URLhaus Database

You are currently viewing the URLhaus database entry for http://hfhs.ch/bildungswissenschaftnet/dkAAe-kMyB_INmUoZ-5J/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:167470
URL: http://hfhs.ch/bildungswissenschaftnet/dkAAe-kMyB_INmUoZ-5J/
URL Status:Offline
Host: hfhs.ch
Date added:2019-03-28 05:32:03 UTC
Last online:2019-04-16 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-03-28 05:34:13 UTC to abuse{at}cyon[dot]ch)
Takedown time:19 days, 2 hours, 59 minutes Bad (down since 2019-04-16 08:34:09 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-122019_03_US_787449108722281638___09364876514750097032.zipzip a4700f8fdaa06f7f25c728b80db14ea589322fbc86580a5131f9986ad6bf3b6dVirustotal results 50.85% 
2019-03-282019_03___US___ACC812841229863415___197571931249.docdoc 18553615f6a2067c0286de4003621934804eef8b983dfaf4a35768221f0878c5n/a Heodo
2019-03-282019_03___US___458959405793623___9761811278971190178.docdoc c58164553162deeb496616f9bb7360a5769fc757d6001e6bab1eff480adcadfcVirustotal results 19.30% Heodo
2019-03-282019_03___US___INSTR68078880494146___3599638085199367.docdoc 5aa86074410aa1b1c35bf87c5546c883a4da6b2bec413e06e42dc56a133cf298Virustotal results 18.64% Heodo
2019-03-282019_03___US___PAY567696081___403573551619791.docdoc acd79fbe38629c06ac53f1332fa50bc6509599309f1dfebdcee6fc5f461ecdf2Virustotal results 19.30% Heodo
2019-03-282019_03___US___INSTR366374064461418___836881356.docdoc e2cde60cb978cc510404c35e2e306f1e8f4e0ad1d4198da2d15e4a7e10956f8cVirustotal results 18.33% Heodo
2019-03-282019_03___US___87645808214208___01872158866170662.zipzip d97eade081ce3c89ae90be8a27749d885ef9515f016176e0a2aba31609381696n/a 
2019-03-282019_03___US___US594160102___5597455924.zipzip 974b78d6977aa1b013c36c16e458502590e0c31e1856d9fb65e2cd997845da70n/a