URLhaus Database

You are currently viewing the URLhaus database entry for http://glcglobalmd.com/F0xAutoConfig/XWxF1QBk34I2LQDKP7gbxdof4nPjk03U1z/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:766772
URL: http://glcglobalmd.com/F0xAutoConfig/XWxF1QBk34I2LQDKP7gbxdof4nPjk03U1z/
URL Status:Offline
Host: glcglobalmd.com
Date added:2020-10-29 20:34:04 UTC
Last online:2020-10-30 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 20:36:21 UTC to abuse{at}godaddy[dot]com)
Takedown time:21 hours, 52 minutes Good (down since 2020-10-30 18:28:36 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30Arc_SR9728128212AY.docdoc 6f999fd1f81ce48aa6d5e6da8c78e33ef00744f321f0f76af259f5846bc69b24Virustotal results 29.69%Heodo
2020-10-29WO_25433636.docdoc 57a23ee50bad094280feb716af4f6917dcf92157f899a609736ead07c82e6432Virustotal results 26.56%Heodo
2020-10-29INF_TV0567421124EC.docdoc f69a365c0b551ac35010e98b64364feedecc32dae4284fb4afe62ced4b5d17ebn/aHeodo
2020-10-29FILE_AU4302973174ES.docdoc f4d2f6dbbb53d79cccef95feda58515350e863a1f1522bf60c830c0230754866n/aHeodo
2020-10-29file_PO_10302020EX.docdoc c685520233b6d670ab20445051b6688bac6affb5c8b99a71213937d99ac9e380Virustotal results 25.40%Heodo
2020-10-29File_PO_10302020EX.docdoc 9f944d45d5e7d40e9f1fce8f48c7fae48a14b56666b6c149b9a2f028567d2019n/aHeodo
2020-10-29LIST_E2BZ8EEWZQAIPDSB.docdoc 30afb0ba6cad7d0adca2d6200ecc891e79a8901808aa35a78dc2e03b6b1b3fean/aHeodo
2020-10-29MES_08491262942850004.docdoc eb4e38eca100cc2ec56b63dcb64261e5267212ee4d3009b7a9bce98cd60bb50cVirustotal results 34.38%Heodo
2020-10-2902387766638941.docdoc 970feee22d30c517c525e36b3327903c843552de7138215c5fec184444b56e19Virustotal results 34.92%Heodo