URLhaus Database

You are currently viewing the URLhaus database entry for http://esser-promotion.de/kuenstler/9JzQquBzAa2erx204JB5aPXVpa0qO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2119508
URL: http://esser-promotion.de/kuenstler/9JzQquBzAa2erx204JB5aPXVpa0qO/
URL Status:Offline
Host: esser-promotion.de
Date added:2022-03-29 15:50:05 UTC
Last online:2022-04-04 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 15:51:07 UTC to abuse{at}hosteurope[dot]de)
Takedown time:5 days, 20 hours, 17 minutes Bad (down since 2022-04-04 12:08:09 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31ZGV-939324594684251.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31UMX-63218520724.xlsmxlsm aae715bd593347d4b94a81d9367b35a192014b0d17aa40e05652b3d84e5aedcbn/a Heodo
2022-03-31VZW-2470083.xlsmxlsm b034cfc88c6603dc0f5519ecba2dbba8c5382b26b8c25da23f8d40368ce8e7b5Virustotal results 33.87% Heodo
2022-03-31LWR-2469845254.xlsmxlsm 63ba5c63fa8f569c1870ab57faeeec2933a7bdb28c90458f6c5373f1a71dcef4Virustotal results 36.51% Heodo
2022-03-31OGA-4771061808436.xlsmxlsm 409e55effd488af9a3d098060e33fe5d66743135fc711a07d6ce4c57e2f2c2bbn/a Heodo
2022-03-31DOH-59930169778.xlsmxlsm 5285de9e0e5323564d48a5d9fc627190ed9bae90f9c0e818958768b0d7c856b1Virustotal results 36.51% Heodo
2022-03-31YK-051726170024703.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590Virustotal results 36.51% Heodo
2022-03-31PR-533827564222.xlsmxlsm f869263419a75a1350a78400b9e3dd186488c7c76d299e7984af7e5e0c91d75dn/a Heodo
2022-03-31KJ-55297599364409.xlsmxlsm a4e22b806505d549a037a67123efb6b397193d7d2ff28e32d8b73185438fb5acn/a Heodo
2022-03-31MME-26875378.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-30SEP-6409224.xlsmxlsm 41f790fa1e0f18e897bdad1de2c9452310c964ab0c50e831d9c1150af849edf4Virustotal results 40.98% Heodo
2022-03-30DQV-4807283603.xlsmxlsm 39bbb570609ea300f9d959dcf23f2161043c6dedc230f97e7eab2388db651831Virustotal results 37.10% Heodo
2022-03-30DY-53763532717.xlsmxlsm 93629f0e94046fc0c1c1a2779a8e58d101136842695fc4ad3addbde6c7757dcdn/a Heodo
2022-03-30HRT-060794391576.xlsxls f3101b6d16751623f8a025bfbf75ae9a32c68b534dccbab4452ee72a9fbe0f5fVirustotal results 28.33%SilentBuilder
2022-03-30AGC-205951010506.xlsxls d743d15057637cf8074f2c125e85dec324808dae8860051c978dcda48f641d86Virustotal results 28.81% Heodo
2022-03-29n/ahtml 0650441e8ecb9b861fbcefb6dd23288684c418065c240fd9e9be1dde4ff41797n/a