URLhaus Database

You are currently viewing the URLhaus database entry for http://valentindiehl.de/writers/ZNtM-SzBXZJDAm1Xx6iE_QJZxOgpVf-0i/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:176036
URL: http://valentindiehl.de/writers/ZNtM-SzBXZJDAm1Xx6iE_QJZxOgpVf-0i/
URL Status:Offline
Host: valentindiehl.de
Date added:2019-04-11 22:55:02 UTC
Last online:2019-10-28 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-11 22:56:02 UTC to tech{at}serverprofis[dot]de)
Takedown time:6 months, 19 days, 14 hours, 45 minutes Bad (down since 2019-10-28 13:41:28 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-09-2778403012_2019_04_12.docdoc 38b3717d24388ef61daedfef45e9668943fb4a38a22c5d50e4dbffc64b9ff034n/a 
2019-09-1878403012_2019_04_12.docdoc 8723e44b0cfc342fdf1ea8ee3c60e380471f96d38b9a479e65541bf6692233b1n/a 
2019-05-2978403012_2019_04_12.docdoc 112278e446cc3c7f538089cae3eaf962b06218cae4bcd8fb9a0b493bc380507fVirustotal results 66.13% Heodo
2019-04-12438946408856_2019_04_12.docdoc 5017ececeb4d4f7c8483dd8178df693760ad227e94053b560ac60cd81870b199Virustotal results 28.07% Heodo
2019-04-1288147559349_2019_04_12.docdoc bb96f404b090c1e4c7853dadaad4846d135969a401747c87ee93b760fc844331Virustotal results 27.59% Heodo
2019-04-1280099926147_2019_04_12.docdoc 8fa2a91359b44c86c77775b3227c8ae0ccf1f882dafaa3309d0b8fb315437274Virustotal results 27.59% Heodo
2019-04-1263412902_2019_04_12.docdoc 9bb3d3a40c0a57ee9a52bab10b2ec0efbf7d665238c421a68c266d356b81a671n/a Heodo
2019-04-1194232728_2019_04_12.jsjs b6cfe1983ff1d2fb772c8e68fcbd69f805d5b488ded023a6c13de39965af95f6Virustotal results 10.34% Heodo