URLhaus Database

You are currently viewing the URLhaus database entry for http://blog.gadzoom.net/wp-includes/g0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:716849
URL: http://blog.gadzoom.net/wp-includes/g0/
URL Status:Offline
Host: blog.gadzoom.net
Date added:2020-10-19 09:28:06 UTC
Last online:2020-10-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 09:30:21 UTC to abuse{at}amazonaws[dot]com)
Takedown time:6 hours, 43 minutes Good (down since 2020-10-19 16:13:58 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-19SN9dcpjJFwe1g.exeexe 7f7d7c5e5944d16149ba1e6e47c0b9057da9e5fc38e67782171dcc1578588a18n/a Heodo
2020-10-19XUZreLlrcw2VJjN.exeexe 6b71adbf0b442cee29706ecd791b9957d777a8fe2a8c343e3726266ab139708dn/a Heodo
2020-10-19SqTkoree1E9J.exeexe dfbb4f9e0a6b9bb1bfe82c2a33430f6292fd53e47864b89d9d56524cf2e5af07n/a Heodo
2020-10-19VscaaXWPeHI9i3.exeexe 4402de5a608a381f4fb3145418d43fbef8c30660189bf3fe05d3054e34ded7b4n/a Heodo
2020-10-19hj6jw.exeexe aabaec6754b959eb71b03d5843b5f323633c7bf5b9995e3c327ef6ed43ac801bn/a Heodo
2020-10-19aq4gsP3cc5Wh.exeexe 58a99a9c0458043487ef12b8944a672bd0abd56b7efafe6674afa75f7f6b9123n/a Heodo
2020-10-19lc88g.exeexe 19c7834005f8b52ad8592b0e6b7a6fb375357f12e2b11ddfb6e9132e80ad609fn/a Heodo
2020-10-19vvb61f0R5P330oBeQO.exeexe e2d85b9d5e177590528bf2ba1cb58a41b2a0ab59e4831d8b21cfa08ee0c813e3n/a Heodo
2020-10-19VGAooDKdrdMoNjm.exeexe ef57f5bcb1779847ab0da19b80635715c00d92b0618bdfdf1458fa3bf3ab4507n/a Heodo
2020-10-19qhwyzuxwtBOeCTi9.exeexe 33ee7efb2dbddfe1e5722a450613455d5584e777c4d0a92fbb3fe11faf28d8abVirustotal results 9.86%Heodo
2020-10-19MS9L.exeexe 23ac2ab537c819ae4bdfa9b6aa102d2a8cab24e7f3e85f95d9032ee092e04b69n/a Heodo
2020-10-19k79jp1.exeexe 0270c3e96b59251783e2bd7cfbcbf5162c105b8e7ed5c53fbcc0911d1e5e16d8Virustotal results 15.71% Heodo
2020-10-19iCK5UUuNEGncb.exeexe 5a7c441bb4302a5681ed19961028e4262ff5f7b450ea6035fcb9302743fcf6abn/a Heodo
2020-10-19Yi6M6drohLG9.exeexe 9df1048cea7650959ce7a402917562515f3595aa8bdb2ae270de7a4f8904a7cfVirustotal results 15.71% Heodo
2020-10-193JXH3K3yyt1ihxEr.exeexe e4400abca0c5d5c377caa8983be09efd0346f5a5527d8741ec953507a9f19978n/a Heodo
2020-10-19j5QkLLsw11RPzyaf0RD.exeexe 2470c84588a6ed9e9f99640074a315dab619c8480fb52a10a9a5aec88f097521n/a Heodo
2020-10-19uJ6e7BK.exeexe 73d9de91872adea3c1321d5954236bd263727b897eaca1648b204a91628ab36dn/a Heodo
2020-10-19YXSPz3AO5GoBzCrMr.exeexe b36cb42f36e5bda95136b5669461c4afffb255d99ac6ecf37231a7f081eea131n/a Heodo
2020-10-19ylGTB.exeexe 47259f3079ad41e0cc40476964c17907a466a948bab88495b880c294e7e5e99dn/a Heodo