URLhaus Database

You are currently viewing the URLhaus database entry for http://chiro.lead-tracker.com/cgi-bin/3cjzauq-geagp-vbltl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:191347
URL: http://chiro.lead-tracker.com/cgi-bin/3cjzauq-geagp-vbltl/
URL Status:Offline
Host: chiro.lead-tracker.com
Date added:2019-05-06 11:06:04 UTC
Last online:2019-05-06 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-06 11:08:03 UTC to abuse{at}unifiedlayer[dot]com)
Takedown time:9 hours, 0 minutes Good (down since 2019-05-06 20:08:18 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-06Scan_6275929026DE_Mai_06_2019.docdoc 14e2c112179900b4a24259af0f459268113ff941cd93d5dde161d0db48e34bb9n/a Heodo
2019-05-06Rechnungs_Details_279914948868DE_Mai_06_2019.docdoc 268a180b6c5dc8a4e70e883ba6bae41b38aabd07c9e2551d15d2973cbabd6caen/a Heodo
2019-05-06Rechnung_369878837032DE_Mai_06_2019.docdoc 3a5184bc92df457e98b04059df4a9710f418da8507cd0d22c853d1fa2743f059Virustotal results 28.33% 
2019-05-0647446010915DE_Mai_06_2019.docdoc f2434cbe02eeb7cb5de506e90b4e04f3f33be30f8cdb96248d6b290e2ca13cd7Virustotal results 29.03% 
2019-05-06Scan_484177999953DE_Mai_06_2019.docdoc eea95bd823fb174c71e3f70a9d625bd51f0b30fc77d2d76d651eed945c7295e1Virustotal results 29.51% Heodo
2019-05-06Rech_6859432095DE_Mai_06_2019.docdoc 242ed851ce446cd9277cab80cb6a9a30af117cf4eab6fede6aefa47c50d14bdaVirustotal results 27.87% Heodo
2019-05-06Dokument_22768591587DE_Mai_06_2019.docdoc dfa0b590e472b2ce178087e821128f1be6ca24fcfaef4dac7959792defa71019Virustotal results 29.51% Heodo
2019-05-06Rech_1419604740DE_Mai_06_2019.docdoc cec5c446695643355f24d074e42f004566b33662dab7713103d60c09a7548b1bVirustotal results 23.33% Heodo
2019-05-0694150448163DE_Mai_06_2019.docdoc 98c00ee8ad22dd45efc6a1a755a17732742b316ee2fdcab3b4b5193146ca9e3cn/a Heodo
2019-05-06Rechnung_746280236109DE_Mai_06_2019.docdoc b696acec3d27a5a7d4d5c8eaf93c4ae348ab17f78fadf6bf591a194047c742d1n/a Heodo
2019-05-06Dokument_260296015473DE_Mai_06_2019.docdoc 1241503187e6eab61e28a83e423358b340acd60ce4dcea04d61946f9c8b6644bVirustotal results 25.00% Heodo
2019-05-06Dokument_4290792546DE_Mai_06_2019.docdoc 055cba13db6f9913a4e120ffe4c9721cc8f9866776444de9d6496b29316ed76bVirustotal results 26.79% Heodo
2019-05-069576067238DE_Mai_06_2019.docdoc 257ee7fbbb316f61014c4c83196299d811c6219023bbecf754618af830490799Virustotal results 25.00% 
2019-05-06773100203342DE_Mai_06_2019.docdoc d4445e77f25f537025c47422802177e83e2964e78613eab8e65d29274f7b4b67Virustotal results 25.42% Heodo
2019-05-06Rechnung_68912865656DE_Mai_06_2019.docdoc 8909e410860976c36699fb5ffe7535464e05f12ca1f97ff3c5c9e9f2d0d877b7Virustotal results 26.23%