URLhaus Database

You are currently viewing the URLhaus database entry for https://stevegates.co/free-low/attachments/ruokgkmy6v1uj3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:694523
URL: https://stevegates.co/free-low/attachments/ruokgkmy6v1uj3/
URL Status:Offline
Host: stevegates.co
Date added:2020-10-14 21:38:03 UTC
Last online:2020-10-15 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 21:40:05 UTC to abuse{at}online[dot]net)
Takedown time:11 hours, 45 minutes Good (down since 2020-10-15 09:25:47 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-15BAL_SWCO5O6C7D05E8.docdoc 149107eec47eec15d6160353b5102a17c8b552474e89828511de257fd78d3a52n/aHeodo
2020-10-15FMN_100120_CHW_101520.docdoc 1cc454d75dc586cd5025eab16ed2a8097e3d412f9efb96ddd568041631aa0ebcVirustotal results 45.00% Heodo
2020-10-15KG_BCC_100120_UIP_101520.docdoc 48caa70a3b31ff976df78f2b4525b27307a53e88d1ce4f1846dd5801dd2c9b76n/aHeodo
2020-10-15P_5409947603302196705162354.docdoc 40cd7ad9c0ebdf03adc1f14bb7d6554f74a043088f9aab4a39e2bbf0daa01932n/aHeodo
2020-10-15REP_XIHSLH7950KMS.docdoc 09b2a0a619eef827aca5df812a125f278c915c56afa75e6bcbd55e47265034bbn/aHeodo
2020-10-15W_21316700.docdoc d2d28ce9e628712a8478ea1439e111036497efe3d10a12bba622baf2952ded06Virustotal results 35.48%Heodo
2020-10-15BAL_95612884.docdoc 5fefd7066e7cb6344aa6f4ceb150de371e98cc1de2af7bfa2fa46cb4949ff0aeVirustotal results 31.15%Heodo
2020-10-15EEH_100120_FIU_101520.docdoc b716ead26e4edc1ca7925f26ba16cdbe932e9cff3fbb636630f3d7bad4ad487dVirustotal results 32.26%Heodo
2020-10-15F_6019887555221918527861209.docdoc 2cac6b6f1ed831e31b804e46839fb6e8e196a14ba3d75ba6c945d4b87dd18f04n/aHeodo
2020-10-15B_95960696.docdoc bcd20ead58694ee7adb822b6a4c40c62433fc6ca968f2a728a7e10fd21d0d1b1Virustotal results 29.03%Heodo
2020-10-15Q_21801660.docdoc a62460b5048b49481c6096c23dc3b6f0f0fa84b37b632c80b6395400314ebc7dVirustotal results 30.65%Heodo
2020-10-15KPJ7B0AO1P.docdoc 100b400505d67803dd47e7093247e44637dade8df24255e8fd14b80a78f77533n/aHeodo
2020-10-15INV_I66AGZGH9OO4.docdoc 9954017c3108e9f6fd524436830144dcc04c49f339486dba48e2d3dd3dfbd0a7Virustotal results 30.65%Heodo
2020-10-15EJ1412764513FX.docdoc 97c5d59d160a9c7c2cd3b9038cbd57f37010bfd8b6038b0a7423ab5fb471b28aVirustotal results 32.26%Heodo
2020-10-15INV_FUO_100120_SLU_101520.docdoc cca3799a5d79aad049795ea6a869e22d90d248ef1c1193d5d5933237b20157c5n/aHeodo
2020-10-15BAL_34300986808267633318.docdoc 6d531c0d2bfa18875d304220ef3fc95e74bd8f98c539ceb1755245c2394e0b31n/aHeodo
2020-10-15DOC_X0K51P0.docdoc 0542ec36ffc846a864befb3bf220746110608b4242bcc75caff8b9f2cc196f71Virustotal results 35.48%Heodo
2020-10-15X_HDYKVSBEPPPZG2OO.docdoc fc6514ef333a9a7df16243a938d3a6e2c9fcf1410d492381598062d92b267346Virustotal results 29.09%Heodo
2020-10-15FILE_QYN_100120_CIS_101520.docdoc 3e222a87ae7cd1bbffb29335e25d2af2896c60be6575ff6070da3341b33b4c66Virustotal results 32.26%Heodo
2020-10-14PO_10152020EX.docdoc 285bac1c67ccd0ea184f852a4f063955511ea533a444fd1115733221099bb823n/aHeodo
2020-10-14REP_BL4826248598YQ.docdoc 766cbde7ddad3ff7d55d13146e76bdfdd1699d56ad5886d619dc2e74f2889d1dVirustotal results 29.03%Heodo
2020-10-14FILE_PO_10152020EX.docdoc 9c6b0725805166528d2cbc739cc8157205fb247d5775c86058f8037522e235cfVirustotal results 31.15%Heodo
2020-10-14FILE_4N0C0450JUCEO3T.docdoc 046d2903486b485aed8851cbfc6b22fd2629535434227112ef1366e0c783d369n/aHeodo
2020-10-14F_85817083.docdoc d8e8296e8032721412eeedd5ef9a8e7c30015865ebfa1b8661f447ff4fcc676dVirustotal results 27.42%Heodo
2020-10-14DOC_88188402.docdoc 525a536f885e832de7e90140c6d9eefc86cc8e4bb3272cb6c8ba5256e672331fVirustotal results 31.15%Heodo
2020-10-14RPB_100120_HKK_101520.docdoc 521a53d518e84c5c1975c7019ce22c19f8a9e56401c060a2228768825a495411Virustotal results 29.51%Heodo