liquidweb[dot]com,ipadmin{at}liquidweb[dot]com)
Takedown time:11 days, 22 hours, 57 minutes Bad (down since 2020-10-12 11:59:25 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-04ARC-12625.docdoc 2e819c61db2c529ce860d500db4f2bdff94d8f278160e35416eb10717ad5e761Virustotal results 66.67%Heodo
2020-09-30MES-2020_09_30-29963.docdoc ccd09c9d5a3e23cf11d4573a5ce8d84c634f8cdcf7188378a94ab61d27544009n/aHeodo
2020-09-30DAT_20200930.docdoc 2e596652391370bfcf5e776a4379dd5061fcb4441200889c726c34ea6207ee9bn/aHeodo
2020-09-30File-20200930-A4885.docdoc d8e405782c4f5b141b6031715d78b4d56a4b64b6f8f61f6de6af59c7cac4e96cn/aHeodo
2020-09-30INF_20200930_DN924111.docdoc dca2f3f5cd4fc577315e8bd9fcb344afb5cdc0726cd6349dd3698c48cc0542d4n/aHeodo
2020-09-30MES-2020_09_30-8043641.docdoc eb8dda76f5e153f5ea9f7c7471f55627870495f236134e3b0a6acb0ab4f067b4n/aHeodo