URLhaus Database

You are currently viewing the URLhaus database entry for http://www.reiwo-service.de/cgi-bin/O/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2125401
URL: http://www.reiwo-service.de/cgi-bin/O/
URL Status:Offline
Host: www.reiwo-service.de
Date added:2022-03-31 19:47:06 UTC
Last online:2024-04-22 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-31 19:48:05 UTC to abuse{at}1blu[dot]de)
Takedown time:2 years, 1 months, 2 days, 18 hours, 38 minutes Bad (down since 2024-04-22 14:26:44 UTC)
Tags:doc emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01RN-9630691.xlsmxlsm 5d31e83b1dda43ba478dbf1bbd5b1ab90021810860493110ac6175f69e58a93dVirustotal results 43.55% Heodo
2022-04-01NHZ-51631957689220.xlsmxlsm d3052eaa2931548083181b1e4724bff791218f947c3f7640f9efeabeed21244cVirustotal results 36.51% Heodo
2022-04-01RU-540423597727387.xlsmxlsm 23dcae1214f777e47304040a77a621c58e9e163d1b27400c5197b75fe00a8d60n/a Heodo
2022-04-01IEY-64971039.xlsmxlsm 5e318e7afaeff1da0ab8f38c466b9fb4e911da7fae7a6eb58cfbab3175d51263Virustotal results 41.27% Heodo
2022-04-01QI-34559349.xlsmxlsm 2cd047043da3c815bb5554f75749f89f6b7f44bf302c395f9685e485e7cf3d77n/a Heodo
2022-04-01RKA-08585071.xlsmxlsm b023e386d641f492de9b4d5bed3205b36c169d9ffe17c13f60c1175cf972fadfVirustotal results 50.00% Heodo
2022-04-01SPH-0406417154337.xlsmxlsm 9a7149b9a22892acb53760e7dafbc7b73904606ab766a03d7eb08ac224f7472fn/a Heodo
2022-04-01XG-641930389.xlsmxlsm fb304773b9bf33fc45eb1fb816a5bc5ce0e481528f81868e4fc5a81608fbad6dVirustotal results 38.33% Heodo
2022-04-01ZP-38606151386.xlsmxlsm 95a5818025092c8bd5c223d791220072df4eee4b7391f34e0868b32e3ce355a3Virustotal results 46.77% Heodo
2022-04-01EG-9657807515.xlsmxlsm 12defc6352bb846667f7048ac22b5ba0a7bededbfdc06aba79c5629671d59f33Virustotal results 44.44% Heodo
2022-04-01EH-87592385574664.xlsmxlsm 8ce2a97a8318d629daf6b48ca033dceb8988c32bf5023f8938f354bdfeb5e25bVirustotal results 44.26% Heodo
2022-04-01UOA-4052695.xlsmxlsm f4e10c5743205f55ce4eca43f3741f71ecfdca9391ae883123c3372d5daae4b1Virustotal results 41.94%Heodo
2022-04-01ZL-9885394.xlsmxlsm f8f5316e59f479286d96010874074660c5afe3ddbbf1bb382c468904b9667595n/a Heodo
2022-04-01KSD-822388600.xlsmxlsm f43408a5254cbcdcebadf6d4f5f4e2e7202cd88b8a6bb1ff62f5caf1bea5a0e7n/a Heodo
2022-04-01WDQ-312094025122.xlsmxlsm 2b24ae43b66b722398ecdce2eda45ce724f63487f3059dffa976479d26a9f3b7n/a Heodo
2022-04-01SA-580837058764.xlsmxlsm 97fc1c969103278fd6fddd2f117d3b418d3f7925a9971bafa8bafd8b2d3df632n/a Heodo
2022-04-01WWC-51271334673845.xlsmxlsm fdaef695835e1a9e056fe2496ef611e4250388f7712102116b6717894e578f50n/a Heodo
2022-04-01OL-898844738986020.xlsmxlsm 2c4b41fdeef820de3df320cf56f01c1fd68bc513eab0a09ce944de90245da0ebn/a Heodo
2022-04-01UB-03933915907.xlsmxlsm f3c06e72e6b0cddb3d66545d59bef1288458f9c106ede60b0507f095971e7067n/a Heodo
2022-04-01DBP-768164169391460.xlsmxlsm 7347e4cf31a837aec00dd4d093a63e3f2b67a89b6af8965707c47717e8075482n/a Heodo
2022-04-01ECL-94682308.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 43.55% Heodo
2022-04-01NM-045924938.xlsmxlsm dbf83f486a7c984113454c8adbaf67592ca234b8918c265d2f37e174aa0bc1ean/a Heodo
2022-04-01MYV-670408320018.xlsmxlsm 4c7b060bb7b1693ef3943692ce9c62204426393f9af92ca39c4c57e09b03cc25n/a c8fc17ff030feb3383d8889f69abbb
2022-04-01UEY-99338281323128.xlsmxlsm 73dc0a16c8430b50b28054c9e0b1e54cc8174554e7b63b4e2fa4be17c3cac1d6n/a Heodo
2022-04-01GO-65474396248728.xlsmxlsm 3390185d81ea6becb7bb5c59f26400a3c75b99da77bd95eb76e9417ca984b4dfn/a Heodo
2022-04-01AMD-692535565.xlsmxlsm 23c128385a0702939e1b4bd33875e38dc27cec42b5561f54859abaa962d2930dn/a Heodo
2022-03-31XK-41809075.xlsmxlsm 5131287d80e747b0ac91053a0490859150d9f84995214a9136ed22466de08835Virustotal results 38.10% Heodo
2022-03-31IUT-454877496.xlsmxlsm 5fb54e96fe17c395fa69dc06933558b083ae9cfb1391218f12c539c2645a8311n/a Heodo
2022-03-31OQ-9152597.xlsmxlsm 8090d0b6d046091604553a331f669273c32d27943faae06a33b6ffda57479dafn/aHeodo
2022-03-31RUI-1780678828.xlsmxlsm 1bdada6954ab20722dfb51b2ace2e6fcdfb556210c74bb059752552f5fa8f78fn/a Heodo
2022-03-31OI-131126799.xlsmxlsm 886b5540d8a7234ca4d384341ef859f08d555dcf16aeb021075140bb81459b9aVirustotal results 36.51% Heodo
2022-03-31FPS-397439745.xlsmxlsm c10cd4c9b699a22be539e47e16dbb91c80084b3afa570a9eb66c2206c3096b9aVirustotal results 40.00% Heodo