URLhaus Database

You are currently viewing the URLhaus database entry for https://manualdareconquista.com/Search-Replace-DB/0i7tk-pr0s4-rpdtehd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:191490
URL: https://manualdareconquista.com/Search-Replace-DB/0i7tk-pr0s4-rpdtehd/
URL Status:Offline
Host: manualdareconquista.com
Date added:2019-05-06 14:33:03 UTC
Last online:2019-11-30 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-05-06 14:34:02 UTC to abuse{at}vultr[dot]com)
Takedown time:6 months, 28 days, 0 hours, 33 minutes Bad (down since 2019-11-30 15:07:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-30n/ahtml 11a8c148351bcc3914a36deac45c47c11de6025914feec4838376c39bcbea8bfn/a 
2019-05-08Rechnung_5825290535DE_Mai_08_2019.docdoc 7569c44f5d04fef27c5b9be4b22eee2f5f81edb46857e077255f4d593cf09d33Virustotal results 32.79% Heodo
2019-05-0821960308738DE_Mai_08_2019.docdoc a6654bf3a1dc1407b542532d1a9d11c30b84cdd9cc736abccfec742eb677b117Virustotal results 32.79% Heodo
2019-05-087989886058DE_Mai_08_2019.docdoc 910b21b089dd8f21d37f4a08fb65efe7d20807abedda2a694bb1bc42dbbf4b90Virustotal results 39.34% Heodo
2019-05-08Scan_128623090105DE_Mai_08_2019.docdoc ce167af75e50476a8b2d4e8b9634594333f949ba78d64001efd6b16c9f4220e8n/a 
2019-05-08Dokument_12532964423DE_Mai_08_2019.docdoc 3c0ad83a45a3cdc5d74704e4ca026a5af448f0fd2d70e43de077ac2defbfbe2eVirustotal results 32.20% Heodo
2019-05-0846459979098DE_Mai_08_2019.docdoc 24267568d3fa011adb7ef53f107f6aa01162750e40eef869781ceb0ce6651f54Virustotal results 32.65% Heodo
2019-05-08731967116138DE_Mai_08_2019.docdoc 93404bc2b21ae4c2eea881e5bfaf89e24e0f038467b271ab9ae1c96ff461b910Virustotal results 31.15% Heodo
2019-05-08Scan_42678787770DE_Mai_08_2019.docdoc 713b34f0494e837eb6b50e34b67c944ca9b271f30fc81ae59ce8cecefb835f37Virustotal results 30.65% Heodo
2019-05-08Rech_79694064280DE_Mai_08_2019.docdoc 3e7d6e2f8a0965f759788182fd17786fa9ba5ecafdca5b71b86c737d09ace85an/a Heodo
2019-05-08Rechnung_4377028804DE_Mai_08_2019.docdoc 9cb9e15e944c542fc3308e7b5c9108994bc6522efa562d3c89d5b20d232a260dn/a Heodo
2019-05-082122469693DE_Mai_08_2019.docdoc d7fc74cd2d6f34bcc7e02522812778a91bbc6591f4805164208847add84ecf2eVirustotal results 33.33% Heodo
2019-05-0858354017130DE_Mai_08_2019.docdoc f431544f9099b4f86cf43b676b6be9752436fc4773cf672f23f743b17c41eb9dn/a Heodo
2019-05-0845212592744DE_Mai_08_2019.docdoc afc7e59c3f7eb40403410c8ea91e4483a08c01fe3dbb9e5ec2d792db05d71615Virustotal results 31.67% 
2019-05-083734697646DE_Mai_08_2019.docdoc 4199ac96a54a1125914dd6d442d3827273228153c600083f1ad4290c9dd2030bn/a Heodo
2019-05-08Dokument_6850372915DE_Mai_08_2019.docdoc 28cd75af6569612c8dc642936de3a2680f75d49e1d38be1a3a782fcf11dedb31Virustotal results 26.67% Heodo
2019-05-0827000853544DE_Mai_08_2019.docdoc 1667101838ea1804515221c8a6b6b55f2629605f5900e10f5ad9681d62659ab7n/a Heodo
2019-05-08195700594417DE_Mai_08_2019.docdoc f47066b0cc76015cc75de6b864de2d94048b07e5907d3aa8de1716050d655b22Virustotal results 28.33% 
2019-05-07Rechnung_734663877484DE_Mai_08_2019.docdoc cc5d88ce8bdcae9b0807e00ac25b8810061ef74875ce4c1e6de004b6bb42c594Virustotal results 27.12% Heodo
2019-05-07883138251637DE_Mai_08_2019.docdoc e7b78b900c3b24784538e7a4c770d7287cf87e3fa2d6b3de7a8d0406f07b4ab7Virustotal results 25.00% Heodo
2019-05-07Rechnung_268987198496DE_Mai_08_2019.docdoc ba9cfe63d81cf564cb9dec71bce28548d8187549e79d308ef2fc0ae273660afbn/a Heodo
2019-05-075571270706DE_Mai_08_2019.docdoc bf55a3a3036d1f003f56596666d4ee9d217fd276a3a24bf38d1eb2f4d581f149Virustotal results 25.00% Heodo
2019-05-07Dokument_61668577832DE_Mai_08_2019.docdoc b1483f528d6f343065873260bd457abe6436aff1c7cb08d3df1f4a293028fc90Virustotal results 25.81% 
2019-05-07Rechnungs_Details_6923384202DE_Mai_07_2019.docdoc 67828c67eec09559b895632f669dd636dc7cf926dc962a68d13b757eaf1f11bfn/a Heodo
2019-05-07Dokument_99493974102DE_Mai_07_2019.docdoc f0e05fcf22d473ad5eb79a73fc82818bdf3555325d04a54b965953de5bdc8c4bVirustotal results 25.00% Heodo
2019-05-07Rechnungs_Details_124920117101DE_Mai_07_2019.docdoc f412a78d93f03f39f6a58c865c75d6481a3ecfb83a3fdbf1ed32c0c546a773f5Virustotal results 37.70% Heodo
2019-05-07Dokument_603812830532DE_Mai_07_2019.docdoc 60b17d785dbd6e4dbee37c553fa9a5617c7d23bda1841de3659b72d910733d3aVirustotal results 26.67% Heodo
2019-05-07Scan_865434954629DE_Mai_07_2019.docdoc 222ce422ca63999aef3b717a2e9eeb0c9d72599815c4f478597d451aeadfdb68Virustotal results 27.42% Heodo
2019-05-07Rech_93754220396DE_Mai_07_2019.docdoc 51dd24ccbe52ae79f2325057045832374d3c494ecf7c6839778846c72f86653eVirustotal results 25.86% Heodo
2019-05-07Rechnung_988384498159DE_Mai_07_2019.docdoc 0254c18365860c3e9bae3740b5059d8e0fec8425e82aede7b75588cd84c40863Virustotal results 25.00% Heodo
2019-05-07Scan_22817914782DE_Mai_07_2019.docdoc 28e68b85f1bb66d9f63b619a9751c51f270b12f221ed712b879ee9c8c4963140Virustotal results 25.42% Heodo
2019-05-0719770376432DE_Mai_07_2019.docdoc 88dfe6f3e5d83d0b707378a681487cf90a2c51132b6d5a273ee42b02b96134ebVirustotal results 25.00% Heodo
2019-05-07990684403895DE_Mai_07_2019.docdoc dc48ee3072f61d701ee3becc3537339fe28e663ab42fad5d075bb0043993d4cen/a Heodo
2019-05-07Rechnung_09150036132DE_Mai_07_2019.docdoc 946b744200b26a382c2490ac1b26a042bc52f6fc5cf04b082cfa038426ca15daVirustotal results 25.42% Heodo
2019-05-07Rechnung_16050044093DE_Mai_07_2019.docdoc 644eb7976025866cb83fb07f99802dabb9ab0100acb262c43488b5c63a068e9bVirustotal results 26.23% Heodo
2019-05-078687188569DE_Mai_07_2019.docdoc 8f0d1f5f9444e54e4d5e9b991b587b672650a440350b2412dcc9c876df527ba9Virustotal results 27.87% Heodo
2019-05-0770968738262DE_Mai_07_2019.docdoc c4b26c40d3f68ea49a6f012cf5235cd50c84bb1c8edd54da39463137551fd24aVirustotal results 28.07% 
2019-05-07Rech_3469675319DE_Mai_07_2019.docdoc 95c225d91c6742ee6e9de9078232173b4460b7eba84d9028d67a30403bfe4781Virustotal results 28.33% Heodo
2019-05-07Rechnung_9493067029DE_Mai_07_2019.docdoc e87fb6d5b919dfb4afdd5749b378723d06980d41360ce49e4e681b15adf00b7dVirustotal results 26.23% 
2019-05-07018400023711DE_Mai_07_2019.docdoc ea5bc88cfbb5d264ce5618d10691dc17d9363ee80775446c88aa7024bd9bf5d5Virustotal results 36.67% Heodo
2019-05-077098509013DE_Mai_07_2019.docdoc 1ebc995bd0203de608ba84c57f8a98077f5cb558d9a256587641ac370763fec0n/a Heodo
2019-05-07Rechnung_355277572256DE_Mai_07_2019.docdoc db2682ac87baf8bf0fce33057ccbcbda5863c92f93289c220c933f3963ada679n/a Heodo
2019-05-07Rechnung_2951806154DE_Mai_07_2019.docdoc 0fa9d4896df9e87c4eb4b76eb95672d804783705810fd229e114859bb7dcc370n/a 
2019-05-0697844007362DE_Mai_07_2019.docdoc 50913fde5c989b2abda49269d9cc1872ef9f7ce9fe42391b08126415eb5e51b8Virustotal results 32.79% Heodo
2019-05-06Rechnung_27249488223DE_Mai_07_2019.docdoc cb5d61dbb577162397d82eb7353fa47e3e4ccdb4a852405c497b365c45fab88aVirustotal results 30.00% Heodo
2019-05-06Rech_095051286278DE_Mai_07_2019.docdoc 81a459d380755575753cbbf2f67801affa3f89093015df85d01b83dda00e40b0Virustotal results 35.00% Heodo
2019-05-06564063984481DE_Mai_07_2019.docdoc 49502af62972b3d73a981c7ee270e3e82db44d7cbff3bcba0c2032b3d005f3e9Virustotal results 33.90% Heodo
2019-05-06704103848593DE_Mai_07_2019.docdoc f0497dd5ae50bb5773cd4796e1314942072157247d3e6dbbeb6b7d7e6f5fa3dfVirustotal results 29.51% Heodo
2019-05-06Scan_82363904922DE_Mai_06_2019.docdoc 7d01b3eac8a7eef6e57bcd509c6dc5fdd09b9306b07cfe668bf47a060c064e8fVirustotal results 28.33% Heodo
2019-05-06Rechnungs_Details_38272247189DE_Mai_06_2019.docdoc 27fb62ff0cd2cdaa537a04ead101edd04af3283d0378ffa1d5595f11a9718533Virustotal results 28.33% Heodo
2019-05-06Rechnung_1960125013DE_Mai_06_2019.docdoc 14e2c112179900b4a24259af0f459268113ff941cd93d5dde161d0db48e34bb9n/a Heodo
2019-05-06Rechnungs_Details_1983184363DE_Mai_06_2019.docdoc 6e5270340473f53e7d2cfe7c88dd460998e5b2ba3b5088693cfa71f763a5f628Virustotal results 30.00% 
2019-05-0658565089755DE_Mai_06_2019.docdoc 44748067e3a571d6495d3a0503ed18f7a7e0f8671bbf5d20342570ac180f00cbVirustotal results 25.86% 
2019-05-06Scan_55251424195DE_Mai_06_2019.docdoc f2434cbe02eeb7cb5de506e90b4e04f3f33be30f8cdb96248d6b290e2ca13cd7Virustotal results 29.03% 
2019-05-0639856480833DE_Mai_06_2019.docdoc eea95bd823fb174c71e3f70a9d625bd51f0b30fc77d2d76d651eed945c7295e1Virustotal results 29.51% Heodo
2019-05-06Scan_3946644475DE_Mai_06_2019.docdoc 242ed851ce446cd9277cab80cb6a9a30af117cf4eab6fede6aefa47c50d14bdaVirustotal results 27.87% Heodo
2019-05-06Rechnung_45483989512DE_Mai_06_2019.docdoc 5b39e1427931db751cb90e5df73733a0ce85a362f67782cefcfe5c101fb6eda5Virustotal results 30.00% Heodo
2019-05-06Rechnungs_Details_193397294725DE_Mai_06_2019.docdoc e171567cc806ea47d2532e4421626143f68bb455b4886518b1007052428c9e2cVirustotal results 27.42% Heodo
2019-05-06Rech_9146472232DE_Mai_06_2019.docdoc 968e4ec02fb4cf8ad16e44c32c7ee9699b22ad957506093f398301958dd8c04cVirustotal results 27.87% Heodo