URLhaus Database

You are currently viewing the URLhaus database entry for https://gazeindia.com/wp-content/MZabT8o0RMMBZhe8JNCQ0zhh5iMRXN3SD0Q/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:763923
URL: https://gazeindia.com/wp-content/MZabT8o0RMMBZhe8JNCQ0zhh5iMRXN3SD0Q/
URL Status:Offline
Host: gazeindia.com
Date added:2020-10-29 06:31:04 UTC
Last online:2020-10-29 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 06:32:04 UTC to abuse{at}leapswitch[dot]com)
Takedown time:6 hours, 39 minutes Good (down since 2020-10-29 13:11:46 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29Arc_PKXF72LH.docdoc c77bdf30a9a94eafd3718a954bd79a8e9ad3b32761d6c45ae1b79245df7599bfn/aHeodo
2020-10-29rep_87020434.docdoc 914409456ddec456e3d23eb4a36d9b3092703f59958ecdb8a3549e0c96f653a6n/aHeodo
2020-10-29List_YFN_100120_QCW_102920.docdoc 3dda8251733c1b96b75d29bcbe3466add36d495368b4b44232fae1dba4a4cec6Virustotal results 20.63%Heodo
2020-10-29doc_24537276.docdoc 8b4afb8076a68f93b44032c82700252f8971b853903b31fd0eaf50671f7c3cd7Virustotal results 20.31%Heodo
2020-10-29Doc_Q71F92JHX5C0BO.docdoc cd49f6f6b2b1cbf28331a1eff67e7179731f34a790a1bb69c89b65ffcfc38e01Virustotal results 20.31%Heodo
2020-10-29mes_PO_10292020EX.docdoc 3a1dd7ec119b96ea68facb223082a398ff4c038e58e7d166c80d7a7d4a3758abVirustotal results 20.97%Heodo
2020-10-29arc_PO_10292020EX.docdoc 8e812f35e13e8d4d2d376ab456fb4335c9468ba58bb5a4bc7fdf14c959388f6dn/aHeodo
2020-10-29Rep_68726207185876158.docdoc 585ab6cc0502c04dedbca9318f5d7d278050dcfbeb477a09e8fee5b66916e38fVirustotal results 42.86%Heodo
2020-10-29Untitled_QJ6719048109SQ.docdoc ffa31d45d93161ab298442d4f9d83cf8b0bcead9e50e92a048b6b0900415b59cVirustotal results 41.27%Heodo
2020-10-29REP_OR5UXNIWAF6D1T.docdoc 6cff316da0b26621e5b1fc3d5a85c6931a68a90fde20acf702195a175fb4ce44n/aHeodo
2020-10-29FILE_PO_10292020EX.docdoc 613bf944597cf7f2300dcd8a24394ca5de6c6f85ae7e41d98b2a3b4fe59b6779n/aHeodo
2020-10-29Dat_5311712890407754809284070.docdoc 42a5e4e595594e5e71e067312918e7858011f85588cc04720f4752f883f45b20n/aHeodo
2020-10-29inf_9OFCNRL98XELC.docdoc 4b6b29d5c14a6ed0524d46202796bf0f9bd18650fa3f44dc5d01e1ab93652600n/aHeodo
2020-10-29rep_2OQ3UZRAZXUOL30I.docdoc bb6a910117fc42075d0f29a1d7f63f94814e7f787223e3af617ca5018180a77en/aHeodo
2020-10-290330684484713690186993375.docdoc e3a96d2e3adca1fc3dfea0ac14af9b1d4cec3a20d9d7c6874edf1c6fec60d90bVirustotal results 38.10%Heodo
2020-10-29DOC_SXQ4IRPUSWSY.docdoc 391bfc40b692a1742119596041c13976318ba374a5f74e5e441a2df28ad57fb8n/aHeodo