URLhaus Database

You are currently viewing the URLhaus database entry for http://geekdeer.co.za/wp-admin/tajuYl8RmxN5AtIPjgqGBr9ueSL2k1z9eVw9XXdRS6MDrdKBNR2grcD4GU/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:945770
URL: http://geekdeer.co.za/wp-admin/tajuYl8RmxN5AtIPjgqGBr9ueSL2k1z9eVw9XXdRS6MDrdKBNR2grcD4GU/
URL Status:Offline
Host: geekdeer.co.za
Date added:2020-12-30 18:51:05 UTC
Last online:2021-02-11 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-30 18:52:08 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 12 days, 12 hours, 10 minutes Bad (down since 2021-02-11 07:02:58 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-31JIL59PZ.docdoc 43af38ecd27585f00463abfee0ca7f492fb36fa862c8d215447d59be27652589Virustotal results 50.00%Heodo
2020-12-310OUJOFPYKP3.docdoc d08bca9f926920b2f85e5b7bec30f872cd48615f0ab552f727f9cae055fab628n/aHeodo
2020-12-313Y460FW0.docdoc c168664a75071253dfd62df7177913300976fc8a363af43e46997584d51669cbVirustotal results 49.21%Heodo
2020-12-318GCRX2.docdoc f188a66e42ab843218ecec727c9910b6205a89b8f96a980c0738f83cb7190e5eVirustotal results 49.21%Heodo
2020-12-31O6NQ0558.docdoc fcd4936265c3d59d43ed6c51658cafd788f22ab0e3601f832346c762c3d97c2bVirustotal results 47.62%Heodo
2020-12-313O6YECQP5X5VSCC.docdoc f4ba2bce0a0fcc57183c73e46feb6f6fddfcac25d12032d47d93302aa9bb40b4n/aHeodo
2020-12-31IWIGQ4.docdoc 6c4a7652f59aa03c67961983f167f86eb3a64ba568f0c4629c5adf18c82e2ce8Virustotal results 42.86%Heodo
2020-12-31T3XU48.docdoc 1486fe920f39107bae3cba0f5fbfee0eeee6a5ff8389360cf26868c9bb692730Virustotal results 46.77%Heodo
2020-12-315462W6O71W.docdoc 92f3ec8ddadbace9623d6af0c230b651775947b4da83ae9b5ab3ea42f866a62aVirustotal results 47.62%Heodo
2020-12-31ZE21441.docdoc f9929b5a3d5cb50bece6e6dd8e553d79f36e34bcf71e2f302d709d108582e6d8Virustotal results 42.86%Heodo
2020-12-31R60N9N7T7D1.docdoc 97a4dbe571c81cf11a56f00a073dca297a48d859ad36ecd46a9d5aff9c3eaa97Virustotal results 42.86%Heodo
2020-12-312YFUTDB8.docdoc cef8b994dc5f1845b385523d62337a44acee6a6b6fde88bd8801e65cb4074ee6Virustotal results 46.77%Heodo
2020-12-31VBY7AF.docdoc 18bb61d704aea3eb9f1d69649f16dad532c1236486dbb9891c0bf5054c63aa16n/aHeodo
2020-12-31KADSVA14809.docdoc 22c9b454977f772e641fd2d5d4c08fb9e124cdc9ec47c69ed037fed87bbf1abbVirustotal results 44.26%Heodo
2020-12-31HUAH2JNNB8GB5GL.docdoc 7dbe3e3f4d5e95b69111858fc5e96f73c1b7f8284276a1280486ab64139324a2Virustotal results 41.94%Heodo
2020-12-31R4IN0TJ.docdoc 75e6fc7e5c98a20bc64f7944d2bead6901f575fe20135e9aafe210ee2e1e2c49Virustotal results 42.86%Heodo
2020-12-31WNRD6H6JKGXP6O.docdoc 3d426817cb9506ac02f7d7ae3cebe38e2125efde6eb7ee4af0251a6afdfa2d26Virustotal results 42.86%Heodo
2020-12-318WGL954QWB6H7SG.docdoc 14eef594729b6784626929323d1f4a040cf76e3774ad5b77a16c28449db182cfVirustotal results 43.55%Heodo
2020-12-31QYKNWGZKX.docdoc c531afa39691d1fec216f1c5c1016c155176f104b4b83189b1f4ca82efcdec60Virustotal results 40.98%Heodo
2020-12-31V9WOALE6.docdoc 214c118a6ea6243f11f97d6a83c14ce0efa696dcf534eb46de221d4199cb7c88Virustotal results 37.10%Heodo
2020-12-3119Y914ABNDMAZGH5.docdoc d6dae3570b800a4a54bbb661e945c2870952058174a0ac704127c7cfe8330bcdVirustotal results 39.34%Heodo
2020-12-319BB0H4J7KYUIL.docdoc 68dafb6ed5bb318a77e710fd66f9beffc66a4f84579fb3c160bb3c8c8b457acfVirustotal results 34.92%Heodo
2020-12-30OBKJRETCC5SG.docdoc 48cbbf0f9680ad78df8965f1b76d756f88912c653711968364b7f7eb3f5795b0Virustotal results 31.75%Heodo
2020-12-30Y3D8WR2I.docdoc a2bee4290712595f0afb87e5a247cafe694d279fb7350e43bc163630e926aaa4Virustotal results 27.42%Heodo
2020-12-301HZ30QXDYV4BU.docdoc cecc306de3cae60a1f3d988356054754d0d3dcf8666045f718d5cfbf53e6a730Virustotal results 46.03% Heodo
2020-12-3091QSGJ.docdoc 819ebcf8ac92646fe0337cfb241ea5ae4d5a04fcc9284cde8adad3f068c018b2n/aHeodo
2020-12-30MYKWCOK24K.docdoc 48242492ae400d1b2e95ed96ed2298bc76c87036b1f79e92d38a07e5cb14712bVirustotal results 41.67%Heodo
2020-12-309EMBPX9T4U5TOW5.docdoc 12648728174c80a68b9992c8759df7e021f27fef6bbee5bed8af71b18a7fadd5Virustotal results 41.27%Heodo
2020-12-301CK3KET.docdoc 6b85d222fb12df6466d8b1dae31bb6e7706463ec73fd86f85e46ef7867183df1n/aHeodo
2020-12-30R6G5660K.docdoc 7a1dddc29a6b87ff807093d52c2c2ea7139641511f39fa0a834c101bd431baaaVirustotal results 42.86%Heodo
2020-12-30NFGA70Y.docdoc 3bf59384c4c1a24eb5fef4453dd1fc63a75324f4aa6b86a62ba47de3393027a9Virustotal results 41.27%Heodo
2020-12-30Q3UA0KN7RKV8YGX.docdoc ef0d7361d6fb7364b837a9356bee96b95aafbc934ce3836f631f7a4683ce40e7Virustotal results 39.68%Heodo
2020-12-30E33WLCSO3G.docdoc 712989be681e3a6e8cd47b84ce5feb957d2cfb47367d96bbc7dcd6551bef1f51Virustotal results 38.10%Heodo
2020-12-309RUU84GHPPW8.docdoc d2178edbfb636aa2baf306d59be6a8c651aa2167f67893e6ee70469cc13de307n/aHeodo
2020-12-30PC5POKZKU0YZ3N1.docdoc 643eeead31f1c79f2a2d191699189bd671ca0169fff0feeb3824ff0b57281e3bVirustotal results 31.75%Heodo
2020-12-30K0SADV3.docdoc d700110437e868378fd668cf27a7df7611da72d285f7b9d7edfd2d08475a47b5n/aHeodo
2020-12-3036I78H.docdoc a3c7030635319611442140f4e775bd30cb0379b86a430e9b54df0ce366d7db30Virustotal results 29.03%Heodo
2020-12-309A46FG6RSNISTO.docdoc 315dce173e7c32092cf4b83b7d27b520156225dc90d11322b56244ac2b61810en/aHeodo
2020-12-30TAP9VPZ2Q0UHXR04.docdoc 58e9689587eedb1e893c93baa299ea296c05222359dbe281306ec12304d3a8c2Virustotal results 27.42%Heodo