URLhaus Database

You are currently viewing the URLhaus database entry for https://drs-spotter.de/cgi-bin/mjMAH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417981
URL: https://drs-spotter.de/cgi-bin/mjMAH/
URL Status:Offline
Host: drs-spotter.de
Date added:2020-07-22 19:26:03 UTC
Last online:2020-09-07 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-22 19:28:04 UTC to abuse{at}strato[dot]de)
Takedown time:1 month, 16 days, 13 hours, 53 minutes Bad (down since 2020-09-07 09:21:31 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-23Inv B26_326424256.docdoc 548e4293f740ef77ecf074a7e8eb5ee8659eb565fd08db697ca873dc770c11b0Virustotal results 46.67%Heodo
2020-07-23Invoice-BN3743_4896200.docdoc cf2ba9c49c359ebc0d9ce182b928db8e967b6720c8d531c8366b2420ce778d21Virustotal results 42.62% 
2020-07-23Inv_IW68_352414688.docdoc 49e8d0e91070520182b76f279d10dea2f17e87c7f69e61352db25d5acfcc0be7Virustotal results 43.33%Heodo
2020-07-23Invoice_NFY073_880395532.docdoc fd1b363068e21fa7a3e86cc0aa6134bfa46a640d70bcef686f19f57f54340f6bVirustotal results 44.26%Heodo
2020-07-23invoice XDK175_614258.docdoc a6c57882ad508e14909fc77b2bcef15fbbbc5cb49e4c8733f2bc810e99a7072eVirustotal results 42.62% 
2020-07-23Inv_6778_82727937.docdoc 063f625ee5274a7caa1637adec2235e98aeaab2f5f8b14877835b82136892654n/a 
2020-07-23Inv_6778_82727937.docdoc 063f625ee5274a7caa1637adec2235e98aeaab2f5f8b14877835b82136892654n/a 
2020-07-23INVOICE B0_5677934.docdoc 823bc611785f0ac57c609d89af04775d2555e96de7529cb5c367e4690c08f6eeVirustotal results 41.67% 
2020-07-23Invoice-TUC7_1760198.docdoc e2796110338cf892ecb47cb8baeafa186dabd1403514af5d5a470c2561c59d11Virustotal results 44.07% Heodo
2020-07-23Inv WAM25_493369.docdoc affd22130c658e33e153da21dacd828359afe4c1bee7d621def53e3c7fb5a712Virustotal results 42.37% Heodo
2020-07-23invoice FQJU9273_601747486.docdoc 88cca8fc8a65b95ca50edf7f8f1bc19f7c7d91935a589e7a4a88b42ea443b603Virustotal results 40.32% 
2020-07-23Inv-YGS1_519997.docdoc 3509f671940107c4ce10122e95808937ef8a81e9452812ee660cdd2df62af3b2Virustotal results 40.98% 
2020-07-23Inv_YPW0893_970100752.docdoc c8bc8587d3706f659ce2dbd1c22be268adad0f5f8c4c7be78ff6b4b17c3f1279Virustotal results 45.00% Heodo
2020-07-23INVOICE_ERP7736_826839117.docdoc e96a19dec04fc49f1360224fea7d16ee6c04d29b296500a3b7edc87d31a925fbVirustotal results 41.67% Heodo
2020-07-23Invoice-LM6056_3368742.docdoc 8699c115f17ea8f5ff05ba03ec55c657a076e5dff4f23802b87fb9d012f179d8Virustotal results 41.38% Heodo
2020-07-23invoice_SDWK5_3794056.docdoc 5ecb66cb399d319d7c2e24a9ae1e427ee2b10ccd3da9b2a2266dd764ba29cd16Virustotal results 41.67% Heodo
2020-07-23invoice VLK283_48359749.docdoc fc138a4add108557757b357a4de2c8c2b60832c018e4ebabf099a4f63121dff6Virustotal results 40.98% Heodo
2020-07-23Invoice OQ64_575278792.docdoc fcdbd1df2994aa81348459cba048cb91f2d0c779911d4abd1ac45bd540eae640Virustotal results 40.98% 
2020-07-23INVOICE DONA7133_9108073.docdoc f815f1d2c10f89e966e1637e1d1478a36c5c8c8ceb852eefaa2247c44f10b9fdVirustotal results 41.67%Heodo
2020-07-23Inv-736_03629896.docdoc cd39e541197218472f3e09dd2b1ba14076247e64e439a47cdc2824aae02f6f66Virustotal results 40.98% 
2020-07-23Invoice 897_2444349.docdoc d0386cd66debdb22584ec18ea9ea4d42d8d7ead5e0da33351cdaa7c4a8b2aa2dVirustotal results 40.98% Heodo
2020-07-23invoice-M7749_7614220.docdoc ec08cea8c07370a30ceaf1877b95d6a4e45728f9f915dfe0e5572c632fdf3331Virustotal results 39.34% Heodo
2020-07-23invoice FLXW54_6314996.docdoc 3ca7f44149bb7302e4e24ee98c1720865e34416a3cc52d005b3a52fa51ff415bVirustotal results 39.34% 
2020-07-23invoice_DJJ6864_759082.docdoc 201e851d0a87ce253787d17e5263362eda13f891604567b19154f6edb7a18c00Virustotal results 40.00% 
2020-07-23Invoice-ZZQR1_72436384.docdoc 908cb95829b5e7219efcf041c922c2633fe8c1bd3b38a4ea6536d80dddef9a54n/a 
2020-07-23Invoice-U6251_234248.docdoc c0689da51a6ac61c10510453b058273111d2eb315cf24c9233f055548e838d7fVirustotal results 40.32% Heodo
2020-07-23Invoice-JCC9386_7102365.docdoc 5da4ed7ce6e6938d87f5b5d3add5191ebefb861c31ad2d43146c8cba80302610Virustotal results 40.68% 
2020-07-23Invoice-TYZ2_6264014.docdoc f752b3c15c7f8300d70d3d0e9680892e4dc0c6ccc7b5cc1eff59e8568a4288baVirustotal results 41.67% 
2020-07-23Invoice-KNZ805_683791.docdoc 9ca51f73dcdb08b4450ae42c0c1a49859ec30c989c6c32c7cf70cfdac515e687Virustotal results 41.38% 
2020-07-23Inv-Z215_396535238.docdoc 83d89d7daf246921a8dde2e54e9e1ea505707f24f069a02034e2fe628c586239n/a 
2020-07-23Inv_FV2_13704788.docdoc a7eba5ce690c5078cfc8875f5a8a07cdf7b8fe15a427b22b2620462b04c4558cVirustotal results 40.98% Heodo
2020-07-23INVOICE AGU12_76427539.docdoc 1d786d897347069b1e0ba3ad92c8fff6d7258a2599cfc50445250478e2c1e65aVirustotal results 41.67% 
2020-07-23Inv-5549_925981189.docdoc 6e8bff5d060f35a5e75bd5b6772e3d5d52f71ec00665d6384beb8f30c8d80a07Virustotal results 40.98% Heodo
2020-07-23Invoice_9_8517839.docdoc 660c977559837c11b18b4131f3459734a2e160602bbed412b7892829fe0c0fb9Virustotal results 40.00% Heodo
2020-07-23Inv 45_0891055.docdoc f9ec4de185e104c1bc417152e6146da999dada960c014f2b7b9eeefda33ab5b6Virustotal results 42.37% Heodo
2020-07-22INVOICE U7_98867847.docdoc 7e10a0e92fcdcd90d995ee6b0b0059e7a879145f512a34f8f80deb336c83fbcdVirustotal results 39.66% 
2020-07-22INVOICE-28_2600543.docdoc f7e57a114b25d746fd0b4c14c656eae2c02238130d90124939885bb0b36f3674Virustotal results 40.32% Heodo
2020-07-22Invoice_LTDL440_99057165.docdoc 2dd5a90bf7f556f0c8a9a024f6ac592b4c6654f59b7d663c5b313e77757702efVirustotal results 39.34% Heodo
2020-07-22Inv_B94_9387491.docdoc 121ed8988b04cd935a814c1721a9f0d568268c9771e9a54104e9d603bfb63735Virustotal results 40.98% 
2020-07-22Inv-R847_34534008.docdoc 90b2a224e113c22ea44a6ff37ed4441133bc38638d2c622f8273fc275d8a5170Virustotal results 40.00% Heodo
2020-07-22Invoice_CMKN265_1862118.docdoc f18cd894f96fe1947a742b359fcc7bea8f2d2c34bc1080cadf3fcff2d2564946Virustotal results 37.70% Heodo
2020-07-22INVOICE_IMKK853_91288604.docdoc bfd7374a797a6c3e77d704c3ec20c246e532ab967cb7cec9f3f77f386bdd7455Virustotal results 38.71% 
2020-07-22invoice_8113_08676614.docdoc 9906a5bee4b9e562812454fe546581f17dcea82db95ce7b846c50d1537cb8316Virustotal results 37.70%Heodo
2020-07-22INVOICE_SH46_0473697.docdoc a8377439065663a204f302e8b1ae0aa1d880b86780a7a8ddf0c2569a8a78ef0eVirustotal results 37.70% 
2020-07-22Invoice-4575_95138111.docdoc abb692721c19ff5f382ccfc5bd6ce5301433d4ff75f8745e73d8fa929b4ab1aeVirustotal results 40.98% 
2020-07-22invoice_40_838508.docdoc 81974e12641a56b689a90de529d306a53cc4570ae79cf6c7e34b4aa15345babdVirustotal results 38.33% Heodo
2020-07-22Invoice_WSIE5553_9841201.docdoc 7757df52299b5b7d7d83f3b72cf1fc8415dd72f90ef93160a30e5270d9528d0cVirustotal results 38.33% 
2020-07-22Invoice-58_8476338.docdoc a09aab2acea55dc5a41e050de922953dedd0f8177ddf8c60a56af74d25daf577Virustotal results 40.32% Heodo
2020-07-22INVOICE_5030_556433920.docdoc 16c6a9dd4a72829040a232b03b8dec183f1b62ba3a8fa829760e83ce534755aaVirustotal results 39.34%Heodo
2020-07-22INVOICE-97_609343.docdoc 73ca49f367f9ccc5d7afeb6979409e1e116a8ff24d143b7cda1482204e8a12c2Virustotal results 41.67% Heodo
2020-07-22INVOICE-L38_67397806.docdoc d8604cc57ed2635d1426b6baf81d79cd5b5a14e28bdb492c2349fe6652d74acbVirustotal results 39.34%Heodo