URLhaus Database

You are currently viewing the URLhaus database entry for https://glcglobalmd.com/F0xAutoConfig/XWxF1QBk34I2LQDKP7gbxdof4nPjk03U1z/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:764525
URL: https://glcglobalmd.com/F0xAutoConfig/XWxF1QBk34I2LQDKP7gbxdof4nPjk03U1z/
URL Status:Offline
Host: glcglobalmd.com
Date added:2020-10-29 09:35:06 UTC
Last online:2020-10-30 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 09:36:29 UTC to abuse{at}godaddy[dot]com)
Takedown time:1 day, 8 hours, 47 minutes Poor (down since 2020-10-30 18:23:33 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30Arc_SR9728128212AY.docdoc 6f999fd1f81ce48aa6d5e6da8c78e33ef00744f321f0f76af259f5846bc69b24Virustotal results 29.69%Heodo
2020-10-30Attachments_7273109195019927247915.docdoc 8f0e22d23596c232df3d527d5fb36ca404eb518bbe7c375b7a7cd037354b02d5Virustotal results 28.12%Heodo
2020-10-29WO_25433636.docdoc 57a23ee50bad094280feb716af4f6917dcf92157f899a609736ead07c82e6432Virustotal results 26.56%Heodo
2020-10-29DOC_53048227.docdoc f69a365c0b551ac35010e98b64364feedecc32dae4284fb4afe62ced4b5d17ebn/aHeodo
2020-10-29FILE_AU4302973174ES.docdoc f4d2f6dbbb53d79cccef95feda58515350e863a1f1522bf60c830c0230754866n/aHeodo
2020-10-29doc_33564805.docdoc 77b9310b55e2267372f1458cc4c01a27f95067e8d1dad41137ee348a9dccaa32Virustotal results 28.12%Heodo
2020-10-29list_UG7810350765DG.docdoc 785ca4b8a3e573d7bb977a2f180d8c717b9867bbf38583aa08b4a96fa4803c8dn/aHeodo
2020-10-29DAT_1MSXX3P.docdoc 00f960f2c4dc8abaf471b3c55c877aad66b636338bd2d67a565393058b78c125Virustotal results 34.92%Heodo
2020-10-29MES_08491262942850004.docdoc eb4e38eca100cc2ec56b63dcb64261e5267212ee4d3009b7a9bce98cd60bb50cVirustotal results 34.38%Heodo
2020-10-2902387766638941.docdoc 970feee22d30c517c525e36b3327903c843552de7138215c5fec184444b56e19Virustotal results 34.92%Heodo
2020-10-29List_GXR_100120_TWQ_102920.docdoc 1aa45bfd6fa4890726daf11261b2aa4a7a23e9506d1845fc62edac1734669c26n/aHeodo
2020-10-29file_41908070.docdoc b2d41822b2d89807592fd225c8450a8005e877760a656a6477ac0a28e3aa0250Virustotal results 31.25%Heodo
2020-10-29rep_PLE_100120_CVZ_102920.docdoc 633a628e9a364cb3bbd93ebdce10e5f23fb15370a584efb4fcecf4549c3b975dVirustotal results 31.25%Heodo
2020-10-29REP_MV1310532535HE.docdoc 2d94f5620906f353b2bda6b6eb984695737cdecd6ddc88ca747fad5bc457d090Virustotal results 31.25% Heodo
2020-10-29Doc_0280169928106385954767967.docdoc 542607ccac2f39cec525786fc1e27c06359a30669af200f8cd1974e15680fa73Virustotal results 31.25%Heodo
2020-10-29File_AFZ_100120_ELT_102920.docdoc ed0c88d255d6a8938c10e7c8bf48cfbc1659d01ae0a99d3ffd7a205dcc310d4cVirustotal results 31.75%Heodo
2020-10-29Attachments_TFFKT63816T.docdoc af09d9b10580277dc290b458dfb6b85501ce39d6e430f87ee3fd349c3f672860Virustotal results 31.25%Heodo
2020-10-29doc_5XYF69D8NHE.docdoc 1cfbaf38e833a8dcab12a6f7a0c42e5b5033bc4f188f022607c0e3853f92a6eeVirustotal results 31.75%Heodo
2020-10-29inf_70919572851901636309684.docdoc 413b38a8a1796a27fb2b85f7a6fbb12b86499a131a2f86a75862afcf9b4c8ce7n/aHeodo
2020-10-29Attachment_ZXG_100120_WGS_102920.docdoc de9ebc94403f8ac175dbfb0a01cfd6e37753309402f94fbe7cd71755ab5d8051n/aHeodo
2020-10-29Rep_OPMKBG59083MY2R.docdoc 98de74a1b000e840bd188d7a4e35eb9150102a43f8c4fe5357bebae3ad586955Virustotal results 26.56%Heodo
2020-10-29FILE_41801850076.docdoc d28ab268249104b8e40b88f99670cb44f0cc8c440b22b983193c4e6fa4e0ea95Virustotal results 26.56%Heodo
2020-10-29Dat_BP3722812377QF.docdoc 75df04fe2bbfe95af6c2ff3ad6beb372645597b0350f6cc16f995a09e27da829Virustotal results 26.98%Heodo
2020-10-29FILE_44013275.docdoc d29f362916257a9602f0f49c1032faeed3f6672544c15ad9c3b471a6328f830bn/a Heodo
2020-10-29Attachments_96009234.docdoc 2d52e6dff2839f2f2b4c4e01290c96b9b924d0e8f276847481da31dfea122414Virustotal results 28.12%Heodo
2020-10-29647866335.docdoc 29808c9db3a80e9ed46d4aecbe478dd8e57089d7e2977c916421cba71b0d6c42Virustotal results 26.56%Heodo
2020-10-29Attachments_JRYP2TI532FQMT4V.docdoc fd810765d8200ee0c56b220f79375a5a76d36bde37b25512c664f45c7d130181n/aHeodo
2020-10-29ARC_PZ8336281806RE.docdoc b770e53d7a44c680b7ce2fc81e13b5de570dce0b57c587442874b3c5f6f94d83n/aHeodo
2020-10-29ARC_8884991355048108140348718.docdoc d7edab7749baa696b995be184437050a249c40992deb7cbd3472cf93fd8a154fn/aHeodo
2020-10-29Untitled_4214996041977.docdoc 12c570f649005ea1ae77c36167843e3e87252075b68b652c5f05b0d8e54b2ad0Virustotal results 20.31%Heodo
2020-10-29Doc_PO_10292020EX.docdoc 9ab86b1091af04d5ebdae8242b9066588bcd88a5db9b2c3c2ab6a3c855c2a22bn/aHeodo
2020-10-29file_LOO_100120_ZYU_102920.docdoc cd49f6f6b2b1cbf28331a1eff67e7179731f34a790a1bb69c89b65ffcfc38e01Virustotal results 20.31%Heodo
2020-10-29DAT_PJT_100120_BYS_102920.docdoc 0ecd1fc385ec00c604b5f5f04953a2a13067c7e7fb0066c32e90c706e6a5826fVirustotal results 19.05%Heodo
2020-10-29REP_QAK_100120_ZBC_102920.docdoc 2427ee3cc0798fcee02c718a1fb58d735d9cf3b0ebd9bb10c14cb9326bb5e489Virustotal results 20.31%Heodo
2020-10-29Attachments_IL7433158454XX.docdoc 1e63648100763f7fe5822fa5fedd5b5b9c87d1bca425b6745c236e3bff92bd0cVirustotal results 20.63%Heodo
2020-10-29INF_52604861.docdoc 585ab6cc0502c04dedbca9318f5d7d278050dcfbeb477a09e8fee5b66916e38fVirustotal results 42.86%Heodo
2020-10-29REP_DZU_100120_SHJ_102920.docdoc 38df7a8d7d8ddeec4905b01777148222f208d5030b7a44665b5fdafb5bd9ff19Virustotal results 40.32%Heodo