URLhaus Database

You are currently viewing the URLhaus database entry for http://geekdeer.co.za/wp-admin/HIkbb3dyWkw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:769491
URL: http://geekdeer.co.za/wp-admin/HIkbb3dyWkw/
URL Status:Offline
Host: geekdeer.co.za
Date added:2020-10-30 13:34:04 UTC
Last online:2021-02-11 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-30 13:36:23 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:3 months, 13 days, 17 hours, 39 minutes Bad (down since 2021-02-11 07:16:02 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-31File_TZI_100120_LNF_103120.docdoc 858159295a83a85ce85a8e18a4398873eb02dfa32012325f963ab2de57c8c0aaVirustotal results 56.25%Heodo
2020-10-31dat_ZEV_100120_PYI_103120.docdoc 7b23df6f1bd4b2e428624bcf7423651fad4742e21e6992d0df41d6d94c199169n/aHeodo
2020-10-31Rep_MOF_100120_VKP_103120.docdoc 396b664fbdde301d1ebedd54f4beacf4726ef9fe1d0807a86fe0b00e0a71772dn/aHeodo
2020-10-31TY7642331746KM.docdoc cdb79e413c85c2fa4724ac77b430ab5a6a0c770f7f6a640fec00d946a93f5e09Virustotal results 53.12%Heodo
2020-10-31DOC_PO_10312020EX.docdoc 780ffddf2dd1fac9d6fc091c707c84751ea2180a253431c3b4700989bd3fc21cVirustotal results 54.84%Heodo
2020-10-31Rep_OJ6588949536BR.docdoc 03b477c67a30f1cc63aa897f954709c42c74cc2907d8639805398a4615cad1b6Virustotal results 52.38%Heodo
2020-10-31Attachment_PO_10312020EX.docdoc b48b7231ac7d5bc0a2ba5883e7a634a557c606b06b97bf45b2842523959c4a37Virustotal results 53.12%Heodo
2020-10-31file_JC7949701214ZU.docdoc 6b199ce53786e4647258111798d4a9f14df4220415ed15639338c5860d98695aVirustotal results 53.12%Heodo
2020-10-3110960289.docdoc 3f1565ba4e9c93cf71b5b5a3f3b16869e7c6a7d86a837a32db34f1f0105e3aaaVirustotal results 54.69%Heodo
2020-10-31File_58389965.docdoc 0406910d3c48dbd18d57086dcab9b4f73a8081dae9fac3010f0ae90b73c7c34fVirustotal results 54.69%Heodo
2020-10-31FT_07112654459.docdoc 12ef90a776bc1f4ae05962313e6b3711ec5211f8ba450527585d2da80c2d03b5Virustotal results 51.61%Heodo
2020-10-31P_PM7924663615ZT.docdoc ffc63081ade619c07061526c15e53d5dd012da2e842f479fefc0c27f46ce2bebVirustotal results 55.56%Heodo
2020-10-31doc_PO_10312020EX.docdoc 60e4646ea5fbe72e1daf6f3d015b37205898569b303dcfc791e0d02a754c9bf1Virustotal results 53.97%Heodo
2020-10-31MJ_PO_10312020EX.docdoc 9210f9032280641d080e5abde6a49a3032839cec91f757f2469a4eeeb4080afcVirustotal results 54.69%Heodo
2020-10-31FILE_63431152.docdoc d1d8c0384f3780dd6287efc3e864f9fe60b6efe14f613f0cc2ec0efb0aa97dd6Virustotal results 28.12%Heodo
2020-10-30Rep_RQ2289794960KF.docdoc 66f30f7d40ef0e230f042cd6abe51971e49af52617515c3d0d99f3f365a59e90Virustotal results 25.00%Heodo
2020-10-30LIST_PO_10312020EX.docdoc 14a8572928770f8d61fa05890c3e0a5cd4396bfde2ce2763d533e89d05120d34Virustotal results 25.00%Heodo
2020-10-30Q_NGGQKJDSC44D.docdoc 1ce95602afd3133a2b2f7ac1df3290e233ba27b2f2b71d6a1b407cda2cb4ca4dVirustotal results 54.69%Heodo
2020-10-30dat_06CKUH8JEJYI1Y.docdoc b79376701bfc97b082e9d8d61f6886b399692a2b154c6095559ab1da86e4c518Virustotal results 53.12%Heodo
2020-10-30C_HOA41BE3OD79S.docdoc 5041a2eae4b04f23df9804031b3a30e815e0c2310bf42d82176cb89618617933Virustotal results 55.56%Heodo
2020-10-30FILE_MDXA4TH1TICFW.docdoc f2413a07e3362999d85fbab3f6c2fe8f228e4567eac899cd565ad65a2d0eede9Virustotal results 53.12%Heodo
2020-10-30dat_HQG_100120_ONO_103120.docdoc d577446435b94d0af2a829f1160b594e95c8051f6b069400ff61fa38d151ba54Virustotal results 51.56%Heodo
2020-10-30Doc_80815315.docdoc 8ead4e972ba536f428fbee5bb8f687ff6a1efdae4456aafb1bbb176b37672180Virustotal results 23.81%Heodo
2020-10-30ARC_NN1690206242EI.docdoc f7cd964fb73ef51565181df0b0bdc561fe166542fc297684546797abcbc24000Virustotal results 23.44%Heodo
2020-10-30Arc_PO_10302020EX.docdoc 5a995a547c20076ca1850fead69dba97ce8af344b544648dc463a9a18899da74Virustotal results 31.75%Heodo
2020-10-30FILE_85247412379202800.docdoc 1e363452c2a67d40f01390488a99f68ce6fab805b45eab93ee2db2469bf1b05fVirustotal results 42.19%Heodo
2020-10-30Q_JUO_100120_IRN_103020.docdoc 5fc665986d6e0e5763554e4d9f9db9ccc61b2c20fc408e955d286a458f622f48Virustotal results 47.62%Heodo
2020-10-30rep_ATN8NE4N0E7.docdoc 1b230d33228fd383eaf4cc6faa376c0173fb8ff8d70c42dc9ab1ee5eacb411deVirustotal results 46.88%Heodo
2020-10-30Dat_ZB1141668050MJ.docdoc eb5d0c08628c3ec2c081dc472157b78cff5ee705d96de5cd061c582c575bb7e9Virustotal results 44.44%Heodo
2020-10-30doc_TF5303862463VE.docdoc f49b970c0f5c5e742a76964f8ac3473e2b6a8558589d75cb54c5f7978178af16Virustotal results 42.19%Heodo
2020-10-30DOC_VFY_100120_HOG_103020.docdoc 969d4f7be038b1be9bc4976a986c8d5652a60b704fcb8da825bf8435a659d500Virustotal results 42.86%Heodo
2020-10-30mes_ECVDN9NL31.docdoc 12b4329a9b823283ea081ce2769d7115a1f1922106019611973ea41b4dae5fbdVirustotal results 42.19%Heodo
2020-10-30FILE_MQ4734183555CV.docdoc de0a1c44011e636f13b7db8734adcc239d484bae417f118f5d1173ff7d708481n/aHeodo
2020-10-30Inf_516045188481154816849424.docdoc 1b8a22caf6297a5c5079fc3020d9bc56bfe5b3dea6cdf5f252539d3c076c9c62Virustotal results 42.19%Heodo
2020-10-30rep_36415472.docdoc 2c35c7c2a35e6c0d057d6a29697d6caeab76363a0040219edbed385309cb15f6Virustotal results 42.19%Heodo
2020-10-30dat_RYE_100120_LYV_103020.docdoc 59eb7f8b98e7601aab446fe4f84b586ecf0ff8b5f092b8144441e50eed459684n/aHeodo
2020-10-30dat_LIX0LGHIXPNFELAQ.docdoc c0b41e22e711cd0385c069a4c10ae102ca7dcc277460d218eecc4974cca8677dn/aHeodo
2020-10-30DAT_2Q2BBZY2GRN.docdoc 62e102b2ca91bf58fe507a7ef4318f7cdc68777ffb02ff3698b2d79c1729c807n/aHeodo
2020-10-30350565013105682189204.docdoc 6263b8ea9431ac48bf402098737c84a9cf49c01488319875132ef15ef7d5c6e7Virustotal results 34.38%Heodo
2020-10-30dat_UK2454643686TT.docdoc b86e09a5bdebde57bd67e1fa11ddbd3381e5972d091fdc61b68e34226fabf084Virustotal results 23.81%Heodo