URLhaus Database

You are currently viewing the URLhaus database entry for https://timbgurudesigns.com/wp-content/attachments/7UsvRHyBIsZgBUerKa/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:698337
URL: https://timbgurudesigns.com/wp-content/attachments/7UsvRHyBIsZgBUerKa/
URL Status:Offline
Host: timbgurudesigns.com
Date added:2020-10-15 19:07:07 UTC
Last online:2020-11-03 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 19:08:03 UTC to HostingSpell{at}gmail[dot]com)
Takedown time:18 days, 10 hours, 43 minutes Bad (down since 2020-11-03 05:52:00 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-16Arc-2020_10_16-AL87564.docdoc a6091d359b405ea83e58000e282b0bd40824c64d36b4546077d786ff19124be1Virustotal results 49.15%Heodo
2020-10-16MES_2020_10_16_5221665.docdoc f9d5124fa2f49422eaacc95990935571a667118bbdebac076de0f178e54e9ce3n/aHeodo
2020-10-16Doc_2020_10_16.docdoc 594458a8901ca25ac09d46ae9f0fc9a0ecd336da9af62a1a4f46940b80bad38bVirustotal results 46.77%Heodo
2020-10-16list-20201016.docdoc a575516d48e96ddfbaa7108fdf2f06fe978074c0a71ff7162c8631b757b8cdc1Virustotal results 45.90%Heodo
2020-10-1619239G_2020_10_16_9808.docdoc c0fcff9f41f313cc5a5b8033b5f724c61f19943859630958d99350d3b18b9eben/aHeodo
2020-10-16Doc 20201016 119849.docdoc 878bb13d04d93f1209ba23990aef838329f86ff7fbd86d5bc6bd24da81dbf0f7Virustotal results 46.67%Heodo
2020-10-16list-20201016-0233077.docdoc 38a5fb11e6266a457f515df1b8c3ba51c2dfafb32164cec12057a63a473daad6n/aHeodo
2020-10-15Inf_20201016_467.docdoc d1fea8b66cd1bf042820cc0c454cdbc6863c24dc54b90afec02b4b0c51394734Virustotal results 39.34%Heodo
2020-10-153763EL_2020_10_16_247.docdoc 7525f0fcd1c0d8d3e9ed758923b6e0ee0090ecdd93dd35f2a901b1bc3bfd8135Virustotal results 37.70% Heodo
2020-10-15UNTITLED-2020_10_16.docdoc 609112e04613f2eed3ecfddccfd458d553696c160e8d452d24621c02e2ecd9edVirustotal results 40.32%Heodo
2020-10-15RI932 20201016 LKC733.docdoc 47ce9bcd74cf07f1e9312e71da59c363eb8c6b91f592da4c37aada97a38318bfVirustotal results 38.71% Heodo
2020-10-15REP-60644.docdoc beafc1267a6858915fadf22b33115584995aae3cef104ec6cb8e2cf4e07434a6n/aHeodo
2020-10-15arc-20201016-HD550.docdoc 57d9875f19239fe1fe11134bde1cf1eae57315b38691deced8eca15315650ee2Virustotal results 37.70%Heodo
2020-10-15doc_2020_10_16_47081.docdoc 17c3d1b520a527f0b3b908b6107db6d0fccac8f66a9c5308cfd02bda68d814fcVirustotal results 38.71% Heodo
2020-10-15List-20201015.docdoc ba684ebc48901ee996b66714e35477d733b515c3c30830ede0647c2d82f61780n/aHeodo
2020-10-15Arc-737.docdoc be2d72ee1a4da699026d47683395cd063bc94662a384bc7352e9596f63f6c843Virustotal results 37.10%Heodo
2020-10-15Mes-99824.docdoc 9d63e85fccb951dc5848217cf3dac5996b6d3a303ac7b404916c3aeb62436d55n/a Heodo
2020-10-15doc_20201015_OLE05249.docdoc 62e82b854fb3f416fe2563b4e5e4b41a2ea0e6eedc68b1189172b773b878c95dVirustotal results 37.10% Heodo
2020-10-15REP-20201015-UE606346.docdoc 7ca67f684f308874cf0e09f91eafd8a0faac215153b89240b04b0fe43a940f8bVirustotal results 37.10%Heodo