URLhaus Database

You are currently viewing the URLhaus database entry for http://engt.de/backup/closed_A3600jyJo_KDPUSZlN7E/verified_profile/5FSavLfvBS_52qLr0jjecL2Kw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417954
URL: http://engt.de/backup/closed_A3600jyJo_KDPUSZlN7E/verified_profile/5FSavLfvBS_52qLr0jjecL2Kw/
URL Status:Offline
Host: engt.de
Date added:2020-07-22 18:20:08 UTC
Last online:2020-07-22 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-22 18:22:02 UTC to abuse{at}strato[dot]de)
Takedown time:5 hours, 34 minutes Good (down since 2020-07-22 23:56:35 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22dat_20200723_G59400.docmdoc ed19b2e61ca0fb6c93c302204b449413511404e0494edbfbda0ec195b8dde64dVirustotal results 40.98% 
2020-07-22list-2020_07_23-IKU32933.docdoc 85c9b8464b14bbfbc90c01fe540a9ba134191dd42668aebfb5c09e35b1887dc0Virustotal results 39.34% 
2020-07-22Doc_2020_07_23_ZPD8802.docmdoc 8aa7ea8c9d1c9de29d54f88600c9ffc99c05fafa3017b298e03b7cbc73ddf5e7Virustotal results 40.98% 
2020-07-22FILE-2020_07_23-R950298.rtfdoc abecaece2a01d6e8d9a77368929fb4d818a0b836c5fd5b075a251b7833e72116Virustotal results 39.34% Heodo
2020-07-22MES 20200723 44110.rtfdoc 093cc1977c0adf342635037335e8d76802041ca0b406c065ee63bb3c4b0d30aaVirustotal results 37.70% Heodo
2020-07-22LIST_2020_07_23.docmdoc be720b7a706eae0e4fb267e2ed1709351ae68658728bc8e55a774921eb79a81cVirustotal results 38.71% 
2020-07-22Doc.docmdoc 06ea16c8f47256c5551752bd00c34d5cb30e9b5ea7daa3434e35ca178ca75c2bVirustotal results 37.10% 
2020-07-22INF_20200723_OF1497.docmdoc 7b0a43ed14a889ff1b2f26657bc4453ef52f45ffa85ed059e8109ce860239530Virustotal results 37.70% 
2020-07-22mes 3628452.docdoc 86ef20dcbdc30f082e16816d3281b197b1e34d03d05c1098a867b9d840802cabVirustotal results 35.48% Heodo
2020-07-22MES_2020_07_23_TF212.docmdoc 41386a0cbdfd22f4a7d46f44c00c2e393e548a2c722a7287046bd76f946c386eVirustotal results 34.43% 
2020-07-22Doc QKV58809.docdoc c1e8ca6ab04cda931078956f97ce9472cbac4e8d0718506c2d4f3c618514e7c5Virustotal results 37.70% Heodo
2020-07-22list_0534884.rtfdoc e5b1755803e1fd990e3747b22c5b2e5dd674c403a309b2931ca7b5ae74262d91Virustotal results 37.29% 
2020-07-22file 2020_07_22 6722713.rtfdoc 61ac92f083c25879585954c7ade43b7b17fefbfadc38a09fa9793f769f33f9f4Virustotal results 36.07% Heodo
2020-07-22LIST-2020_07_22-97339.rtfdoc 73d6cf5248a0604eba81bfe1a1f55473820a97df0c5746014dd47e3d10071cb2Virustotal results 35.00% 
2020-07-22File-20200722-2903.rtfdoc 905996c85050d4b5b56ece80b9a231c6e5d46d0ec5e5ed84d7ee33f64011f88dn/aHeodo
2020-07-22Rep_685549.docmdoc 4e5ca71ab308655fe2a2430dfbba2c2f7633fbda4a0e4c44714724f00e27dc51Virustotal results 36.67% 
2020-07-22INF_20200722_7715.docmdoc 0909752f9e8cf877b820f107687a6dc12e42ab76f995635a56116d94fa3cc86aVirustotal results 36.07%Heodo
2020-07-22DAT_2020_07_22.docmdoc ef64e139ac5120bcb2be7ca49559d2e39d9a00d5007ba03f7745618a805d08cbVirustotal results 40.00% 
2020-07-22LIST 2020_07_22 T4192.docdoc d516375ff9a645547e27b1359395936c1ba1c5725795a78864b281f8a8b426d3Virustotal results 36.07%Heodo
2020-07-22Dat-3309199.docdoc 9386f4a822f6bb11eb7588717ea43c765b9501a32ca42607846f8f577ea7a8eeVirustotal results 36.07%Heodo
2020-07-22rep_20200722_9278.rtfdoc 8377d8c4302ad8a31a44fa320938d524ba143b4b076ad91fda4c5c1b73aa804bVirustotal results 36.67%