URLhaus Database

You are currently viewing the URLhaus database entry for http://www.reifenquick.de/Scripts/open-0627720493640-azQ24PfFjRm/guarded-space/gxkx9t42ra6yf-6x7uyx330389w/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:426390
URL: http://www.reifenquick.de/Scripts/open-0627720493640-azQ24PfFjRm/guarded-space/gxkx9t42ra6yf-6x7uyx330389w/
URL Status:flame Online (spreading malware for 5 years, 4 months, 10 days, 19 hours, 34 minutes)
Host: www.reifenquick.de
Date added:2020-08-06 16:04:05 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (phishing)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2024-12-20 07:37:53 UTC to abuse{at}dogado[dot]de)
Tags:doc emotet link epoch1 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08MES-MA1333.docdoc eea494e866becd4ce5d21eaf4ba21c10cb806a32d385336edd7517d8b14af028Virustotal results 43.55% Heodo
2020-08-08FILE-2175.docdoc ba50483a5407dc7d213263534638c2e4e0445d9d06f977dc496e979beda32f33Virustotal results 40.98% Heodo
2020-08-08REP-20200808-78153.docdoc 84cce9a551dc2eb66990351d4d17dd8c37f457ad337bcb9984231f608208258aVirustotal results 43.33% QuakBot
2020-08-07Inf-8203710.docdoc 5d2b88e4fefb1593bca1de5b27276ba0d00140416c91339fc6fd44431c8ccbd9Virustotal results 40.00% QuakBot
2020-08-07Mes 2020_08_08 J6970.docdoc 0ac47ffbd42f03c480345a7dd4402200a64b23da9c45e237bc7dd243e9047948Virustotal results 37.10% QuakBot
2020-08-07Doc_2020_08_07.docdoc acf64b8e97e3201f06314a33733d479adef77620d8c569663be2e02c3ef38e98Virustotal results 33.87% QuakBot
2020-08-07Doc-NB344.docdoc 8cbee4a45b5e799b5147bd50530fc9dded0b2e61503523a65ca24a68a3ac2c08Virustotal results 29.51% QuakBot
2020-08-07ARC_20200807_IS71274.docdoc 0c521d971d4f848f0fe2d2602be0198ed41c412db71a3dab065d5100be08bb04Virustotal results 31.67% QuakBot
2020-08-07doc_7110.docdoc 18df1f0332f24e7a2a573935396295be9ddaeb01f6008e8e0adb15c0a2b51bbbVirustotal results 26.67% Heodo
2020-08-07Mes-38246.docdoc c5900771fe96ab3ae58a92effdf774311499cccacae052f64f8b4ead02e3c15cVirustotal results 24.59%Heodo
2020-08-07Mes_2020_08_07_67073.docdoc d19de294ca34ac739da82bca124ab66a015895df4257b9010bc196ae0944bdd8Virustotal results 25.00% Heodo
2020-08-07MES_HG2352.docdoc 0eb0994986124da10b6ee49b964e94dbe57134f1819b3fc46a6aa11253b5c977Virustotal results 26.23% Heodo
2020-08-07Mes_JAP189.docdoc d55a2e0971027bd30b6722f6827d6344f1126b7f7ba6c04a91179b881ca6e98aVirustotal results 26.23% Heodo
2020-08-07MES_2020_08_07_8354.docdoc 9fda153dee6f47ac4ab198402cc17dac3bd96bd975458ef5dc23e2345abe48bdVirustotal results 43.33% Heodo
2020-08-06Inf 4573.docdoc 5cb62b11691b27c6ec5d24b27bab599c25a26d94a7edc30aac2f8693ae3fcc72Virustotal results 27.87%Heodo
2020-08-06mes-20200807-APE84537.docdoc 60317c70b7bf645aaa1486df2110ed8d5b562fa849d73b3d6c850093713545b8Virustotal results 29.51% Heodo
2020-08-06ARC 20200806 D731.docdoc a0e4c8a409c56a22b765c4ebe9e42dcaa8078b4986f8db0db88b91f0ee11f107Virustotal results 26.23% Heodo
2020-08-06REP_1214574.docdoc e4c0b9acd76b72b5cfaae774818c9222ae052b5fdcb6c29bac642d6c0b720477Virustotal results 26.67% Heodo
2020-08-06List-20200806-V73616.docdoc d526df7960cf7fe141094c78d40e1e5840f5782cf93e0b0fce601e70c56dec75Virustotal results 22.81% Heodo