URLhaus Database

You are currently viewing the URLhaus database entry for http://lagershop.rs/cgi-bin/ut_jpkooqwq03w_tkmoqwn_3mhtehx5fmg/test_profile/DBtGciEjAIP_4qIemxlh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:426990
URL: http://lagershop.rs/cgi-bin/ut_jpkooqwq03w_tkmoqwn_3mhtehx5fmg/test_profile/DBtGciEjAIP_4qIemxlh/
URL Status:Offline
Host: lagershop.rs
Date added:2020-08-07 05:57:15 UTC
Last online:2020-08-07 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 05:58:02 UTC to abuse{at}hetzner[dot]de)
Takedown time:8 hours, 4 minutes Good (down since 2020-08-07 14:02:07 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-07Rep-2020_08_07-252.docdoc a288dd3026142c4fb729f070fdb05a968a11a0cb77d24bdcc066866ac51eb936Virustotal results 26.23% Heodo
2020-08-07REP L7127.docdoc 5758ab9165be010ed997a923a16d1d5651b13ede3b6ec4c96faa236f8591759fVirustotal results 25.81% Heodo
2020-08-07Rep 20200807 38972.docdoc a250ce55a113006da7d4cb57c16786f3d0c62ba5ab7c1fb76b0baf89b4ec9332Virustotal results 24.59% Heodo
2020-08-07File_2020_08_07_88698.docdoc c9446d50702574217eb30ddf8a9f1752c77215b5a1d6a451532920aa2a8ad5e5n/a Heodo
2020-08-07inf 6061140.docdoc 382174823a7c36d512b36fa77c017170465f34034a645db3517ca6de6e902aaan/a Heodo
2020-08-07MES 458704.docdoc b556ecc3eb51d65551b28b2e9647f7104ca35427be65f2f2cb9b6384a1b5b3c4n/a Heodo
2020-08-07File_2446.docdoc 1cc3fe55cd9952581cd54ff7b1a12d5a7a2aa90d760fda8b9a6b2ea8d010e1a7Virustotal results 44.26% Heodo
2020-08-07list-394.docdoc 2c5b7f8488ec8abc944d1a90f84293494cb7c6dea6cd23bad40fce8429f41442Virustotal results 38.71% Heodo
2020-08-07DAT-20200807-WJO615402.docdoc 9fda153dee6f47ac4ab198402cc17dac3bd96bd975458ef5dc23e2345abe48bdVirustotal results 43.33% Heodo
2020-08-07FILE_2020_08_07_72015.docdoc a6cf38618a58d0076e02ca5aa15020a6971e1367e0b8c00168775a31f8b92618Virustotal results 37.10%Heodo