URLhaus Database

You are currently viewing the URLhaus database entry for http://www.gifftekstil.com/C4mAvqn/service/vertrauen/042019/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:178632
URL: http://www.gifftekstil.com/C4mAvqn/service/vertrauen/042019/
URL Status:Offline
Host: www.gifftekstil.com
Date added:2019-04-16 12:02:03 UTC
Last online:2019-04-28 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-16 12:04:02 UTC to abuse{at}cizgi[dot]net[dot]tr)
Takedown time:12 days, 1 hours, 58 minutes Bad (down since 2019-04-28 14:02:26 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-18256000458-O-20190418.jsjs 73da7ffa3619e3e8afbc2334219f1bd4be18b4128d835e2dfa9db8e3a9e239f5Virustotal results 7.27%
2019-04-1781691294868-R6-20190417.jsjs 7460accf81db3640d5f7e1e7b430431adfd687918983e78ecc12a0308f95ec47Virustotal results 7.02%
2019-04-1700116483602_AT_20190417.docdoc 26ed293e598bbbc392e9a279ca16107df3cae693344100e53b0b6868f3eab1c2Virustotal results 19.67% Heodo
2019-04-1742070884_A_20190417.docdoc f6339ecff9972ad336d7f8205dca001b36969fa1fe9a0096ee6e4e0adc896b61Virustotal results 22.41% Heodo
2019-04-164199064965_E_20190417.docdoc 2e8d8850ce6eef2b5c581585b71f4dc1aa794b0ff01abd369386b4cdfe8996fdVirustotal results 36.21% Heodo
2019-04-1609312979142-X-20190416.docdoc 069c96335cd2e28a1a7bb25f4a3435be8a006971550e5f96945fca1b32488d46Virustotal results 31.67% Heodo
2019-04-165894030-B6-20190416.docdoc d248f2846356902c426216bf0746a0ff149172789ec9407054428968f3133329n/a Heodo
2019-04-16599822983_WA_20190416.docdoc a06cd9a2d0ab03dfb8075a730c198655bcd5759395a33843831339c71d8e133bVirustotal results 32.76% Heodo
2019-04-1644558718945_R_20190416.docdoc a505fc37d8eb990b3d8567df5fa28f8c217fcbf0ad2b69fbad4d3090b1c3927fVirustotal results 32.20% Heodo
2019-04-16871382135-1-20190416.docdoc 56459d52dd7a5f3045b96edabc33e19ce54b76ecb8c499d406acc77a1823cd91Virustotal results 32.20% Heodo
2019-04-16888426395_JJ_20190416.docdoc 2d4c184275e72715123f48151daaf96797095b62be433ff2b2942136b8cd0d6cVirustotal results 33.90% Heodo
2019-04-1688978379542_6_20190416.docdoc 680ee4977dcd11eb2e044535549cb20410efed7ec1992723d965553dd7170006Virustotal results 26.67% Heodo
2019-04-160650248436-4-20190416.docdoc e1b6a1f0ec7bbb25df0af7523500ed76849c77b52766336de44266d36f821a76Virustotal results 27.87% Heodo
2019-04-161119361795_YI_20190416.docdoc 8a703f09affec429c37d4b1a33713cc14783deb3a11fdc3a9eac96abbe474a7bVirustotal results 26.67% Heodo
2019-04-163525596_G_20190416.docdoc 93e3eefa3b8a2f13770e7ed9469079af83cb67383c49ba7adb68e5576bc10432Virustotal results 25.86% Heodo
2019-04-1609409083-HH-20190416.docdoc 40f7c562ff31df5261bedf7fa61b88e172076727367cfaec53493459be662381Virustotal results 24.56% Heodo
2019-04-163015771072-R-20190416.docdoc c36a84ac4248717b11593ae5d171b18d356f9320df67bdf7bab7a99b2ecf028aVirustotal results 31.67% Heodo
2019-04-1697190940635_9_20190416.docdoc e00805df54f4f51b169f272498d70faa22d3522c81d7a6dbd3b3ee21670f3be5Virustotal results 26.42% Heodo