URLhaus Database

You are currently viewing the URLhaus database entry for https://meinhaarzauber.de/cgi-bin/h4rms-5pr-166131/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:420397
URL: https://meinhaarzauber.de/cgi-bin/h4rms-5pr-166131/
URL Status:Offline
Host: meinhaarzauber.de
Date added:2020-07-28 06:19:03 UTC
Last online:2020-08-13 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-28 06:20:03 UTC to abuse{at}strato[dot]de)
Takedown time:15 days, 23 hours, 52 minutes Bad (down since 2020-08-13 06:12:13 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30InvTHYQ5094-470366.docdoc 84f1793acc6d7c229aed03c0334fcb223eb89415c1d96b08822e988c1a5652afVirustotal results 45.90%Heodo
2020-07-30InvJ7520-795767400.docdoc c99f367eba08850d6a62e56f9957b44656cba498c67bd78b284d5fafa7bff959Virustotal results 45.16% Heodo
2020-07-30Inv NOX2647_97821457.docdoc bdc1e8081137db7607848b3b7d546b6cf36935eef3c38a07a97116868093afd3Virustotal results 45.90% Heodo
2020-07-30Inv-HWX8884-6412481.docdoc 1bb56e849596fd788a8c9905d08684f8043a4cc4e72209d9978d78aa4f9f6f22Virustotal results 46.67%Heodo
2020-07-30INVOICE-ER3{:REGEX:.docdoc a99c7d681efd2f154e47e585cda75103f5e9abbffee3f7e86dc9da37260624ddVirustotal results 46.67%Heodo
2020-07-30invoiceXHZM2-43408867.docdoc 7579d4a1d6d4da73019950ba9cd7de417560465889ccbc12fffbebff6b87ca3cVirustotal results 45.16% Heodo
2020-07-30INVOICE 99-69598625.docdoc 201be4f7a7d31a69ca92f73a75c5a4df9eedda88e619a35fc83f3b9d318a4703Virustotal results 47.46% Heodo
2020-07-30Inv_JCVH9854-9879994.docdoc 88a8cc5f762749790bd0cf686c79950ba34466fad7753f87b86a7c94a4ea6e8cVirustotal results 45.76% Heodo
2020-07-30invoice_VTL1194-77231310.docdoc 1a36bd245a9053a5742fb8aca3169f91382921c429bc62eaef3471cb4bfc743eVirustotal results 46.67% Heodo
2020-07-30INVOICE S6{:REGEX:.docdoc 907516b73bbcea22b548ab281f487773521e2af661bbe7615b82466ceb99e403Virustotal results 47.46% Heodo
2020-07-30Invoice H259-8767059.docdoc 6aaf1d2548a2d3e3af5573be71f022d7b0f795816398a54e9bd79a341453530cVirustotal results 45.90% Heodo
2020-07-30INVOICEXJRG0097 315150471.docdoc 434275c04e5ac65d4e763e14aa5291f8e9e7b344fb8e4768dcdfbdeea9af06b5Virustotal results 45.90%Heodo
2020-07-30Inv-774 731571.docdoc 4ff286a06a66c0c8d7c44bbb7c1be4363222a33701847a86402bce22e085889dn/a Heodo
2020-07-30invoice_FG0406{:REGEX:.docdoc d5a5e07b856fa95bb954729db5a02b3415dd89b0be6048cc7d0e3f0a8afd89f7Virustotal results 46.67% Heodo
2020-07-30Invoice 33-7344454.docdoc df9e30e0ae0d6fef25c5e4d2e36f450e5eadfbe74228b3dec9a056e0788e02dfVirustotal results 45.90% Heodo
2020-07-30Inv Q113-48531818.docdoc b56bf0f5aef789b7a05528c971f8f709495c67e7b3025fb13dba152446d9c197Virustotal results 46.67% Heodo
2020-07-30Invoice-K1876_768816.docdoc 0daff577173686557b6c179acf668ffbbc64cfecd2545ded9102108e81b557e3Virustotal results 44.26% Heodo
2020-07-30Inv_WDB561{:REGEX:.docdoc cf7363d569abe51412e602a505dbb2d3604aaf97ee7c71db42e66b09224dce54Virustotal results 44.26%Heodo
2020-07-30invoice_BUZ02 987533.docdoc 9073425e395c1b7a8d42cabd461cad86cd0646bd77f042e13bcd2f98979fe12dVirustotal results 43.55% Heodo
2020-07-30Inv T364-77010197.docdoc 72244c8748d1f0b37e10ef8b0f5be0624ea7ac975aa1214281b4f326e6b2f4b2Virustotal results 45.00% Heodo
2020-07-30Inv-IET972-40190572.docdoc 9682cb3fed20b168899452201908168de9b2c2d82530d7227a4474b8b2587eb8Virustotal results 43.55%Heodo
2020-07-29invoice J33_684182653.docdoc 51077cb5f430fd81fc483c397d7619718e338949394dabaa9ca2f95283c1e1ban/a Heodo
2020-07-29InvRCV00{:REGEX:.docdoc bab5c1d78dc95301e33f2feeb7364a84411aed85ded73a18e6c108ee554ffda8Virustotal results 44.26% Heodo
2020-07-29Inv-SMPV2-53720264.docdoc b6eb1c7760e06c0bf914bc6f8d26d4aa98a1d859d71fed9d6712db95af81f5f0Virustotal results 44.26% Heodo
2020-07-29invoice 6-04636266.docdoc 0154bb8b4ba5c8ae6953ccef01b7c2520377c676c34d08564a7fb556b5dd5dc3Virustotal results 38.71% Heodo
2020-07-29invoice_5 961733.docdoc 4e5402409bed2c6052e6cfb0cd998f3b88be85d561edff6ee16212a4df9d844aVirustotal results 34.92% Heodo
2020-07-29INVOICEQD96 489920.docdoc 0538723c17579616d35fe643f326b6b5b81319f1e5081079bef5cfc6cc2eefc3Virustotal results 36.07% Heodo
2020-07-29Inv-DBU925 282227975.docdoc 9a2096146b8ace7eb4e64e5a25cf48da7bfe891b37e48e83edd349cce12d5628Virustotal results 37.29% Heodo
2020-07-29invoice-U3_68653790.docdoc 0644fc32d19fccfcc17f4c76d1f463049498e6005f7228f63aa9b88a1d17c95eVirustotal results 36.07% Heodo
2020-07-29Invoice-AYAS7{:REGEX:.docdoc af9d5de07f7e571202c737e34a1b5a962949f65253c1ac006aa5670b11c653d5Virustotal results 36.67% Heodo
2020-07-29Inv_YZC30-131162313.docdoc c9908873e05408d13895e8545fd5b9e3eb95032f5e363086b19e6a14a8ed7075Virustotal results 35.48% Heodo
2020-07-29invoice-DP7777{:REGEX:.docdoc eedf761aed061fa63744aa541d5ddef3b7d53978fd00882cbf9fb0f88bd82550Virustotal results 36.07% Heodo
2020-07-29Inv-PJ619-451976.docdoc 090a984722426633b73001523378c0fab17c231b0f9702306e9caf01c98f3655Virustotal results 36.07% Heodo
2020-07-29InvoiceT6{:REGEX:.docdoc 8e127a93bc03c8172db9914d942e9d256f3c926b1c4563be6ebff452f82d2c3bVirustotal results 36.67% Heodo
2020-07-29invoice960_860292687.docdoc cf3685fed8afc244c9057d567ba9c44bf565b3fdc38d6b9cc483bef951667accVirustotal results 35.48% Heodo
2020-07-29Invoice_IZQE2054-04820923.docdoc 1b0122c96de8f870e55e55bca4672466ac7364708a15487e05dc22aa712697efVirustotal results 35.48%Heodo
2020-07-29invoice-W6-859339487.docdoc 1506ac2044400ad8ef962e4a6869f6691adf13c46c27733f26bd8eede6136244Virustotal results 36.67% Heodo
2020-07-29Inv-PH1463-611297051.docdoc 1b23e6893b349fd94640f1425a5ffebe9b61b4d3e21ad8f8ab5117384f0ffc0dVirustotal results 36.07% Heodo
2020-07-29Invoice026{:REGEX:.docdoc 0028341f11b512a3b80bb54598e61666379dffaaab8a08ddc7d9a92fd029233bn/aHeodo
2020-07-29INVOICE AAK0238-5019855.docdoc 2f455cc6268ecdade0ca6fffc1663cc0afd5ba64feef4dcad85b6d26f5a6de40Virustotal results 33.90% Heodo
2020-07-29Invoice-X104-0244667.docdoc 5e4915b311bd06915e5e10b171fa82cd29d5e308771a468a0d28bfc9c9731540Virustotal results 34.43% Heodo
2020-07-29invoice-IDRL1-48398736.docdoc 6ecb72b433b635a49ee2f82737cec4103d08d18e988b42d36bd1b35d175ef612Virustotal results 33.87%Heodo
2020-07-29Inv LC277_7031269.docdoc 4c4eb4ee78767e5ef21bbc3ff9fd20cbc8824981980172c54aa2b5bef9c05f0en/aHeodo
2020-07-29InvJS7756-59884676.docdoc 9e6e228740b8491e06fa21ebc02825a274d28765e6d5f03532d04723f27ea3c7Virustotal results 34.43% Heodo
2020-07-29INVOICE-T61{:REGEX:.docdoc cfc4f08eac512749e059176dd3bd0dcaab3bbabbed46c9a54aec74e7b4d1c28cVirustotal results 34.43%Heodo
2020-07-29invoice-VRI5541_231994848.docdoc 98f17256c293c9d59235854b445eefe7587415563922d028dad64b7ea2732964n/a Heodo
2020-07-29INVOICE_JRK3471-937318574.docdoc e9c41a03b0a30df94da213516e68cb7f81634c2d04fde2f5fd4f4b72d0e58b79Virustotal results 34.43% Heodo
2020-07-29invoice_CRJ5612 088683.docdoc ecd6f0ecbe8a5736cbbd0ad4095e8d9197f31f8278a839928a6b1ff342310541Virustotal results 36.21% Heodo
2020-07-29invoice-KYQX1868-6803693.docdoc 9f7b28a08045dbd6d625a5950b7bc9f7e84b95abdf7554296560433cb2055bc3n/a Heodo
2020-07-29INVOICE GZBC7{:REGEX:.docdoc 17a4069c85045814878237711fcbc6f1a31c634acb4a0910251237f38d1fcde6Virustotal results 30.00% Heodo
2020-07-29Invoice-UFP6640-7734223.docdoc 9b170d1513d2e3329d1d0175a661e0b646b9d374bb6cb73b7b32103438a80430Virustotal results 30.00% Heodo
2020-07-29InvPJU04-7166671.docdoc 5dc2988ac1400b5b41834fdd756973d29c974e2beb985cbff7b83833d0175243Virustotal results 28.33% Heodo
2020-07-29Invoice-1_8850636.docdoc 48ff47bbbcb8b53f6fefa1fa1ca276d9cd1a82956cb00511b6718bdc6818d503Virustotal results 27.42% Heodo
2020-07-29invoiceCBWT68-425610002.docdoc b55637e397616929dd5aa9a5dce20753de9ecf2de51cd00672d022fe335ee5c6Virustotal results 27.87% Heodo
2020-07-29INVOICE-OLJ43-38090943.docdoc faf515ab474069ff648bbe291975efe9b7be1e0354b0e61b6c4fc9e91d0880fdVirustotal results 28.81% Heodo
2020-07-29Invoice_A2356-9346425.docdoc 048fa686a033e894b6ab66472e3add1b8e1d6bbcf6b2f3abe4be995f54c3e61eVirustotal results 27.87% Heodo
2020-07-29invoice-5048-3954245.docdoc 480b1b9545e5697bfb108b5b9a7a193a94820d63df524ad4b0105dfbc6d438b8Virustotal results 27.87% Heodo
2020-07-29InvoiceBT82_062815388.docdoc 009859076a22db75a808e34d09e312e434a8be46bf83d418872c73b187711da5n/a Heodo
2020-07-29INVOICE NIL736_607484362.docdoc 99903e427c59e157ff1cb881dc4e59aab7c564426e9bb93e130779cf4d43c0fcVirustotal results 27.87% Heodo
2020-07-29INVOICE-Y7{:REGEX:.docdoc 4136355b5354cc7a91489e062ef45ae19eb9045b552097772e4a382ff8e74aban/a Heodo
2020-07-29Invoice-G5104 5361971.docdoc 5e2bc2a29319e2606d949889c887bd1a896fc47dad72379cd36d28130d43e1b5Virustotal results 26.23% Heodo
2020-07-29InvoiceGMJJ00_21397384.docdoc 6bccac77a72403880d41bb0e487db280610c96089a428b7471ffe4c3f970fed7Virustotal results 26.23% Heodo
2020-07-29INVOICE_301_851832127.docdoc f5bfc401355756e46750895f0551ce275971d05c441917c26ec8bb0d3054d114n/a Heodo
2020-07-29Invoice-E4 737523.docdoc bd6c77378489cb8fd4a161d48e7942912147f621de2390270a9094b8ae137397Virustotal results 25.81% Heodo
2020-07-29Inv-80{:REGEX:.docdoc 445eac6a0537d629f9fb1564dfedbe24fcd73cd97034d53ef2257ddfc9a2a0aen/a Heodo
2020-07-28INVOICE HJ8-2086805.docdoc 930850ad4dda7f97f6e988ffeb2f6a78c71aa6376e437be4aa4eb23910eb9721n/a Heodo
2020-07-28InvoiceTJR12{:REGEX:.docdoc 1528aa95a67f97d195034d9d8fe577e858e7320bdd878ab0c9ce49f2847af3c8Virustotal results 43.55% Heodo
2020-07-28Invoice A8080 836563.docdoc 1659c5b0a90ab237c7bda0b92dc6b81855c43ee6eb0bddb69871d42657215e03Virustotal results 47.46% Heodo
2020-07-28InvoiceW1_9587978.docdoc 46ffdd22a492c297bb31ef326f748e8ba75657ae2049ab4d2412900fc74e3367Virustotal results 40.32% Heodo
2020-07-28Invoice AQX1-626453.docdoc c61820249fb8e9e6d4e20f466c9eb023334d37138f66b001e5b2221392fb7eedVirustotal results 40.32% Heodo
2020-07-28invoiceV0_3618400.docdoc a2c192131c94c238384e83d521ae6568774258c7267ff5e74a015255555ac4e6Virustotal results 42.86% Heodo
2020-07-28invoice F7 8534184.docdoc d2c93f7df3610ee2f4cf3f2716e5b30b5cd23faf8aabcf2ff01a623923088cdfVirustotal results 40.98% Heodo
2020-07-28INVOICE_V983 523928.docdoc 25e12758f5837d2de012b1df34c4e8e72fa0a90075d040f92d97bb65c641690bVirustotal results 40.32% Heodo
2020-07-28invoiceV036-355481656.docdoc 93af75ae71cfa54968b415afeca6de510c2b304d936c496bf4f56690ee3ec63aVirustotal results 38.71% Heodo
2020-07-28INVOICE-66-70453165.docdoc 42cec717e6e1fd0b9a895f70073c7c41acdba3cfc000faa687bfdec03fcd0670Virustotal results 38.33% Heodo
2020-07-28Invoice A75 30104024.docdoc 6a604ee31d3ad5b027844967a2c07fad16484e677e4deb36e797b98b6b959194Virustotal results 38.71% Heodo
2020-07-28invoice VEZ80 75572666.docdoc 54171a3ad4b125dc2795767c4e783e474bddf5f973b21bfaad94b3d15057b763Virustotal results 41.67% Heodo
2020-07-28Invoice LOJ8-018952882.docdoc 0034fc70978e5e2fbd485351d863a0f1f6eb072e56cf5eac63df39bd8aa5bf40n/a Heodo
2020-07-28Inv-UC688_077987.docdoc b72f8c2a69de87ac9abe79b1e167ed8622746bf5ec275ded3f6925190413caacVirustotal results 39.34% Heodo
2020-07-28invoice_N568_264403967.docdoc 66d8ecba1453aa8cb05ecc2f1e68de32bee30e7c4da041888c339b33032beae2Virustotal results 40.00% Heodo
2020-07-28invoice_N568_264403967.docdoc 66d8ecba1453aa8cb05ecc2f1e68de32bee30e7c4da041888c339b33032beae2Virustotal results 40.00% Heodo
2020-07-28INVOICE_ZA661{:REGEX:.docdoc 9b53e25c18550bb28f84e6697c4ad8a1024b50dd98073ba4d187c207aa3efacdVirustotal results 39.34% Heodo
2020-07-28Invoice-PBYK9 3011592.docdoc 2b65ad40529ec61fe0b466afa8ca082896a6b69a734ff60aadc5431853b64e87n/a Heodo
2020-07-28Inv-C7-098561379.docdoc 28511f631bf376ca915a3a1e51bca9515ae3b6e4577ea494758204b95000007bn/a Heodo
2020-07-28invoice-CNMJ204{:REGEX:.docdoc 6e260261305be197c26591f7e71682cf271d71bc346224fed0b99a334c6e8d2dVirustotal results 40.68% Heodo
2020-07-28Inv QP0{:REGEX:.docdoc 1fded3892f4fe5d626ac2db13e3fa102887a58570ff4e24394e6eff607f980a5Virustotal results 40.00%Heodo
2020-07-28invoice-BFIR272_869559.docdoc 6fe3e37f73020cc0143aa21d850a62b2df7af29a651c35246d41d463c7276d86Virustotal results 40.00% Heodo
2020-07-28Invoice-N86_1876048.docdoc 4fc696232ad4c1214d2b3d17bcf0f268ddab6901590133a86284fd475bffc038Virustotal results 37.10% Heodo
2020-07-28Inv-OAZ9_6807049.docdoc 35f182246a6245227b09f3f93802700efb8a0ca75d89922a7f8ec04f38d1ba05n/a Heodo
2020-07-28Invoice-MG2115_042396.docdoc efc93a4b32e611d4d72a3dea59ead7b779e734ab7ce5047f1b22804c11e2af3fVirustotal results 36.67% Heodo
2020-07-28invoice-GLSO6221_2306302.docdoc d652244433caaa17c36aac28e633467530b4f4405da4280dc2ce54de0cee1f96Virustotal results 44.07%Heodo