URLhaus Database

You are currently viewing the URLhaus database entry for http://www.citygroupkw.net/Januar2019/INFPPXH9980256/gescanntes-Dokument/Zahlungserinnerung/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:103939
URL: http://www.citygroupkw.net/Januar2019/INFPPXH9980256/gescanntes-Dokument/Zahlungserinnerung/
URL Status:Offline
Host: www.citygroupkw.net
Date added:2019-01-16 05:14:48 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL :Not listed
SURBL :Not listed
Quad9 :Blocked
AdGuard :Not blocked
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2019-01-16 05:16:18 UTC to abuse{at}privatesystems[dot]net)
Takedown time:13 hours, 42 minutes Good (down since 2019-01-16 18:58:26 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-01-16this-site-is-virus.docdoc c2e393ff568f4a87ce48011f10664138e569710f56ddc0462aa7f36bdad5ecadVirustotal results 0.00%
2019-01-1616_Januar_2019_17_49_01_Uhr.docdoc dc36ba3238a3f4761e54cc6f9bc4b43420cdb2b00705574d61898b7c5acf003dVirustotal results 23.73%Heodo
2019-01-162019_Januar_2282577550.docdoc 116e6f63bd00606d7861a22bd786633c7d7d1e99c61fa2827429ce8c8a53499eVirustotal results 25.00%Heodo
2019-01-1616_Januar_2019_3478855356.docdoc 22221150a875fd5e24ee0a554b2cdead6543e35b6899641a3f21425c632b0201Virustotal results 25.00%
2019-01-162019_Januar_8265037815.docdoc b1ed504b77cb03d7387f7cb22a98b12b661281d8983cf21fd702c7bf95129c7cVirustotal results 25.42%Heodo
2019-01-162019_Januar.docdoc e7c1d077cbd3dd185b7e7ecd6ed2f0195b2ea098e571c78ba60da5cff90c897bVirustotal results 21.31%
2019-01-1616_Januar_2019_13_53_42_Uhr.docdoc a54aee546321a9f8cce4b3f90fe12e293f606221472287b8939eaf74d18f2a9bVirustotal results 20.34%Heodo
2019-01-1616_Januar_2019_5598687774.docdoc 1209a346d7a0910677c17501cf403fcdf0c2d747fa6f4c8e19309490581437f9n/aHeodo
2019-01-1616_Januar_2019_13_04_45_Uhr.docdoc 9890c5f1c9bd2bdd1cd1994eb824a3578639fab9915352433d414862ec8d2c90Virustotal results 16.39%Heodo
2019-01-162019_Januar_12_31_54_Uhr.docdoc 45a1488212de6bb015b47f1cebe3c9060af7fdb41f5f52ea951c444731c83d5bVirustotal results 16.95%Heodo
2019-01-1616_Januar_2019_12_00_42_Uhr.docdoc 03edcabef5dd2d66c7490c0ccac33462f9c138ea087d7572ae0fe26b76cb8051Virustotal results 16.67%Heodo
2019-01-162019_Januar_1369303276.docdoc 8a5691abd1d7ccd29b420dd08d622362d79a17dee1aa5d47bd0fe35117dbdca6Virustotal results 17.24%Heodo
2019-01-1616_Januar_2019.docdoc ad19964733761607dfa3e86a27be17de79bf6580e62588cc90a2c1a9a9bc8f53Virustotal results 16.95%Heodo
2019-01-162019_Januar_7310582970.docdoc 6c6cde186a8b11112384e7e53ecff759d36b1e28463cbc63b1822875ae5119a4Virustotal results 16.67%Heodo
2019-01-1616_Januar_2019.docdoc bf34cdbfc143baf710e25dbbb29c52a557bbb0485e5325f085f926f32507ba63n/aHeodo
2019-01-1616_Januar_2019_10_16_42_Uhr.docdoc 12aadbd5b565bc0fbb49e9b677df6eca87ff5c1b4513c72e33e4ee4afbaee8a2n/aHeodo
2019-01-162019_Januar_09_43_43_Uhr.docdoc 9b8d80b18ce7849e7be22615a192ca30f4cd2bafee6adb7b26ffb78a6ae548f5Virustotal results 17.24%Heodo
2019-01-162019_Januar.docdoc 512ec5b03376581c8ee4c65e21e9b2e9966017551c28a76310729ff44d661a52n/aHeodo
2019-01-1616_Januar_2019.docdoc 11d3a960368ceea3387f2b25f5c488f84835ea9d04c01a9e8fe043e49bd02496n/aHeodo
2019-01-162019_Januar.docdoc f6d3c9abc6ddb2a5b0b88f1b0737f4c2d25febbea2822c411ab8fdcda2e0734eVirustotal results 16.95%Heodo
2019-01-1616_Januar_2019_8142123430.docdoc b01700c2715b92973f8a54a9f478d269c98f065cfe14e43f3cdb6eeda77e504fVirustotal results 16.67%Heodo
2019-01-162019_Januar.docdoc e01fd8b0d49aabbdd6506dac67eaefb794ef6e6a3e8e6db8ab9314017b4fb000Virustotal results 18.33%Heodo
2019-01-1616_Januar_2019_4207080461.docdoc 9b2a3d826b621706a832ca9b8c8cfecbcaa0f182565faf46b5fb6c137e223e01n/aHeodo
2019-01-1616_Januar_2019.docdoc 88bd59d5cbdaa89a919961ef9c2af7cd643844100a4c36e0775e85286a1c4f71Virustotal results 21.67%Heodo
2019-01-1616_Januar_2019.docdoc fb3f9c2fa4da38083e182a4dc9f941a7b8b4f23f4da3bed7c51aea64c6ba6b16Virustotal results 21.43%Heodo
2019-01-162019_Januar_5540220233.docdoc 851f42b2bc5cd34e97fcd6f72e11a58b49cb66e3482ac0cd4faae086d530be5fVirustotal results 15.79%Heodo
2019-01-162019_Januar_7735790182.docdoc 59a592aa6da98097a35f8f9055c4e066c4e28246b272caed01552a3a292b094dVirustotal results 21.67%Heodo
2019-01-1616_Januar_2019_06_29_28_Uhr.docdoc 3c0bb36132eed1bd610822e35d6e17ce064ab7d003e112beb0cf41a3da6acc4bVirustotal results 20.34%Heodo
2019-01-1616_Januar_2019.docdoc c62f02ac392d005e396bf0bdf4d7eed9c2ce49183d1fe4c694c13cbe7201eaa0Virustotal results 21.67%Heodo
2019-01-1616_Januar_2019.docdoc 4fb0a7b276294ff5e3b63a47928915d35fd1ace3aea908c2d23d0f6a42f8b3a7Virustotal results 21.67%Heodo