URLhaus Database

You are currently viewing the URLhaus database entry for http://team.neunoi.it/ohSVI_R07-wtfC/Xrb/Clients/2019-02/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:120197
URL: http://team.neunoi.it/ohSVI_R07-wtfC/Xrb/Clients/2019-02/
URL Status:Offline
Host: team.neunoi.it
Date added:2019-02-08 14:24:49 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2019-02-08 14:26:21 UTC to abuse{at}hetzner[dot]de)
Takedown time:3 hours, 4 minutes Good
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-02-08attachments_521616410363.docdoc 6dd3db17a49bdbe0969b3bc5518cedd9ce2cfc3ea3de0802861d04ce6eb201b1n/a
2019-02-08Attachment_03215887.docdoc a331d635cc6ea54cc90520e8f5d8007365a09eeb7484944049a8e3e9339a6978Virustotal results 38.60%
2019-02-08Attachment_952359362.docdoc 63323b9b68fc5110ae3c48f539a080b8de1f1e993ffb459afefd63167beb41dbVirustotal results 41.07%
2019-02-08attachments_00340739594.docdoc 9708a46ec59b25381115ba45aec14e641520502ef69757d5935277d645d2d602Virustotal results 37.50%
2019-02-08Attachment_094006753650.docdoc a3fbdc3e28f63eadd3255e26b33739b2d9fd03fe55398c089338eed822a119d3Virustotal results 34.48%Heodo
2019-02-08Attachment_43634327.docdoc b2757e9ba840282daa4e369705e54562b5ee31a26f8707644eb512fd2212c876Virustotal results 36.84%Heodo
2019-02-08attachments_48200336678.docdoc be5256995ca42d63a36e9eb9d273cfdcca4c3fc4e2e7e973a11ae660d17857d3n/aHeodo
2019-02-08Attachment_48798188.docdoc 4b3dceac6169b45b6fc9a934e8d31cde7d147f49eb51a84ba9e72c11f0d7251fVirustotal results 32.14%Heodo