URLhaus Database

You are currently viewing the URLhaus database entry for http://ultimate-24.de/logon/personal_section/verifiable_portal/79327268_kImG0pU12BbGPx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:426168
URL: http://ultimate-24.de/logon/personal_section/verifiable_portal/79327268_kImG0pU12BbGPx/
URL Status:Offline
Host: ultimate-24.de
Date added:2020-08-06 09:38:05 UTC
Last online:2022-03-22 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-06 09:40:03 UTC to abuse{at}dogado[dot]de)
Takedown time:1 year, 7 month, 23 days, 9 hours, 36 minutes Bad (down since 2022-03-22 19:16:17 UTC)
Tags:doc emotet link epoch1 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08DAT_3452001.docdoc eea494e866becd4ce5d21eaf4ba21c10cb806a32d385336edd7517d8b14af028Virustotal results 43.55% Heodo
2020-08-08DAT-20200808-MTT358.docdoc ba50483a5407dc7d213263534638c2e4e0445d9d06f977dc496e979beda32f33Virustotal results 40.98% Heodo
2020-08-08doc-314.docdoc 63d401363df2dded7f8e2507f64a6f20c9443fccc2f862d8b78641328d13f579Virustotal results 40.98% QuakBot
2020-08-07arc-20200808-502.docdoc 5d2b88e4fefb1593bca1de5b27276ba0d00140416c91339fc6fd44431c8ccbd9Virustotal results 40.00% QuakBot
2020-08-07LIST-20200808.docdoc 0ac47ffbd42f03c480345a7dd4402200a64b23da9c45e237bc7dd243e9047948Virustotal results 37.10% QuakBot
2020-08-07MES-20200807-F707.docdoc acf64b8e97e3201f06314a33733d479adef77620d8c569663be2e02c3ef38e98Virustotal results 33.87% QuakBot
2020-08-07Dat-697514.docdoc 00aa9e9dcbecd3aa1f33bae92e906d48b96429b10b0ce2dccf301ff03682d536Virustotal results 29.03% Heodo
2020-08-07List-2020_08_07-ACE645922.docdoc d44d322769b573492a8bb345b4ffa1062789e82c500080d25cd09227c79d8483Virustotal results 33.87% Heodo
2020-08-07Dat 20200807 VMK768.docdoc 18df1f0332f24e7a2a573935396295be9ddaeb01f6008e8e0adb15c0a2b51bbbVirustotal results 26.67% Heodo
2020-08-07arc.docdoc 9b1840f434d4ad429562837709456e572e94dadc8428ec8b9168042ca0d23361Virustotal results 26.23% Heodo
2020-08-07arc-2020_08_07-0303511.docdoc c7bf1627327bc4ecfac7884f9f9516a48c8e95bf7628f17043e115c72f68ff26Virustotal results 26.23% Heodo
2020-08-07dat-1442.docdoc deb669530640786d01b93dc6537ae68c13fd0b2785de9133fcccfa08dd5fb96aVirustotal results 26.23% Heodo
2020-08-07doc 20200807.docdoc a6cf38618a58d0076e02ca5aa15020a6971e1367e0b8c00168775a31f8b92618Virustotal results 40.00%Heodo
2020-08-06Inf-2020_08_07-UA63431.docdoc 4105a7b924615ef7a3d142ec138f6a7340a715250f3e957c73a5c377c572ee7fVirustotal results 26.67% Heodo
2020-08-06ARC-2020_08_06-WRX405.docdoc 1e35f91e2a870f4fd57e12b38ad4d191424815e19a8e73d5cf3b36188308be4eVirustotal results 27.87% Heodo
2020-08-06REP 20200806 7943715.docdoc 13d3f89e0880281bef900884d46138dcef1c203c652e750c13fe38ff5f968ac7Virustotal results 22.95% Heodo
2020-08-06MES-20200806-29057.docdoc 48c9122a26741dad73b2b5eb26728c9aea5e93081462554216fe3710ce612a22Virustotal results 23.33% Heodo
2020-08-06rep-4213.docdoc 92ff6045a6d5beddda905a0f0f3d8f1e21eda444f0434f20819d682cd6103c50Virustotal results 19.67% Heodo
2020-08-06dat-2020_08_06-60471.docdoc 64cc76e8a30b80fea4d14b10dd5fda014463de539eb8c165aae3c386f0ffe998Virustotal results 22.41%Heodo
2020-08-06arc_20200806_U06243.docdoc b3257fc405ad35b2ba3b4f2480809bf548eb54ac85d635846be5de2d7f313c8dVirustotal results 18.03% Heodo
2020-08-06Doc_338934.docdoc 5e8577ab31f890f1a4b1d74b0f90b14ae0fad744678fa8936ff7cbcd9e85b575n/a Heodo