URLhaus Database

You are currently viewing the URLhaus database entry for http://tigaeurope.com/cgi-bin/eai-a7p-363/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427242
URL: http://tigaeurope.com/cgi-bin/eai-a7p-363/
URL Status:Offline
Host: tigaeurope.com
Date added:2020-08-07 14:23:37 UTC
Last online:2020-08-11 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 14:24:03 UTC to abuse{at}provider[dot]nl)
Takedown time:3 days, 18 hours, 15 minutes Bad (down since 2020-08-11 08:39:56 UTC)
Tags:doc emotet link epoch3 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08Invoice-KHZY5-7747953.docdoc 5d7f4b905c268a16b873261ceb5f2bca434dbaa45ad6c5b20a3d43091709ace2Virustotal results 39.66% QuakBot
2020-08-08invoice-XTWD384-541603918.docdoc cd3b6e6b12ba31ef7328753a5202713990a7a53cffd127c1883ae43eead6d338n/a Heodo
2020-08-08Invoice-APW2-239988.docdoc 6976f6b22b770cae154126db827c87484c4c1c757099f6a5d477760a364dbb04Virustotal results 39.34% QuakBot
2020-08-08Invoice-808-79723879.docdoc 7e6769ef042d11235ccb92f40d7ee699bd81ef995b00f66e10ddd3b5bb5e92dfn/a QuakBot
2020-08-08INVOICEISJP6664636000.docdoc d9117ec342f11a6f9cfe66f8c223ad054a26dc3cde8c442a7a72d537701fbff8Virustotal results 38.71% QuakBot
2020-08-08Invoice-6-9304200.docdoc 83fadccccb33a9b873d6790f162ad11cb83476c3e42ea6c6a6740b0ea5736299Virustotal results 38.71% Heodo
2020-08-08invoice Z50 514193072.docdoc 09e2172af9c38a6d8145f2bc5f71ef35e7aa2fa507c32d432b76fbd3e07e6c11n/a QuakBot
2020-08-08Invoice-65-56449340.docdoc 3861a52ad582544a7eed808c49f41588b9620ffc729cc2c9de6a83aca5762fd2Virustotal results 39.34% QuakBot
2020-08-08INVOICEXW727795299.docdoc 0c2d5e2908fae3e85bc9c59e5055bc4b15aea4fc7c168326831bcb05b9b6521bVirustotal results 38.71% QuakBot
2020-08-08invoice-08-238884.docdoc b67b32bfd579e0f9ab07e5c28fbffa92e3b061190d7b010a0ac40655aecabbdeVirustotal results 37.10% Heodo
2020-08-08Inv_29_580824.docdoc 2659421c624afcfc6ad404b436a664c9faae922b703e516ccdcfe79f2cbffb27Virustotal results 37.70% QuakBot
2020-08-08invoice-2-75258222.docdoc 181a73930d18db229ad4ae73c4132a6cf281b75283d8f25c2674bfa2294e9152Virustotal results 40.00% Heodo
2020-08-07Inv-WJ5-03276857.docdoc d91731a4dfcfb45b578cde0a57e35273bdc0eecf426e738a1f52a32e989c9fb9Virustotal results 37.29% Heodo
2020-08-07InvoiceKFR71593132862.docdoc a4b97280b1cceda62816b36b8b40327eea965a74334cd171eeca03b3158d3177Virustotal results 37.29% QuakBot
2020-08-07Invoice 6 260179727.docdoc 522dfd2bd5983277254467284eb5cb1ae79a0957444adbd473462cfee3599c4dVirustotal results 37.70% Heodo
2020-08-07InvNQW139901706.docdoc 7ce67620298aa7d0fe5e7f2bab8e052f4a4ce937c3300c92875e33d7b466acc0Virustotal results 36.07% Heodo
2020-08-07invoice-ACTH61-677118.docdoc 255d93f7b3867d2064ef2b770e78dadcb7bbba75c83390116b3f3b9222877559Virustotal results 33.90% QuakBot
2020-08-07Invoice-EO2423-167776.docdoc 5871ec926c8f2a5e608bbcc0aadc55520fcba58d418280c7f44449f8e88a3d41Virustotal results 32.79% Heodo
2020-08-07InvoiceO7795265815.docdoc d43e6eec7587cc038fd92be0d45b18cbd948a9d927fcb5d378e47e1c1ef141c6Virustotal results 27.87% QuakBot
2020-08-07Invoice KTV73 691491034.docdoc b0ca63e844878888dfd2c5e0ec67432ddbf00dd81de2f91d7b807308d942b84aVirustotal results 27.42% Heodo
2020-08-07invoice-PYUO3352-299236.docdoc 38484bba81fe221467f8808a6667bd4344ab116fdfa4f92a1acccbf8e86d0b4dVirustotal results 25.81% Heodo
2020-08-07invoice-JAET1542-6207504.docdoc 8dca57bd20cb1aad6ec1fa7527c59fac9aa9f278935d7eabade0ff47817bda58Virustotal results 25.42% Heodo