URLhaus Database

You are currently viewing the URLhaus database entry for https://meinhaarzauber.de/cgi-bin/jgGjVSz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422373
URL: https://meinhaarzauber.de/cgi-bin/jgGjVSz/
URL Status:Offline
Host: meinhaarzauber.de
Date added:2020-07-30 20:46:03 UTC
Last online:2020-08-13 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 20:48:02 UTC to abuse{at}strato[dot]de)
Takedown time:13 days, 9 hours, 24 minutes Bad (down since 2020-08-13 06:12:04 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31Invoice_BID6961_542420.docdoc 6b6e072d0d18e1b1c941206ff11fb1a9126c5bc5472e7466c68ff933bfd016d9Virustotal results 47.54%Heodo
2020-07-31InvoiceYDU0147716370.docdoc c13e46d1796c767f42fcb0b83df4e4e8775ff207b91c3cc649a3fe3f4690a89fVirustotal results 49.15%Heodo
2020-07-31invoice-RF5298-7786316.docdoc 72415af9d773933fed912104a4d2548b885c0adb139a6d29ea8a167a3717c48eVirustotal results 48.33% Heodo
2020-07-31INVOICE-6994-580860895.docdoc 604d8d4b25d82a9fa60525c21b4f7ff9f0edf0d00aea808ceef6bef8e9e4f4c5Virustotal results 49.18%Heodo
2020-07-31invoice-8054-2931207.docdoc d435dd55cb5ac574d2109b9052330650fb4c355ff4cb2533077281558e7d4de9Virustotal results 46.03%Heodo
2020-07-31invoice-PUV640-035291.docdoc 56e8a51e917d57655dd5612da8b9618280c29273e601c8628c787029996d1823Virustotal results 48.33% Heodo
2020-07-31Inv-OGD8-0083409.docdoc f7188943259ba89e508eeffa4bd48ce022205b06f13e18944c59e419604dd722n/aHeodo
2020-07-31Inv-JID0-342446452.docdoc d4c0573790c2e02c30dc3ef6e219a26840751e18de0537fb023782af9db88116Virustotal results 47.54% Heodo
2020-07-31Invoice_9369_236137.docdoc 015ea078c5fd0a7e7358750b113536aa28746f179954e4c37e6185b99888c39dVirustotal results 46.77% Heodo
2020-07-31Inv-V382-48775807.docdoc 8d668df833984a5c527237ca2ab0cafd0d9358925912ce0c64cfb8fb749d09f8Virustotal results 47.54% Heodo
2020-07-31Invoice 4878 83067643.docdoc 2793dc7590ad4da3c118e4aac6a771ee48f213454bea29f708b1d4590fcf2ba8Virustotal results 46.67% Heodo
2020-07-31Invoice 4878 83067643.docdoc 2793dc7590ad4da3c118e4aac6a771ee48f213454bea29f708b1d4590fcf2ba8Virustotal results 46.67% Heodo
2020-07-31invoice 8 763412.docdoc 2ffaeb1accf696b047193a4fb4a47238f2a3b582415a75cade2bfe9b69982a2eVirustotal results 47.46% Heodo
2020-07-31Inv-S822-0930320.docdoc 80b42f3e3f2aa0e14a13b15336be50853898ab711533f01420be367c69d9911bVirustotal results 47.46%Heodo
2020-07-31invoice RMT495 776081.docdoc 6157dbba4f741eefa74c0f002ed410a6117e719c2e626ea9dd8668d7452afa24n/a Heodo
2020-07-31Invoice-QW1-5447716.docdoc f38d973c25ff2fc00109ee8ed445e3bdaf3fcaeff6db54b863ad025a9104ae24Virustotal results 49.15% Heodo
2020-07-31Inv-NKQ8352-5651843.docdoc 882e44a7683a4befbb3083a772a54362fa0e70ac235c112cfa2005278e6db042n/a Adware.ExtenBro
2020-07-31Inv-FOGD261-53439432.docdoc 8f73071e0edbc9813f45554df26b3414e3650b0982700c2ddae27bc950c10d08Virustotal results 45.00%Heodo
2020-07-31Invoice-1815-224393570.docdoc e8960fed4c714be347182294b90b9fc936d842241905fe3e4376bf7c904b6b1eVirustotal results 45.76% Heodo
2020-07-31invoice S7 3306017.docdoc ffcca6f9140c3ff0a3f0e0b888148ebf2d55a3ccfa54636106362ea6f9045f0cVirustotal results 44.07% Heodo
2020-07-31Invoice-TAFU465-3444522.docdoc 3d8ef147ca84e9943fdc850171e2de9c05b0db3472cd05901e4f109e7fbe07f1Virustotal results 50.85%Heodo
2020-07-31Inv 4_364046566.docdoc c7ed06b6f4284ba3fd857f03875187654aad78683efa88d3ed984fe057d484abVirustotal results 50.85% Heodo
2020-07-31INVOICE-8658_89141000.docdoc 0154af8049b8a7ec498151777f31d6e971c61bdfc439fe1a8150ad0f69c0e4f8Virustotal results 50.00% Heodo
2020-07-31INVOICE-79_733949.docdoc 5399417505ae67bdc2253943f273fe2b69fcdb71294530cbfe0cbe731a251b48Virustotal results 50.00% Heodo
2020-07-31INVOICE-AR204-46171662.docdoc e3b83c00a51a401c88f8ab7d52dbee1d71b7a843fdfe5c2a6f3b76464efd77b2n/a Heodo
2020-07-31Inv-593{:REGEX:.docdoc eae169c0ec808dcf097bfd419bae07e5c001b1157d781d90b037250ea07fd4bcVirustotal results 50.85% Heodo
2020-07-31Invoice NN6775 485224597.docdoc 09d8024f4904f92b615ceabf3c50d048d8600e410bd728c5ca6a09f15ac8d0aaVirustotal results 51.72% Heodo
2020-07-31Inv_7-612071.docdoc 48c0326e786deae1ebf50df4773916c79325d15261708cccbc89d2421c639729n/a Heodo
2020-07-31Inv_OLDM1-2082115.docdoc dcfb38249b589a264dd4ce2c25853335f1399685fcd68d68c337f308d110a793Virustotal results 50.00% Heodo
2020-07-31InvoiceSPUN828_993932946.docdoc cee085d16cb1dec28ff7ef5bd5399111ba8a5e26623b17902866e886144c228fVirustotal results 50.85% Heodo
2020-07-31Inv-T38 45541481.docdoc 468c03e5514c45db80f93d359506f99bcdc95812e5e37680b531dd2fd1cba7f2n/a Heodo
2020-07-31Inv_RF9465_716127.docdoc 2a378624ddc963eca6688d3c25bec4bc7637de2153e1f23f594622a03f6e600dVirustotal results 50.00% Heodo
2020-07-31invoice 3 4128117.docdoc 2789d1d3eea1e5dcb760faf9bbf395f267ec901bc7c52a67ae60133050897609Virustotal results 50.00% Heodo
2020-07-30Invoice ED8123 027755.docdoc e42656550ed8d746cb8b453d28e1ca374da03e76bdf6b65633f3b1bedd1e051cVirustotal results 50.82% Heodo
2020-07-30Invoice-71_377757.docdoc 213e581104ed3930497515d2be67c1c61a9ab1060474d3e43986aff52b418099Virustotal results 51.67% Heodo
2020-07-30invoiceZ5-997807.docdoc 5ae9df4be21b3400965fc280ee49768b7e00b21fde24a904ece809bfa5c19491Virustotal results 50.00% Heodo
2020-07-30Inv ZJKM8055-097039.docdoc f2bef647cf5f376c3807d6693d2fcf28cd42e71629fb0cd64847604a0e189081Virustotal results 51.67% Heodo
2020-07-30Inv-ND1{:REGEX:.docdoc 1c8026d6bd75a1ea091d6a6676d3a7e3bcba3b17717e21607488b9fdb762fba7Virustotal results 49.18%Heodo