URLhaus Database

You are currently viewing the URLhaus database entry for http://givingthanksdaily.com/qlE/VeF/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:949281
URL: http://givingthanksdaily.com/qlE/VeF/
URL Status:Offline
Host: givingthanksdaily.com
Date added:2021-01-05 07:38:06 UTC
Last online:2021-01-05 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-05 07:40:24 UTC to abuse{at}servercentral[dot]com)
Takedown time:2 hours, 32 minutes Good (down since 2021-01-05 10:13:18 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-05DT3e9TWw5cVoIXsC9.dlldll a45ffddcb3f374dbef17bb4a26ba8fb490e295ae0c2c8e70f35babcf00c01212Virustotal results 14.49% Heodo
2021-01-05kRXND.dlldll 043ba68cc2b551279a8163ae5c5e6b422fc05cccf5fa98d8088d517fd095355dVirustotal results 11.59% Heodo
2021-01-05dblzDcg0SxH.dlldll 43150154fed2021c7357ecfd4588c3980b096372e5a10182aad327e218b90880n/a Heodo
2021-01-0557Z1s7zC8.dlldll b08d33bc65b2e991df863e275b1f8a5c624b00db3981d60851a23bccf50e0300Virustotal results 11.59% Heodo
2021-01-05ey.dlldll 0ae0d956218ebb9fb6f594f7634c965b0e95f3dfdd5b354a6be3423253948e9bVirustotal results 11.59% Heodo
2021-01-05haOfeCPibeJyHvby.dlldll 1ff3801f8d40cc7641d50d04ccd1b552fa0a62c44746d0b99af73dd2daa11e4bn/a Heodo
2021-01-05K30DWazWMWTO5r.dlldll ce257abce9958843402eeb6b66f47d2ee89f51b98ea8f9caa75d3ec37e0ff21en/a Heodo