URLhaus Database

You are currently viewing the URLhaus database entry for https://koenigsmarck.de/blogs/FILE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:426692
URL: https://koenigsmarck.de/blogs/FILE/
URL Status:Offline
Host: koenigsmarck.de
Date added:2020-08-06 21:39:19 UTC
Last online:2020-08-12 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-06 21:40:04 UTC to abuse{at}dogado[dot]de)
Takedown time:5 days, 12 hours, 21 minutes Bad (down since 2020-08-12 10:01:37 UTC)
Tags:doc emotet link epoch2 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08DOC_PO_08082020EX.docdoc f43b44e247e702710aebe9ba02ffca511b4dcc85f9e09baf16e21cdcb979894eVirustotal results 42.62% QuakBot
2020-08-08C_W4AJI1E3ZIX5E9L.docdoc de2c0d155018df39b6034698ea9c4b08c4abba8900d1fc8c386b299d49abe792Virustotal results 37.70%Heodo
2020-08-08FR2466311793TM.docdoc 50de14dea661933d17f3c90f9ebee84882f992beedcc93567606c0b8612d2649Virustotal results 35.48% Heodo
2020-08-07TS6123991148KU.docdoc 41ef6b4c13a98f92f61c7a14e9619f68f166ea699a7ea6eee9a1bf0165512f81Virustotal results 36.67% Heodo
2020-08-07BAL_EHMSOARH.docdoc 76d2a23274d866daeacca1a0038a331961c83d61224504b2c10fd41ee3d133deVirustotal results 37.70% Heodo
2020-08-0774800266.docdoc 6adcae1a6473200202d0c7be82e65ec464926066b908d230dae42ca6e257389eVirustotal results 34.43% QuakBot
2020-08-07E_PO_08072020EX.docdoc 0f47f64c0de139973e1023613b4f36d34598d3c7fc713b324b3b096d8f183d3fVirustotal results 29.51% QuakBot
2020-08-07FILE_13895802430837540782.docdoc 60582057db0b8b7677173d87d87d3855d5f189ebf39995e2d7ff0e138007a75fVirustotal results 31.15% QuakBot
2020-08-07DV5295195956DR.docdoc e76e81b9b17d625e14b2a2932f7e8bc0c579f16b407c82afe10fefa4b67dbbbfVirustotal results 24.59% Heodo
2020-08-07PUXP_OBA_080120_LVZ_080720.docdoc b87f59456b02d9174ce28248ff70093d222e4c500074ae78e04251067ce1901cVirustotal results 25.00%Heodo
2020-08-07QXF_PO_08072020EX.docdoc 968f325c4ec73f09cc4737a009f8e2fc298737b4bb379dd2bc39ae7c67003e81Virustotal results 25.00% Heodo
2020-08-07YHJ_81585709730470627.docdoc 1cad925612219827eb9d0768f2b258c80357eee36911d631a298354b42641357Virustotal results 20.69% Heodo
2020-08-07DOC_YV6634538556BP.docdoc 6011d30bda10ff7a9f9e5cc83968a34178af8cb958e7eb7fe50f5d735c06c590Virustotal results 44.26%Heodo
2020-08-06DOC_4290724977683.docdoc 858e1bda8036482c0e003f669fcca4873ed7d3432732db2835e050ca15121a5cVirustotal results 26.23% Heodo
2020-08-06BAL_9332847615161879931182476.docdoc 482bdf529303b816ba84503cf9f6e2b4f339b81d01f1350c3af7565d7ab1f0d8n/a Heodo
2020-08-06KBO_080120_LGN_080720.docdoc fdd0de7dd1df09b348b4eef3c0328110d0e972faf74a98aaa056ec109dae7b20n/a Heodo