URLhaus Database

You are currently viewing the URLhaus database entry for https://goldenyemen.com/wp-admin/INC/RUoRW1W0oDKQg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:751551
URL: https://goldenyemen.com/wp-admin/INC/RUoRW1W0oDKQg/
URL Status:Offline
Host: goldenyemen.com
Date added:2020-10-26 12:31:09 UTC
Last online:2020-11-07 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 12:32:09 UTC to abuse{at}cyberwurx[dot]com)
Takedown time:12 days, 10 hours, 37 minutes Bad (down since 2020-11-07 23:09:11 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27MES 2020_10_27 3135.docdoc 303cdcd85a6295f4839ac8406c15873c56c6db045d02f16605a495f6fd952261Virustotal results 55.56%Heodo
2020-10-26MES-990.docdoc cda387ea9c2b7ee2d0a9087af444765247d452d8edbd1185726cbdc5c1bc7e1bn/aHeodo
2020-10-26INF-0840.docdoc cb7ba7a31e5fb8bae2b722fa5deb8ada4ba392a89068d2ae985850a4470f2e45Virustotal results 32.79%Heodo
2020-10-264233411 2020_10_26 4144947.docdoc 50ae991ce6ef920b330eab06fed63e4189477c5b5c449311b9b3a509c174950aVirustotal results 30.65%Heodo
2020-10-26List_2020_10_26_701364.docdoc f2f59d2c2562fe07af0ef91ed759d38a68fb624be852b05856354fe4f476c307Virustotal results 32.26%Heodo
2020-10-26File-2020_10_26-LOE916258.docdoc d1abcf7be3ad51873e8f18e2f2d07487da68b9450943ee963efc561fd680fc3dn/aHeodo
2020-10-26rep_2020_10_26.docdoc 5bdfa0c917624bd7de8b3378352e10dfc48b33bd79c14f27cc5b3e9dfe1d1ed7n/aHeodo
2020-10-26Inf-GZ5693.docdoc 4c42cdb38e4b83de81d9ae2f8e709dfb3eb681761bc551eeab0b6338bb249882Virustotal results 28.57%Heodo
2020-10-26538114-20201026-Z4403.docdoc 7fe82452655b311a5f4854aabfdd91edb37e5232dc2e4020eacf3714c964353bVirustotal results 28.57%Heodo