URLhaus Database

You are currently viewing the URLhaus database entry for http://geekdeer.co.za/wp-admin/b3rlkflDgzReGyGZFiivLIKrd3y8C38MJJ6pQ3VfQzPF3x/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:937347
URL: http://geekdeer.co.za/wp-admin/b3rlkflDgzReGyGZFiivLIKrd3y8C38MJJ6pQ3VfQzPF3x/
URL Status:Offline
Host: geekdeer.co.za
Date added:2020-12-22 06:19:06 UTC
Last online:2021-02-11 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-12-22 06:20:24 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 21 days, 0 hours, 50 minutes Bad (down since 2021-02-11 07:10:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-230Z5TT5KYCGDPDYN.docdoc ef1fccd54eea48427d2f6011fe8786cd9ae4f0fc4966130f9f3a99877c49dd04Virustotal results 23.81%Heodo
2020-12-23RBZHOA54RMS8H.docdoc 8538d00638c32a97eac2e8a9e1766a39268d8effa55c28026d3b75fe114dbc18Virustotal results 23.81%Heodo
2020-12-23P1SB7S.docdoc f8d8367d54febac27068bc20e25b1c3260b9bdc78d4874c00368e65ec2e37ceeVirustotal results 23.81%Heodo
2020-12-232PPNUY6MD2.docdoc 7e0f29831e6732a730d1b231a94cae3a27525976381cf6b97d15fe45c295f239Virustotal results 22.58%Heodo
2020-12-2329J8M065E4Y.docdoc afca4fb94300e4d7cd65cf15d802e9a4e1e6fe20051f8c2428b3a821bb3c8cben/aHeodo
2020-12-23T0EYAZN4K1QM.docdoc d03bdc5b9f72efd01d6cb79bfb3a1a2abb46914234af6d3439f4879a1af9d35bVirustotal results 22.22%Heodo
2020-12-23HY8OZ4GO.docdoc 055f997b54c9f0fe5ab2c07849d8e88daae0adb0ff26458d823b6f7413f3ac72Virustotal results 22.58%Heodo
2020-12-23HE1V3H47.docdoc 241c359520f4cef1af1de9d4789bf620f8086c7feb5aa2deba772b87aef3d514Virustotal results 22.22%Heodo
2020-12-23NCSWR8YBZYW.docdoc 6083b405a5bfb099398dc2417486e1c2913bba82b96baff811a71ee6feb0884dVirustotal results 22.22%Heodo
2020-12-23BA7H2OQ6WI341LG.docdoc c31a2ac228c882d72c112ad120473d012e0ba62c8d157e83cb7738293120eb15Virustotal results 20.63%Heodo
2020-12-23PW4A1I4ZNACYE5ZX.docdoc f2c16e9517e4e5e59a8640d99cda01c3078c6e7720f68f7f47a8a4d7b422b72dVirustotal results 20.63%Heodo
2020-12-23Y21UV9A2KDL.docdoc cf2febee508b7992d107d1a46b3deb724fff5b3905e1b7208ed0b5106c2b63baVirustotal results 39.34%Heodo
2020-12-23EJF1G7G.docdoc 56355a08b488d103b9a4d6226e1cf2cac8bfdc7381febb47feec6b0eff3ac332Virustotal results 41.27%Heodo
2020-12-236F6PGVNUNSR.docdoc 93901d975d0df11ab32c4eaf841b43684882ce002e1222696c629076b1b81792Virustotal results 41.94%Heodo
2020-12-23QB6WD933OJ9JW8.docdoc e269c87f3edd655d2fa4f379bac4ddee2c652386ccd598daf260157b1b9c033cn/aHeodo
2020-12-237M8DM2S0X69YK.docdoc b1094f6feb1a423a3b72309f5d023edd3d9509d5444912064029530fe0e8842cVirustotal results 39.68%Heodo
2020-12-23KU168M231T.docdoc cf2b33d88046f8e39c8299718c9132fc22247ef02bfe6ae6d404b0ca1c7c6119n/aHeodo
2020-12-233IPZ8HTD8SAJ.docdoc 9e353b38f1dd65bbd6f1e50dc63ddc1350f17b8e382a9fe24328cf1f1609b181n/aHeodo
2020-12-23HCX1LJY9.docdoc b534c439ac7a89c6af82331ebd70e5b5ce5e13a2e871bb7ab122b00004605e97Virustotal results 36.51%Heodo
2020-12-23VT19QUTTOTH3W.docdoc 14b878d7208fdf92d601e33a77f38b05f586c568ff44cf3e7e73b8b2e1dadad6Virustotal results 31.75%Heodo
2020-12-238SE9PVKEBPJS.docdoc 15cb67d0f913bc719642e9e5e394958d9c89afa25bc408bb42c593b9fc43cd58Virustotal results 30.65%Heodo
2020-12-23EBR0HI.docdoc c80244df2388e37d8c799e9968c52c9ad8c72b789ad85a2a91c35f8c28b0afd3Virustotal results 30.16%Heodo
2020-12-233QE3Q9416XT.docdoc 810ffc95c449b426c6bfc03c98c5e10cfbecbfff7858f10cd9c1c5ec29e2216en/aHeodo
2020-12-23HLVG3NAMOMF4XY4Q.docdoc 57f57ee9a02ff9b2983b7b3110a0269f0ac9cf44c8163805edac226aa6a5cc01Virustotal results 30.65%Heodo
2020-12-237DNV4MB3JIQV4.docdoc 168fe6ffe9e78f01a7f784833ba9306ef1edad3ccea334df35937424ef0220bcn/aHeodo
2020-12-23VD418HLHYC.docdoc ba96b09e7eeac72b4363f7b0749f36b0f3b68ecb4b3c40462d0f9d426b4cb483Virustotal results 30.16%Heodo
2020-12-236JFGCTQSW.docdoc 9377cbdbd93e4aed19bd96c21d35c83fa1a0927df233e481ce3f7eebe2c0b0dbVirustotal results 28.57%Heodo
2020-12-23IWFZYXX.docdoc 158e3c1a9e0f1942aec57f44ff4569d2a576bad56846a77053f5b4f726c14258n/a Heodo
2020-12-23E93NQ502.docdoc 34754f71c9d37d965839231746871e3afcd7cc6d4a4515dffcf6fff4c8e7b739Virustotal results 26.98%Heodo
2020-12-23IRT3KEXOG99OAFB.docdoc 521ef9721a64f893dc83cf84caab9a76ce0b537e5605d20126c954d3489d89e9n/aHeodo
2020-12-23UX0RFHHP0C6NK98.docdoc c693baac5d3227d362a0fe99ad187c18cde1f45a404c94c881d424023303a744Virustotal results 27.42%Heodo
2020-12-220PYFV67GP55O7.docdoc 5c4cab29ee87b07eb6a57ccad782631b9281fa4db8f0a1b12d2672584426ccceVirustotal results 25.40%Heodo
2020-12-22VNRPSMN.docdoc 000b049debe1595e96d46d2cb910795e269d9d3f1b3210bfa45901356b3b3b3an/aHeodo
2020-12-223700FCIDL347B.docdoc 05c57f48c8b1958bf16f64a292f9aa05a43f6185d02c54a0d8cf03b2fbc56ab5Virustotal results 25.40%Heodo
2020-12-22JV7D3C9DNH.docdoc bc80ebc602752fe60bc486b8620ac2692c2cf2f368e79cecd3a281ce807855e8Virustotal results 20.63%Heodo
2020-12-22J5VVXIH2YYMVPGH.docdoc bdfab9675a34c6da34487f2c70f297960002e6c3c2a8e6fdc60ae7edbe67101en/aHeodo
2020-12-22ZPLOQLZ6H3Z.docdoc d4f5f3aaeeddc099dd63c275bdb2ae1bfcb6c3232c75e93fa0f670eecb36e518Virustotal results 22.22%Heodo
2020-12-22MUN58WVM3AWPUDU.docdoc 44b69ab822ea1d2cea11bde2cbf85cb033e753dcc8b5e30dc49cb042d3310aadVirustotal results 20.63%Heodo
2020-12-22CNC5XKJF689GSS.docdoc 2b3c9804804fdcc11bb7fe3e0d269d644f968eae8f77d314ab1e8e700529d5e5n/aHeodo
2020-12-22VDAOGOWF3UHOIKV.docdoc 38c88edd4794af1b22aa61cf3280125279349dbe7040742abea9ad97b8bbccd5Virustotal results 17.74%Heodo
2020-12-22IBA891FBFC2BEW.docdoc 3e85ec8cb82ca5f5fe148bbee44739d915ff8413a23e4deb32326b4b57b68d8bVirustotal results 19.35%Heodo
2020-12-22G0L87SJMY.docdoc 755b0648467884ea407cb2be70ee59bdff597edec6e149816e553134e25aaf54Virustotal results 20.63%Heodo
2020-12-223C5ZQ4ZA43HFH.docdoc c694552f75318998b6225a21646a9893f1a581109b151e283b09868cc24424d8Virustotal results 19.05%Heodo
2020-12-22UCWMFD99O.docdoc 636b5138fc52da9fd4cc02ade2b4dc4986baf4b8614fec61d464e4a55f8e7e22Virustotal results 19.05%Heodo
2020-12-22VRWYTJ.docdoc 53349be9f04bd91fc2896163434923295124f86d9f8cec1d0c6a244cc15bde9dVirustotal results 19.35%Heodo
2020-12-221RTQ220SEKO86WC4.docdoc 7bf5d728fcd19d3df1127a4d8648cd870c5d123ce9ea4b10eca54cbcd18e10afVirustotal results 43.55%Heodo
2020-12-22674U6PTB5.docdoc 488f8395eba5921015765418ae513c78b43c6d199637c8f1df754431da65cb91Virustotal results 42.86%Heodo
2020-12-22CG0XJ6DYLV.docdoc b0116ad85e9336df147a793ad30d615386ccf2df1095c8cf30ada653b5349f3eVirustotal results 41.94%Heodo
2020-12-227WCSVLESPPI.docdoc 46d74826799bc3bea6197713c8b199ed1faed920028c4d3acc7cbcc186276b6fVirustotal results 42.86%Heodo
2020-12-22PALMR6SD.docdoc 0bf21df6643e15a9eadc034f6e7bb35aa9d1b1433bad331c1944fe60418e23b7Virustotal results 38.10%Heodo
2020-12-22UJDD6E7RAS.docdoc ca93317d1d526ec7ad19a487cfff9df808e5ca37aefd09b481f17cb982adf0ben/aHeodo
2020-12-22WPQKR4MM.docdoc 884af4ef4c4cce6b4b6d059a23ddacf8aeb92b68fbb4dcedfbaae3352f1fc5cdn/aHeodo
2020-12-228GZYIQ5E.docdoc 30fcb0b638fa78c9ec712cfdde89641c5d6a6ae28c3bd1fa75b29f9b78855721n/aHeodo
2020-12-22DFRTI484Y2T6QI.docdoc 7ec200a834392208ae8521c4804d11ff669137b4265b732a17660527ccf3cf36Virustotal results 36.51%Heodo
2020-12-22IWLCCI6.docdoc 0ca72ce4d6b45d4c63a514d52e63ef5d16506801e86c1580e6196848f66577d1n/aHeodo
2020-12-22XIEKY9QM50KJYMM.docdoc 2eb890f47074a802abff73fabb722541ca607ff36a0139e4d236e875191e0078Virustotal results 36.51%Heodo
2020-12-22GNTCXGU46VIL91.docdoc 551910c092733b7324c377351583667a6389e76f8e36f1ee73c82d354f970cbcn/aHeodo
2020-12-22H8NHV0JVZ0F.docdoc 7be2388880d2ad20b0cfa616a726d7c91d2904da8f3f8ad4d2236d3c79e935fcVirustotal results 37.10%Heodo
2020-12-22T7RCO49YVVN.docdoc 44567a5fc7455899c29966d8b05b823a60aa48487ed47b4ee9262fbd73bb6a1dn/aHeodo
2020-12-22OGK4K56MB2A5KIP.docdoc f5c3a4835556312def47eec6b714b8a28021bcd8815fe1151f2f2a5097b20c9dVirustotal results 31.75%Heodo
2020-12-22ILATPUY2.docdoc 0fa3b6c84324a37d9b25ef2c2e916f46e676dc5ca1b25c54784adf43ff0e52efVirustotal results 31.75%Heodo
2020-12-220F86V4SKSBNRZHM.docdoc e48eb9cca61adb1998120f5444bee783433127651cae6b81024a94d30d219652Virustotal results 31.75%Heodo
2020-12-22R6FOJEM3YAXD9.docdoc 5bdc116f61159b0fdf12780d8228204288849c12c8cd79641e3061b1c4a8c0c0n/aHeodo
2020-12-22W8H6N7EBC1.docdoc 90eb141295b5129c24d9912d41c928c501d0686504aa1f4df32fe72fedaabf6dn/aHeodo
2020-12-22FF6YRJO5QOL2OJ.docdoc 40662dfab1c2354498969010dcf09c1998267de262631c1d19b8b7596278d92bVirustotal results 32.79%Heodo
2020-12-22W4ARSNF5P4J.docdoc 566fe93d300d3868d8d2cd02737b4f06a8cbbe4827e8280a372807fa3b807e80n/aHeodo
2020-12-22FTPW0I14L.docdoc d891344c9d8a55fb3c94ca53e96c96b05a56789cf097d10b30e9f0533abb1665Virustotal results 30.16%Heodo
2020-12-220JFVJBBU9U.docdoc 8c609a2a6e8a0753a2e8749e054a04f699c4bc379523bf3029413cc4f61163c8Virustotal results 50.82%Heodo