URLhaus Database

You are currently viewing the URLhaus database entry for http://ferienwohnung-malcesine.de/html/open-resource/individual-warehouse/tigcc-u7w0wy5s16tt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422389
URL: http://ferienwohnung-malcesine.de/html/open-resource/individual-warehouse/tigcc-u7w0wy5s16tt/
URL Status:Offline
Host: ferienwohnung-malcesine.de
Date added:2020-07-30 21:14:03 UTC
Last online:2020-09-05 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 21:16:03 UTC to abuse{at}dogado[dot]de)
Takedown time:1 month, 6 days, 20 hours, 1 minutes Bad (down since 2020-09-05 17:17:58 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-01Arc-2020_08_01-450644.docdoc 92a8c9729a35ef4fbe97b8b931ac2ba3284ff4c1aaaab30eadbe36ad12c75465Virustotal results 47.46%Heodo
2020-07-31File 2020_08_01 I423.docdoc 4fd05fbbaa5f5944ba99f31291ed14d6991f4084c7c5f7fceb29dc462b7e68faVirustotal results 47.54% Heodo
2020-07-31INF OY499.docdoc 18bbd28cd8b9f9734cd12e10add7b892fc7e384aa4a24fb2d9a13e0b99122d58n/a Heodo
2020-07-31REP 799.docdoc 2f5edec4351fad5521646ffb86ecb8c584fc8da1f3b7852d1302cb8ec7fc696dVirustotal results 49.15% Heodo
2020-07-31FILE-Y586148.docdoc 09b591c165b3ecaa1fdc7b1afc9b6a2f9cd8a49b1e9936d7949a8ebd083163b3Virustotal results 47.54% Heodo
2020-07-31Arc 20200731 P583205.docdoc b90405b5945098e5acd1f81f9821c66b49f8bf3b41ae47e41ffb76e5a95de4f3Virustotal results 49.15% Heodo
2020-07-31Arc.docdoc 6845b4264086309f419c423aa1d2d867b27a3d2139e9a348939bf6ad0620c4a0Virustotal results 47.54% Heodo
2020-07-31dat_3968437.docdoc 8594a5bd9d47a5be27cdcb80d89dd173415bb88ad0e6e8c2a45d81ac594042a7Virustotal results 48.33% Heodo
2020-07-31Arc-20200731-069126.docdoc 775cc5726879d9b9708606b11e87b678b61b022aa5ec842c5666d3cdcfb8a4acVirustotal results 47.46% Heodo
2020-07-31list-I677510.docdoc d36b953bd7ce710bb1ccd1f2889d6c58118736a8d384ea994040b79f02cc3c31Virustotal results 46.67% Heodo
2020-07-31dat 2020_07_31 347.docdoc ec8b46f21d2533753c2813ecba4080d27fb413b98099f87223b5ef00175669c5Virustotal results 43.33% Heodo
2020-07-31DAT-20200731-6007.docdoc 5a2684ad28a602e041aeddf1c0ffab3a0ce29c3420b4a4d8a8351043a2269483Virustotal results 43.33% Heodo
2020-07-31INF_2020_07_31_RJ800.docdoc 176798f8aef40d58037ff4a5095d177dc47533593fb136804c3ee5c07db50449Virustotal results 42.37% Heodo
2020-07-31Doc_2020_07_31_ES140730.docdoc 36566f964378e3e960ece207acf122fdccf09851b875a0620880289738794e56Virustotal results 43.33% Heodo
2020-07-31INF-2020_07_31-1982.docdoc e5b7ca03743efe37bb95aa3800a1a6cce4097f10559da6e89c52d20e0903069eVirustotal results 42.37% Heodo
2020-07-31Arc_2020_07_31_DO096833.docdoc 27ce43fe47db68424483795b29ece2105efd82b3916c52c71c7e90acda9c6134Virustotal results 40.00% Heodo
2020-07-31Doc-HWH29758.docdoc 5335d6881bf6a2b0776a89724043b6693dec8ffb4848b0c66954f6373c38cb20Virustotal results 40.68% Heodo
2020-07-31INF 2020_07_31 P796.docdoc eedaaf67ad14a0213229367966ad1333e3f8085e1e6b83683d7fac0e3e16ae28Virustotal results 40.98% Heodo
2020-07-31dat-PL255519.docdoc 925fb8974d3622ddd5df080f3bee888c2ce91a92d43cd6b685ee82c8108deab1Virustotal results 41.67% Heodo
2020-07-31list-20200731-PB019776.docdoc bf9c2f98bb050feb53af183589a17d02c30fc473d9ec103d40c2a1d27ac9befdVirustotal results 40.68% Heodo
2020-07-31Doc-20200731-7729500.docdoc f65e81e022734e0c7885dad4bbed2d4269a32b6174b776af11c5c32571e79c24Virustotal results 49.15%Heodo
2020-07-31FILE.docdoc 0d9bd1c99b795fe81a3fd93c3876a155141a8aae073c9bc13d6e68771efdd59aVirustotal results 49.15% Heodo
2020-07-31dat 2020_07_31 ACB141488.docdoc 140b640e5a4eedcde235ef010770af96408aedf4e0d32745177410858b7e5caaVirustotal results 48.33% Heodo
2020-07-31Inf 537253.docdoc 57b075be6438184bf527bd055363a33f851ee9acb765aaff3c717f2ca6ea7d5fVirustotal results 49.15% Heodo
2020-07-30LIST 2020_07_31 W49774.docdoc b9c357adce4a39fef2bdc25779951e2f40307dade90e05fdd0f95b77cf77c786Virustotal results 49.18% Heodo
2020-07-30Mes 2020_07_31.docdoc 80565d4ed000d2c561645c79096f5e2fe04ac3f5c7e9e34ac68cb4ed9306ceabVirustotal results 50.00%Heodo
2020-07-30dat_20200731_ABH7400.docdoc 4122a94cf3814bd9e32328263e6b981316558b31ce38df659a1853a02274dc00Virustotal results 50.85% Heodo
2020-07-30Arc-A86602.docdoc 1076bbb650f5180bd85eead7b5411b8d601b04cebbf38dac7328ea86b4e7adb8Virustotal results 50.00%Heodo