URLhaus Database

You are currently viewing the URLhaus database entry for http://alpinaemlak.com/wp-contents/legale/Frage/2019-04/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:178621
URL: http://alpinaemlak.com/wp-contents/legale/Frage/2019-04/
URL Status:Offline
Host: alpinaemlak.com
Date added:2019-04-16 11:38:15 UTC
Last online:2019-04-17 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-16 11:40:05 UTC to abuse{at}cizgi[dot]net[dot]tr)
Takedown time:1 day, 11 hours, 28 minutes Poor (down since 2019-04-17 23:08:34 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-178557061238_1_20190417.jsjs 7460accf81db3640d5f7e1e7b430431adfd687918983e78ecc12a0308f95ec47Virustotal results 7.02%
2019-04-178459552_HB_20190417.docdoc 26ed293e598bbbc392e9a279ca16107df3cae693344100e53b0b6868f3eab1c2Virustotal results 19.67% Heodo
2019-04-1791041899-7-20190417.docdoc f6339ecff9972ad336d7f8205dca001b36969fa1fe9a0096ee6e4e0adc896b61Virustotal results 22.41% Heodo
2019-04-169044734_Q8_20190416.docdoc 069c96335cd2e28a1a7bb25f4a3435be8a006971550e5f96945fca1b32488d46Virustotal results 31.67% Heodo
2019-04-162208333-D-20190416.docdoc d248f2846356902c426216bf0746a0ff149172789ec9407054428968f3133329n/a Heodo
2019-04-1619678801981_WB_20190416.docdoc a06cd9a2d0ab03dfb8075a730c198655bcd5759395a33843831339c71d8e133bVirustotal results 32.76% Heodo
2019-04-169643145120_Y6_20190416.docdoc f86aab4608e99544ab0be1b74cc25db563ed1415e9aa52adb110ac5afb2ef5daVirustotal results 34.48% Heodo
2019-04-160133262-W4-20190416.docdoc 56459d52dd7a5f3045b96edabc33e19ce54b76ecb8c499d406acc77a1823cd91Virustotal results 32.20% Heodo
2019-04-1668540652_EM_20190416.docdoc 2d4c184275e72715123f48151daaf96797095b62be433ff2b2942136b8cd0d6cVirustotal results 33.90% Heodo
2019-04-169867117507_L_20190416.docdoc 6b71be316e91d4679de2085f3e1652bdacded4f30630f2351124d1e1387463c9Virustotal results 32.76% Heodo
2019-04-167763287-A-20190416.docdoc 8a703f09affec429c37d4b1a33713cc14783deb3a11fdc3a9eac96abbe474a7bVirustotal results 26.67% Heodo
2019-04-1603635074264_DK_20190416.docdoc 93e3eefa3b8a2f13770e7ed9469079af83cb67383c49ba7adb68e5576bc10432Virustotal results 25.86% Heodo
2019-04-165043022-S-20190416.docdoc 40f7c562ff31df5261bedf7fa61b88e172076727367cfaec53493459be662381Virustotal results 24.56% Heodo
2019-04-166495695766_5_20190416.docdoc 9d9aaa50a40637604a1240aa8364f96c9a0d42c80cac98eb49ff3e26b3d3f86dVirustotal results 31.67% Heodo
2019-04-164725649-MB-20190416.docdoc e00805df54f4f51b169f272498d70faa22d3522c81d7a6dbd3b3ee21670f3be5Virustotal results 26.42% Heodo
2019-04-16839991706_V3_20190416.docdoc af06427e75ba3f81013ca4d2303e110dd6780e8f7f9bfac3336a02d39b79c8cbVirustotal results 28.81% Heodo