URLhaus Database

You are currently viewing the URLhaus database entry for http://lindnerelektroanlagen.de/pages/closed_array/corporate_Qvt1WRAIL_wizVz4iwC2/Mb2cyxZUJuX_et9L1IppzGs5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427002
URL: http://lindnerelektroanlagen.de/pages/closed_array/corporate_Qvt1WRAIL_wizVz4iwC2/Mb2cyxZUJuX_et9L1IppzGs5/
URL Status:Offline
Host: lindnerelektroanlagen.de
Date added:2020-08-07 06:36:05 UTC
Last online:2021-07-18 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-07 06:38:02 UTC to abuse{at}dogado[dot]de)
Takedown time:11 months, 15 days, 13 hours, 49 minutes Bad (down since 2021-07-18 20:27:54 UTC)
Tags:doc emotet link epoch1 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08Dat 2020_08_08 610.docdoc eea494e866becd4ce5d21eaf4ba21c10cb806a32d385336edd7517d8b14af028Virustotal results 43.55% Heodo
2020-08-08dat-CI15483.docdoc ba50483a5407dc7d213263534638c2e4e0445d9d06f977dc496e979beda32f33Virustotal results 40.98% Heodo
2020-08-08ARC-2020_08_08-4294650.docdoc 23f6ed44eda0ab1b7274653b618ac891a8cbd3c467f8b658297cf68173bb842fVirustotal results 42.62% QuakBot
2020-08-08List 20200808.docdoc ec11d3cebaa5d4d05ef93c8b88ab79e34d82fede8daa5a821d119d12de060ffbVirustotal results 44.26% Heodo
2020-08-08rep-2020_08_08-HE6848.docdoc f3be0b911d44447b80b1337f332187ad596fbfe6a0739cdacdd2f9d759e12114Virustotal results 40.00% QuakBot
2020-08-07Arc.docdoc 53ac99d5826bd318da8d98fc65d4b28ee61fd3f4cf67cdf387cc88e35a0fed86n/a Heodo
2020-08-07Rep-20200808-3286.docdoc 5d2b88e4fefb1593bca1de5b27276ba0d00140416c91339fc6fd44431c8ccbd9Virustotal results 40.00% QuakBot
2020-08-07file-2020_08_08-VXW490.docdoc 16c140684e32eb93fa92afe82d5679eab09dd7d0b81e58a701c6a2958d31934fVirustotal results 37.29% Heodo
2020-08-07LIST-2020_08_07-60679.docdoc b73f780a433d41cd9d6d0046f85474514b51eb5471e34e530974673c6579eb1aVirustotal results 35.00% Heodo
2020-08-07Rep 2020_08_07 4174.docdoc 646ccd64823cfa77dbb491953dde3333f48c8c19ac7a2753088a96dce8b0d397Virustotal results 33.90% Heodo
2020-08-07dat 20200807 W369340.docdoc 016ca89513a40f3189a3620d63b4ddeecb49bb57f1459ad75154e1ddd9f2370fVirustotal results 30.65% QuakBot
2020-08-07inf_94813.docdoc 130323d560c36acdbc705cd39ea4f9e0e6b490fb2495f500989fa48940f3e174Virustotal results 32.79% Heodo
2020-08-07Inf.docdoc aaf9724d17a02da2ebb37c991ad51b1636ae22b4af318713bc3aa68538bb632cVirustotal results 25.00%Heodo
2020-08-07INF 2020_08_07 1052.docdoc 15be7667cc3b8d6445b3b4c245f2befdcf7a96e438a771828ca1ed6c12682670Virustotal results 26.23% Heodo
2020-08-07arc 20200807 0553044.docdoc deb669530640786d01b93dc6537ae68c13fd0b2785de9133fcccfa08dd5fb96aVirustotal results 26.23% Heodo
2020-08-07Doc_20200807_501441.docdoc 4d66b8fafcf69f590dc74a3383fa08576a6de54ef030b8d47bced68e03f63065Virustotal results 29.51% Heodo
2020-08-07doc-20200807-MQY85041.docdoc d21fb5ef05cc6d7375ad67529c3b74d7111dff2fd9a11ce6944a25e4dc2463c0Virustotal results 27.87% Heodo
2020-08-07Rep.docdoc a6cf38618a58d0076e02ca5aa15020a6971e1367e0b8c00168775a31f8b92618Virustotal results 40.00%Heodo