URLhaus Database

You are currently viewing the URLhaus database entry for https://cali.de/cgi-bin/balance/p7mkoxy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:272247
URL: https://cali.de/cgi-bin/balance/p7mkoxy/
URL Status:Offline
Host: cali.de
Date added:2019-12-19 01:57:05 UTC
Last online:2019-12-23 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-19 01:58:03 UTC to abuse{at}keyweb[dot]de)
Takedown time:4 days, 5 hours, 2 minutes Bad (down since 2019-12-23 07:01:01 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-21RP_PO_12212019EX.docdoc 2caf05fb34bd7d621953ca25eb813c6ed8bcbda224727f82e072e3417ab2fa65Virustotal results 47.54% 
2019-12-21BAL_BT4K67OBMNQH.docdoc 01634f4d231d70f5cf731cf9b82db1495a3e4231de921159aba75b9ac62a030aVirustotal results 42.62% Heodo
2019-12-20FILE_83838967.docdoc e23bc5ee382cc5f5a5c5a62deca1d119ee4347bfd72aa40765a336f933d1f7f8Virustotal results 37.10% Heodo
2019-12-20VVXQ_PLROIF3BTRDT.docdoc 73e0e1bf7fcb823cfed34dd9fcd5ada1a006f8f0fc06b5e19bd581819cad12d6Virustotal results 32.79% Heodo
2019-12-2027646872.docdoc 79e3cdd3341c2a20f5f88852caecd48fd292124c4b9e649a4c29305142ceb114Virustotal results 28.57% Heodo
2019-12-20PAY_J27PLQ6CUW2W5GH3.docdoc 6d74be1af79dcfd81b6b1aa64e4990733c0264973ca86c0ef0a1730ef2ab1919Virustotal results 30.00% Heodo
2019-12-20ST_PO_12202019EX.docdoc 99e567b65413467cd68e866366bcd22e1245a74078213fb4a5b21e4b1dbaffdeVirustotal results 29.03% Heodo
2019-12-20SW_16716941.docdoc a59c9e9e44e265083559fa39278c124dda988863ee5a7425b078e2e4500b6cffVirustotal results 27.87% Heodo
2019-12-20ST_PO_12202019EX.docdoc c19e4f9564e304e11d679ca37dc75ab35b3feb1f6e63df36add9dc12cc43e6baVirustotal results 27.87% Heodo
2019-12-20ST_QJY_120119_SQG_122019.docdoc 6fcafbb8d2f4e90853451e5aa49f2f79b3be844072b59cca9e9370035b832c90Virustotal results 27.87% Heodo
2019-12-20Y_16429159.docdoc 8f62870ed7ba3a13c0f2552e3789de9221819090622393d8f689e7af17a42ebeVirustotal results 24.59% 
2019-12-20BAL_07875131.docdoc e0cdb9e34c1cb66d32617db2d7a495c3b0c1699a12375090306a3c9c85a33d08Virustotal results 23.33% Heodo
2019-12-20A_1QV14GYRW79BBJ.docdoc e4bba0d01cbf6f796e53cffedf881a3285eff0426d344221ae144ac4cea10679Virustotal results 26.23% Heodo
2019-12-20LV3489277657VH.docdoc 19f2c7093452e7e5230593bed7cbcf8ce570ee2eadd6fa0513349c4f2dd4a175n/a 
2019-12-20PAY_QTI_120119_BJW_122019.docdoc de8ee9d6ff5217db052c005f8e49a89873ee06eeae2acf202c3de1f3d9a33e0eVirustotal results 37.29% Heodo
2019-12-20Q_PO_12202019EX.docdoc d10b8661fdf417f1700879f39275b0f3a37f6f3603935ce813f57b737618652cVirustotal results 35.48% Heodo
2019-12-20INV_JE0633891361VB.docdoc 5e9f296059ada7a1e02754b95ca973f96c959cf8d6080c456f434904bc48e8d2Virustotal results 30.65% Heodo
2019-12-20RP_KPH_120119_FFC_122019.docdoc fecd749716a57e87ee47765a5c72b1a5c50fe8a8695a722aea8fa89537aeb30cVirustotal results 31.15% Heodo
2019-12-19REP_FKZ_120119_JKS_122019.docdoc c888f7b103b54c164d6a5cace0158c0566bb1821087fcfd2bfd34f81f48b58a8Virustotal results 29.51% Heodo
2019-12-19GDR_UCR_120119_SUX_122019.docdoc 8bb88afaa050944f8d8b39aba36fb4591d18ce911023ed6f7de206c3c49f7651Virustotal results 29.03% Heodo
2019-12-19378117949350548659.docdoc 7a2ed8fa46f8f6c6f5ebfad8d9b345a5a4dd4e8f65d8e416f2a88faa6d17d327Virustotal results 30.51% 
2019-12-19XJ6JY4CNM44UN.docdoc 667bc6a7147e3a904a22c3a024fb30cd9b58e73cdae0586e49e061e819c47e7cVirustotal results 31.15% Heodo
2019-12-19SW_02851309796850.docdoc 1667943cac3b754e8669bbd51cc61883aa9646b01311dbbe88c1a9028e5fa7a0n/a Heodo
2019-12-19PO_12192019EX.docdoc 4448cfe08582beb41ec0f8ff6afd2d790f612b603ea24b6e98d97ccf0ca467f8Virustotal results 26.23% 
2019-12-19PAY_DE0738183135AU.docdoc cf1e1c5fdce6dfaeb87c86090e186b06e0165f13e4e47b7136298473f02118bdVirustotal results 25.00% 
2019-12-19BAL_99704598.docdoc cdeba1be6ff661149500bbcb2f45ac5db0c0af310c302a1bbf4439e1aea7bfaaVirustotal results 27.87% Heodo
2019-12-19IF_70854761.docdoc 0daa6de717e589ea8c3126e8d7047ad5304119e733a8ba96202115ae84adf049Virustotal results 24.59% Heodo
2019-12-19DOC_AXXXY8W1.docdoc d72a222b6080f71609f51e12cb182d8aa0b37224caf6281ae9a00474cd312e87Virustotal results 26.23% Heodo
2019-12-19ST_DY7589342905HR.docdoc 829263c831f1b2b0cec4218df826504150f2b0c15acb1a72e09300d5cf23c115Virustotal results 25.81% Heodo
2019-12-19SW_16861351.docdoc da12aa1e56bf92ed4900b9c22cd5bd6aad2086c5521e67cc73875c88433a38f3n/a Heodo
2019-12-19C_74846471.docdoc ea8762cde8721bcd9d366dd2c0cae94ce0ec0f44a624b76335c464d49d368d96Virustotal results 22.58% Heodo
2019-12-19REP_27879272.docdoc 2922cd85282f4ab008fbf22435c81ca09a98f863290f665b23c299718995369an/a 
2019-12-19DOC_PO_12192019EX.docdoc dfde887979e2a371477ada84d0cecb56737421b00cb048f0186ab16146f11fccVirustotal results 22.95% Heodo
2019-12-1968TUMLX45R73Y.docdoc 22461874b83b6287baadcf227b2e495c257af92469d2ac02f98270dbc3fca8e1Virustotal results 21.31% 
2019-12-19FILE_79821121.docdoc dc19d868cbfccec6608b904b7220dd1384fe24e6137be714af752d6c5c86725fn/a Heodo
2019-12-19SEXN_DG0281653686QB.docdoc eece617e68c6bd59cba0abfe3a92b1bd28f333ded755fdeecdf32aa5d9369d44Virustotal results 30.51% Heodo
2019-12-19ST_YS817KT.docdoc 43cf36bece6360c16a5c550fa8a8d5a8bc1520b790e42c2c3b00b5fdb357bbe8n/a Heodo
2019-12-1911966989600598225271093.docdoc 748f1de4fe7b5a64ca5b23ed7a691aac2ddc9a121eb3c82394ea320650063f8aVirustotal results 24.19% Heodo