URLhaus Database

You are currently viewing the URLhaus database entry for https://gunreview.org/wp-includes/1sir9ElTQ65Bzq2ipsvurLO44GuDRg6mXySY8rreZlHvz5QjjpqD9MPZ8vR3BxN6ZWio98/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974652
URL: https://gunreview.org/wp-includes/1sir9ElTQ65Bzq2ipsvurLO44GuDRg6mXySY8rreZlHvz5QjjpqD9MPZ8vR3BxN6ZWio98/
URL Status:Offline
Host: gunreview.org
Date added:2021-01-23 00:18:05 UTC
Last online:2021-01-23 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-23 00:18:07 UTC to CloudFlare Anti-Abuse API)
Takedown time:13 hours, 48 minutes Good (down since 2021-01-23 14:06:11 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-23DS4ETWGMKOBHS9.docdoc 526866190c8081698169b4be19a6b987d494604343fe874475126527841c83a7Virustotal results 52.38%Heodo
2021-01-23OXRS7F4UF14V1.docdoc 57d7ff4664c6bffcb350211f1d9cbc272747c201c3c784fcfbab0f49c986f53en/aHeodo
2021-01-2304BJYE18.docdoc 3f67cebcc062ff44206ad6b1c356021133426bcb3a4070824b03036e36ba17caVirustotal results 53.23%Heodo
2021-01-23WDAONCUNRD1H.docdoc e84a53c9c72675201ca77b855375618ecae8bf0f4ce43acb1ba16b53f5a67eb3Virustotal results 53.97%Heodo
2021-01-236UJDP7R1E.docdoc 156db699149efcab714cb9f97ccef3b2179e9a3c53d20e6e0ad7e318e17ac1bcn/aHeodo
2021-01-231VFR5KU.docdoc f967919221798935016821892199d1eaf45960045a79bf0ecb89297edf4d4cfcVirustotal results 53.97%Heodo
2021-01-23VC4SJ7.docdoc 6733462a7b5f699b61d26d88edae4feb26115c8c76e0ab92f21e4605136e621en/aHeodo
2021-01-23OAGDYL8YFDJ0CB.docdoc 343a9444d82311b35e225e7f819846eb81890d285f051585d33692e2d78fb73an/aHeodo
2021-01-23O2X7J0KUCXQ7X9ZU.docdoc dcfb145c4f46a072e988cdeafc065f8116dc3b27d6bed447024677f3ea2f252aVirustotal results 53.23%Heodo
2021-01-236X5F3XGCFDLKZI.docdoc fe303e9b7b33de110864829b531bd9a586c93da165ca271358192edb57722988Virustotal results 33.33%Heodo
2021-01-23D0DKTJW5.docdoc 22d173bf822ad2a201b67dbe4adffb9e3542bc1e72c408fafd435b91ea6ea799n/aHeodo
2021-01-23YFEZKZHZ0.docdoc 1d131a111ffcfdeda18316ead79206237e3684246c4cb6ddc191994737f0294cn/aHeodo
2021-01-239DUI5I2OJX.docdoc 24093743cc1b5882bb6b43c3712d06a13dad73e41f2c95f44d71286d515a1120Virustotal results 52.46%Heodo
2021-01-23LMCP9KJZJ.docdoc 3c473745d772ab4e108f092726f7362a9e44fcd8bef2ccdffcba3363452dc927n/aHeodo
2021-01-233TWZQ6HGAKTJ21.docdoc ac3a231f0035c95d710e53ec6dd86a4a915dc23b12238c4d118e7c2b656cad2fn/aHeodo
2021-01-23LHMNMJUNIX0OQM.docdoc bbefec31ea0c2301e8202d73acf49ca0d72f4a3b80b6a81836e49b1591d3d78cVirustotal results 52.38%Heodo
2021-01-233GYE2M3UABTX.docdoc 0d95efeb799d69a27255270804aa8efa5e91cd71b55943e37e88e772c961bca2n/aHeodo
2021-01-2390FI36HCM1E4N.docdoc cb4aaffb479ed567e1cca60bdb16fe0ede6ca520f16b1129e28eae589d6f37f6Virustotal results 51.61%Heodo
2021-01-23M7NDLPQH6R33.docdoc 88b4e1657c14287bb263fcb0ed92b0b58b294c9b6e822cc1dcd152e08346dc5fVirustotal results 50.79%Heodo
2021-01-237B7PG946X8XIN.docdoc e621537a061ede5d0f947fecfccc7e9568fbc21942c2b64801138b227e4f23e4Virustotal results 31.75%Heodo
2021-01-230SJE16YXDB0L0C.docdoc ac612e34cb415fcaf5c0ae462ed0e4efee5897879ee434b80354b39fe34e9317Virustotal results 50.00%Heodo
2021-01-23GVTL9YYSL.docdoc 3b8c1a7288a8940c4785141389d323f7949b9639ca7821ebad1fc2182a2acf58Virustotal results 48.39%Heodo
2021-01-23VKHIWNA.docdoc 962dce7cc5ed4f64919264917c5f74afd1f8a3710f08274d1b6edd3653e93e2fVirustotal results 31.75%Heodo
2021-01-23OQSYDO439.docdoc 56e78f5aeb76d3b2002f79b51c0344a1bc95e0c171a56f5e7bae43028543e1cfVirustotal results 48.39%Heodo
2021-01-233OAU7D6VGKSEJ.docdoc 20b1f1c932f9ac88685c65ca2ed2d57ba42e6cc5d643c567fbff933e64e09797Virustotal results 48.39%Heodo
2021-01-23PNF62I.docdoc 65d65b1d65fcab110eca51cb529feca603cc4c5bb9102dd756faa35f157744ccVirustotal results 31.75%Heodo
2021-01-23DYZR989AQM851C.docdoc f241cc6276c27e057b1caf39073c1aaf230cd54bf6ecfbd7e08ec9bc0ff9a83bVirustotal results 31.75%Heodo
2021-01-23A214MXZH52.docdoc f34429ad75df699dbcc635b6afcd91b52756fa1d34dce852fead86e0c7eea37fn/aHeodo
2021-01-23S4NKLXY.docdoc 06706618f6fb465f559d7359295a2757c1cfd4311ae5ad13d1b3ed2acac1a2b9Virustotal results 45.16%Heodo
2021-01-23HSZY3V03.docdoc 04d66ed2d7e82444ce4d2b8227f03b6612a55e843e3ef434c01c93b65f10ff04Virustotal results 44.44%Heodo
2021-01-23Y1ME311Y5MH7NR.docdoc d5da4dc5a6a3fc416aca8ffbfaa3b6cb18a1efd11b94eb7f40a584fd96813f8eVirustotal results 46.77%Heodo