URLhaus Database

You are currently viewing the URLhaus database entry for http://diskobil.dk/gearet/Scan/v11mr92a14q08u_p5kx0-081584184/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:192555
URL: http://diskobil.dk/gearet/Scan/v11mr92a14q08u_p5kx0-081584184/
URL Status:Offline
Host: diskobil.dk
Date added:2019-05-07 21:08:08 UTC
Last online:2019-05-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-07 21:10:05 UTC to abuse{at}zitcom[dot]dk)
Takedown time:9 hours, 56 minutes Good (down since 2019-05-08 07:07:04 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-08LLC_16719437956US_May_08_2019.docdoc d7fc74cd2d6f34bcc7e02522812778a91bbc6591f4805164208847add84ecf2eVirustotal results 33.33% Heodo
2019-05-08SCAN_1772744234US_May_08_2019.docdoc ca3df80f2b645b8d3eca905f0640d605b9d70f79ae9424e883fa73c50ec1fe88Virustotal results 33.87% Heodo
2019-05-08INC_3032682960US_May_08_2019.docdoc afc7e59c3f7eb40403410c8ea91e4483a08c01fe3dbb9e5ec2d792db05d71615Virustotal results 31.67% 
2019-05-08LLC_4005059756US_May_08_2019.docdoc 942c15d908cca46bf861a0f12afaa5564f358631ac5438f46dd8aec5320ec8caVirustotal results 25.81% Heodo
2019-05-08DOC_300022130227US_May_08_2019.docdoc 28cd75af6569612c8dc642936de3a2680f75d49e1d38be1a3a782fcf11dedb31Virustotal results 26.67% Heodo
2019-05-08SCAN_932121302448US_May_08_2019.docdoc 71b6be26315c131c1fe9fea2b209427cc31e69b472690d38b8f32e8c8a3132a9n/a Heodo
2019-05-08SCAN_300915231929US_May_08_2019.docdoc ca79cb63740912029a80925b94cdfeb13c9ffa62743e6371de9f7ff5c49afbfeVirustotal results 29.51% Heodo
2019-05-07LLC_08327245023US_May_08_2019.docdoc 36b7c488433df34c87e4908670f6e9672e213accaca3edd81fbf66221628ea15Virustotal results 28.07% Heodo
2019-05-07Document_2445025048US_May_08_2019.docdoc e0cca29fbe79912a60ba57c8776d7f84e85495fa54a0e5244c0917df09b6b359Virustotal results 24.14% 
2019-05-07LLC_24962827124US_May_08_2019.docdoc 497fe0c5adffb28afd5d1add4b8fff359cd9a43fcb88aaa1f0e3ff9c30e268b8Virustotal results 26.67% Heodo
2019-05-07Document_91728702385US_May_08_2019.docdoc 3ca3b11abd89194bed84645f9427a71ca200fb70aef0af93eb6e20511228f36fVirustotal results 26.67% Heodo
2019-05-07DOC_7148428298US_May_08_2019.docdoc b1483f528d6f343065873260bd457abe6436aff1c7cb08d3df1f4a293028fc90Virustotal results 25.81%