URLhaus Database

You are currently viewing the URLhaus database entry for http://rassow.de/wp-includes/paclm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:419766
URL: http://rassow.de/wp-includes/paclm/
URL Status:Offline
Host: rassow.de
Date added:2020-07-27 10:52:07 UTC
Last online:2020-07-27 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-27 10:54:02 UTC to abuse{at}netcup[dot]de)
Takedown time:3 hours, 9 minutes Good (down since 2020-07-27 14:03:08 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-27FILE_AGL_070120_WTI_072720.docdoc 09f7d48ed4d70c24ee8888b1ef67071cbca500ff3fe98267923a5ff68d113b28n/a Heodo
2020-07-27FILE_720427847554009653.docdoc cfb29bce041ca72fbf97be1b608791b9d7e4fd6b632aebf4f91111ce6491cfc1Virustotal results 36.67% Heodo
2020-07-27LAD_070120_WIL_072720.docdoc 2ae81b3cde0a7cc2ff55de0a4184f193e47817812d4f3cddcbeed1b937123958Virustotal results 36.67% Heodo
2020-07-27QLBAAI57L.docdoc af5545ee3c8c0341fdc1dd81f1a09b627b2ea9623702bedad19767e1a0c281a7n/a Heodo
2020-07-27INV_73229100035391678956250.docdoc 1a6d1ba1fd2cc8f3f4b5fa40d134e14a9943a5a7388411e51265991344390afdn/a Heodo
2020-07-27A_PO_07272020EX.docdoc e6d2342bfb704d83b243db57ccdee9c8e91e63f95166a4325170017d66f5d1efVirustotal results 36.07% Heodo
2020-07-27FILE_F3997KHQ2VIT.docdoc 6d0c01bf6407219c53a6c8d1d0e49c2dfb8e564ab8c8e8d43282b537184e2053n/a Heodo
2020-07-2713754114.docdoc 79ca2b44528e5a943259587e1d02d7d31dea8f6f5d2dad3010d89a8e61afebb3n/a Heodo
2020-07-27PO_07272020EX.docdoc 6c963e5f156a1997d05217dd2e95b78b3acc18dd0d021edef023bc2cf3da4f9fn/a Heodo
2020-07-27NE7425854173JC.docdoc 091c7db7d68767950328e64b4574e0ccb394c6362ae3ffba9458abb4d2eb549cVirustotal results 39.34%Heodo
2020-07-27S_VIC_070120_YWK_072720.docdoc 6f897aab655e9d25966fbfbffd2855933c78ea167b2092cd239acf29ac12d51an/aHeodo
2020-07-27QYU_070120_TRZ_072720.docdoc 7da491ebf960db553ac5406c952edb7e3f5edbf1c8a0cbac65e1ec1a7a0ee766n/aHeodo
2020-07-27DOC_2KGB5BH9D.docdoc 8c47f73c13e522ade1cbeb7dc78aa1f0736c8c1b7ddc65e2cc2e27b86d70952dn/a Heodo