URLhaus Database

You are currently viewing the URLhaus database entry for http://gnlsafety.com/cgi-bin/sites/a8u06jiu6bois2pt6sr81/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:705925
URL: http://gnlsafety.com/cgi-bin/sites/a8u06jiu6bois2pt6sr81/
URL Status:Offline
Host: gnlsafety.com
Date added:2020-10-17 05:42:06 UTC
Last online:2020-10-17 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-17 05:44:14 UTC to abuse{at}amazonaws[dot]com)
Takedown time:5 hours, 40 minutes Good (down since 2020-10-17 11:24:43 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17MDMH_MCO_100120_GKL_101720.docdoc b0f945ed6afda303421f9501b2b2d1d2996a132eb27486911019cb9996538460n/aHeodo
2020-10-17DOC_O2IAVKSYUYS.docdoc 5ab2456a7a5d44a28ef32f5ac8c55e8eaf4b24802b2d326a29cd9aa4199e0b97Virustotal results 54.10%Heodo
2020-10-17INV_PO_10172020EX.docdoc 169fa4037e8c45a38a3b2e862d860e955fc810c63682c78155bbbd45820b83bfVirustotal results 54.84%Heodo
2020-10-172JQHF1RQFM.docdoc fa3c245c0bfe5a4b95d229481cbdac5dc3798f1948badeecb3dc692f589c5f7fVirustotal results 53.23%Heodo
2020-10-17BAL_PO_10172020EX.docdoc 8eed16b7e0a64351cb06ea437eeae8f69b227cac04237187ed17cff470a3cb0dVirustotal results 52.46%Heodo
2020-10-17C_XL1460883005ON.docdoc fdcbcd4f6d22900775055fa03ab8643f72041e73d6af1c271a672ce65268e0ddVirustotal results 53.23%Heodo
2020-10-17FILE_7KC0QATTA5P5M.docdoc ff9996026d66c80170010bab3d84d0ba1ecac3a6b87f8e694008feb0bc0b3d4fVirustotal results 53.23%Heodo
2020-10-17FILE_FGS_100120_RLB_101720.docdoc ea065a0dbc3ca645237d0c98e82887ca636451f3fa822c6c0a087a2fe98c230fVirustotal results 53.23%Heodo
2020-10-17MSH_100120_BZW_101720.docdoc 72e665a7d43027e4ad6206ba82bfb44f113e89c81b249b2c9ea29c45faf022ddn/aHeodo
2020-10-17FILE_97477491030935478.docdoc 9e5f94414bcc33c4f9405dd2c0747ccc8c79921dbaab834a1ce8cd0205bb1f9bn/aHeodo
2020-10-17REP_21170074.docdoc 6d5ed047cba0f40a2bd108fdb285520a5590c29ac64b7a9d32a20719905f1e7cn/aHeodo
2020-10-17DOC_XMI_100120_WJP_101720.docdoc 85a42a8d612d20af55e105cdd7caa6c881ebae398c26dea03e0cf147e543f917n/aHeodo