URLhaus Database

You are currently viewing the URLhaus database entry for https://egger-kirchberg.ch/scripts/hw-xiu-101/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428494
URL: https://egger-kirchberg.ch/scripts/hw-xiu-101/
URL Status:Offline
Host: egger-kirchberg.ch
Date added:2020-08-10 16:43:05 UTC
Last online:2020-08-13 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-10 16:44:02 UTC to abuse{at}hosttech[dot]eu)
Takedown time:2 days, 19 hours, 45 minutes Poor (down since 2020-08-13 12:29:54 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12INVOICE-CU252-396602.docdoc 94c5bd12d0292d5fe16c0c752e9963ad159eef1b55f987e0b0e69f2921fc6bd5Virustotal results 34.48%Heodo
2020-08-12invoice-SLQ569-269877443.docdoc f65d75354c94e954fda329743679e15d9dfc256057635221efad367833138f2eVirustotal results 32.73%Heodo
2020-08-12invoice-VNPR9-303860928.docdoc 501db74c182ca6ac3329ff9f536d58b82eee74b221ee3b0997a74a32110e6804Virustotal results 31.67%Heodo
2020-08-12Invoice_SXS6350_8896886.docdoc b06e62505b71b7c8f9877cf99eff81c680cc21dc871069cbd98141bc77e6a4deVirustotal results 31.15%Heodo
2020-08-12invoiceQ5246331352.docdoc e7c01fa90a3164924439c7e9579e0f4228a4ed9fa320d2ee564d2f2a7f5f5139Virustotal results 29.31%Heodo
2020-08-12INVOICE-0364-90696878.docdoc f3390052891e7cf3c580921e2522e4a8fe5aec87e6c819a16e738ab283ff586bVirustotal results 28.81%Heodo
2020-08-12Inv 0 1312784.docdoc 02d47faf3570a6ecec0501092d7f4edf16ec2d36f64d65812fa7157b1583c4c7Virustotal results 30.00%Heodo
2020-08-12INVOICE-BT29-073605965.docdoc 6610beb62b2916d0194d87458804ec7ae2e18e6efd800866b9d65db7a6e6b361Virustotal results 30.00%Heodo
2020-08-12invoice_LK5230_2178404.docdoc 18b61563a6f5f949870cf35801caa3b17dd86bde7d60f0446e77f85f974969a5Virustotal results 30.00%Heodo
2020-08-12Invoice-37-82249407.docdoc 08d1bd7eb9b7a4ff987f2d3825da852bee8259128948a327f78e7b1b843c3e8dVirustotal results 28.33%Heodo
2020-08-12invoice I279 774040.docdoc 6f4f19a715105100b0f216fc7eb79d12e6fbd59904da2296bc077dae6cbb8435Virustotal results 28.81%Heodo
2020-08-12InvoiceCAZV0549700155147.docdoc 28af5978f878de657395657384a4ed7a7c0d19fc418f06628d0213309c3c17ddVirustotal results 28.07%Heodo
2020-08-12invoice PO903 2872441.docdoc b194bd3195976a8b5db818cd4081aed18283e76af0dc14637905fa3d1b92b67cVirustotal results 27.59%Heodo
2020-08-12Invoice_RQG0_1352757.docdoc 0c8168de8059f07bdf21871e0043fb09e40f7788a4c6028ea4e69db047a17563Virustotal results 28.81%Heodo
2020-08-12invoice_WEZ0784_858735.docdoc fea443cdac59dd7f98d2141afd162ad736f49936f906f5ec5ed88ac95b63ad91Virustotal results 28.33%Heodo
2020-08-12invoice-K19-7242748.docdoc 6c818eb9af4ba3479156ffdddedf9e68f03dcc98579d8a7df9cdac88c483335dVirustotal results 25.00%Heodo
2020-08-12InvII0866293608850.docdoc 24d695ee5d47e6fc47afc097c1c09639443097d9fddb06851d8cc02e19aa6509Virustotal results 51.67%Heodo
2020-08-12INVOICET1777799241.docdoc 0bbbea7a2b309d9aba95c407c00367d4fe0aa1e0fdc2a0c7098c4f99e49040e9Virustotal results 51.72%Heodo
2020-08-12INVOICE530178698.docdoc 650b40b3be985f71970fc935af9f94d135cfe88873bcb3748b3ab6c5000111caVirustotal results 53.33%Heodo
2020-08-12INVOICE_VLMU8758_48161278.docdoc 0345821c81f88f77f1ff11d7ee92e3fe5544c20d62d25f5463ed5f6b72085e65Virustotal results 52.46%Heodo
2020-08-12Inv_YGO3954_901687218.docdoc 23616c6f25bff95b4f079ebf3b072f7fc60b509bab3e2245021095817829b653Virustotal results 52.54%Heodo
2020-08-12invoice 60 886252563.docdoc 9b6d187849d9a7145a75ce48447c2233436112426c805497bab8c1d342fef6d4Virustotal results 52.46%Heodo
2020-08-12Invoice L3 314671.docdoc f187d66fdb939f8dba5144cee441601671652077d4b7f795a6d0a5ce18e0fc50Virustotal results 51.67%Heodo
2020-08-12InvoiceSWEA10053899.docdoc 5ed47d47ebc0597edf84ae0658438eff8b3241ae47a071fffd0144e1c074d560n/aHeodo
2020-08-12InvoiceYLC046274449.docdoc 843b812d3b7326a6483d4b0062efba730edd7b2b6880fd6f9126309d8d498ca5Virustotal results 53.45%Heodo
2020-08-12Invoice_Z532_7937690.docdoc 0af3f5b45bb78712c8ed836cb9c83c6799e36000f09c7c4ec285f36ad72b336bVirustotal results 52.54%Heodo
2020-08-12Inv-A0292-6133905.docdoc 44b8c2c694e595c5c101cd70e1c07cb585b19db23cfd60049e3fe445f6df525dVirustotal results 52.54%Heodo
2020-08-12INVOICE_D9495_4951160.docdoc 6e9b1ad824b0bc35792a2ec92fabb0456af70c654e99e5f6d0067903f3c771ceVirustotal results 52.54%Heodo
2020-08-12Inv_76_176504442.docdoc c9a3637927d6c089d282b7e5f89be7e0269eb7fd1e823cefe8844e25153f2cd2Virustotal results 51.72%Heodo
2020-08-11invoiceKW5531464439.docdoc d1ada929c1d864f25ddf89d90029767d6c3b46a1bcd2f20cc967703c3d84bf5bVirustotal results 50.00%Heodo
2020-08-11INVOICE-H2692-91222296.docdoc 96c6a329f0da6f8cb3e414f2bde2a0084912d8de0f46d04f69f613f061c0ccbcVirustotal results 50.85%Heodo
2020-08-11InvoiceD16554237917.docdoc 855f271178a061c154a5feed625773d8a02e960340dff7e0e0aedfefd40c2873Virustotal results 50.00%Heodo
2020-08-11invoiceY169247197.docdoc 4e7dada550866484045928cef6fdd4d7ccb5d19d79febe490ed7da33d3491b01Virustotal results 50.85%Heodo
2020-08-11invoice_U8015_923658631.docdoc ba9a8497f8d62ce6e51e23f89f045998e57f187f7b8b9ff3168e5289d1758e80Virustotal results 50.00%Heodo
2020-08-11INVOICE-DE75-983820601.docdoc baa7ec55d76e7be67f654211832accb7b7352442fefbadd3a4047e63adcc24c1Virustotal results 50.82%Heodo
2020-08-11Inv E3 546595408.docdoc 98c981a420851abdca6108f1264153f000a93d4efb36a2df630d0fb91c63aaeaVirustotal results 51.72%Heodo
2020-08-11Inv-OPOD999-188357423.docdoc c427cbb868038c912ba21fe4de92c5dc4dfbdb5395c7ac27c1bd07a2f683fa93n/aHeodo
2020-08-11INVOICEK671372856.docdoc 4ce8a32a7d3405a784a5a896b2faeb1ae1c73f9201af0716bffd10fb59e38ad9Virustotal results 47.46%Heodo
2020-08-11INVOICE_HXH44_966893.docdoc cb5234b6061bbdf400ee2833eaeba7a4f39a5d883194f1c0bf3c317267799d27Virustotal results 45.00%Heodo
2020-08-11Inv UF37 931397272.docdoc 7d920c5f7bd61fd5654014e11949e391003f188c96fcfdea3e32c9d2d046db10Virustotal results 38.33%Heodo
2020-08-11Inv-FO96-418135.docdoc 800e57c4ad645349b6c44afc8fe14062e1f9ab0b9073ae5b69b17bb231eaf189Virustotal results 37.70%Heodo
2020-08-11invoice-PTZE99-266140279.docdoc 2357f42f582d5ac9f33dec658a1d79498afde67b80fbc7c557df394cf60992d3n/aHeodo
2020-08-11invoicePM327790607.docdoc adb26ad83ef85f269e46bf0219eb870350556bfb3317da039b196c487279d318n/aHeodo
2020-08-11invoice_LFC816_262663647.docdoc 81a81cd7bd810ce513cc65228f2046fdaa21f79402d31a76221873894c844982n/aHeodo
2020-08-11Invoice-6921-5627911.docdoc 003987cf80ddeb4dd704742521844c36a1b64224ca8a8aecb5d30986db8b3dd7Virustotal results 37.29%Heodo
2020-08-11INVOICE-HRX102-5184644.docdoc 70a726919b0c5a17e38584cf3948fe775e56c0927430ada9bfdcb609da988b9fVirustotal results 36.67%Heodo
2020-08-11invoiceCG05668106.docdoc 82f07a41d75f7fbed08df507a83ec451c223e71abc6b9214afd44b7a65d474ebVirustotal results 31.67%Heodo
2020-08-11invoice_MAIR700_228875.docdoc 4ed6407bac7a7d0e0122dd585bd1479764cebff3701d3e6bce6f59fd8698378cVirustotal results 31.15%Heodo
2020-08-11Inv-WQ49-6948412.docdoc 04f7553b46f71decfd022eb6049fbf4c560a3e16fa5574ace26be93a5082265fn/aHeodo
2020-08-11Invoice-RDL48-636209396.docdoc 31c192808540a3b274af57c730136b44d6a59ce3befb42f7decd08b3c0429facVirustotal results 29.51%Heodo
2020-08-11Inv WLI77 73684868.docdoc 05fac21a4430186852c51837d7f5787747aa9fb1afa75cd3f00b2505dc79351cVirustotal results 28.33%Heodo
2020-08-11INVOICE-6428-106920.docdoc 08c803b50f7f39e19f42600f5eb40b891849cce060fc514a261a4512d8084725Virustotal results 26.67%Heodo
2020-08-11invoice-5114-17810525.docdoc 7a95c345a8439026794c587553c122019925fe3072d0902ae4411458c2d68ad8Virustotal results 26.32%Heodo
2020-08-11invoice A15 733363.docdoc 744f82770d4c090be9a6bd6e9d2ab09a760ae5cdc58ba11385871d2660555586Virustotal results 27.12%Heodo
2020-08-11Invoice_CE478_850976.docdoc 5bbb813939f64e2278c6179f38bf23079ef73e26cfb042b2127fd7e8101b58cdVirustotal results 25.00%Heodo
2020-08-11INVOICETS04381541.docdoc b16e37a0663d4850eea084147f345f8ed5f0771b13cb970e6073598106508476Virustotal results 26.23%Heodo
2020-08-11Invoice-C166-040793.docdoc b97f21c9d86c3f8c4a66a3e12e9a89c5d9f0bb23fc7b90a95618bc0faef06250Virustotal results 26.67%Heodo
2020-08-11Invoice-C0-941239467.docdoc 43048cdd340fff0306fb245a60aadab8b1f8ecbad52db75e5a31771d36796e75n/aHeodo
2020-08-11INVOICEO3328644.docdoc 52e28ea8aca2d8740bf1588be8b31149155d1ed1b03f5515245289f97419268fn/aHeodo
2020-08-11Invoice-KNYY1-38743421.docdoc 6bc1e3ac932ab1cbc6359f9bf1af246523f8fa7050160994440732dd1a41281dVirustotal results 25.42%Heodo
2020-08-11Inv-WMJ0-223956626.docdoc b41a21b3db4cc29e46dfdfde2a27e0009b489da8a9530a37bb33efb21680ac2bVirustotal results 25.00%Heodo
2020-08-11Inv21736407135.docdoc 4e7876b5c5c8158924c347d181e19fb3d15f7642e7a645e7587d9e106888e6faVirustotal results 25.00%Heodo
2020-08-11INVOICE_UBN42_988737.docdoc 233870a634ccdf96fdda69a701b37127e715c783be8864a56bf8a4ac81223f8cVirustotal results 24.59%Heodo
2020-08-11INVOICEX787145681.docdoc b62a1e1adccc08cc8064309a5d7feb151348e3b1de2175cff71db2b252db5336Virustotal results 24.59%Heodo
2020-08-11Invoice-IY6-13191461.docdoc c3d1ee887506f703f42f5bbe776af1f43c0f610a72981e9ca4b81d01a01e8b4eVirustotal results 25.00%Heodo
2020-08-11invoice5969760741.docdoc 539b9b6a1a67270d4042d4a27e6c105ab464ca4a6bde8bc31a6cc617867c6dbbVirustotal results 24.59%Heodo
2020-08-11Invoice FUN4 66521915.docdoc 07d3d6eeef944a90aacedb00ffeb5fd9cbd867e927ab53097a5ddd2961259613Virustotal results 43.33%Heodo
2020-08-11INVOICE_C2926_07146098.docdoc 02d69c7b621ac1851c40603dbcc91967a103f0bc77fca48e1c608b396bc8e9b7Virustotal results 43.33%Heodo
2020-08-11invoice_054_948170721.docdoc 7d2506e9c7dfbfae498a492b500401cf7831e8f3dee4e2d9eeec527191728709Virustotal results 43.55% Heodo
2020-08-11invoice FT272 62501941.docdoc 3afe8c66d0ae9fbee1d824b8ac7538b8afc887b6ca5264206081555aa77a09c6Virustotal results 44.26% Heodo
2020-08-11InvoiceQS99600523580.docdoc 388acc363352d198585f0e176846ff7ce69c6ff6863e405e7aa422244a21b7fdn/a Heodo
2020-08-11Invoice_U91_279571.docdoc 1fbc9ed8fc7699f9210bb96065f2a385bfbda9a92af0b62c5f1d1c16815883c8Virustotal results 44.26% Heodo
2020-08-11Inv_A626_0653418.docdoc 8ae38417b073e0d10ce8af04602bbb886fe6a48206d5f9a1d23e6ad1cd8e2964Virustotal results 44.83% Heodo
2020-08-11Invoice M8431 72060762.docdoc d9d5afd0f83aa28a06f4a1b5dc642926301d0b9bb7cd9dc22dc75ef49fafa296Virustotal results 45.00% Heodo
2020-08-11INVOICEHYH6329049479217.docdoc 00c79cf67a9dad04c8c95c56c0ee755066e266c384f38f106cbcee90931e6cc7Virustotal results 44.26% Heodo
2020-08-11Invoice-M8334-2282228.docdoc ad8067bbc1e7e3ed6a24c8387fd0cfcc072810a1fe43e6cae9a1a46682f1dfeaVirustotal results 43.33% Heodo
2020-08-11Invoice-KHE9831-845424128.docdoc df9751edb6d3f6da4e475cc3b05844cb0833623d6e9f3d268a38611dd8bd15a3Virustotal results 42.11% Heodo
2020-08-11INVOICE-2-1160700.docdoc c1fc85d3b078b060a5335fd6ccf06322f2e7f97c39ff74defd85719891c024d2n/a Heodo
2020-08-10INVOICE600136920.docdoc 2ed80e234eddcbf09463cc2ef0009ebe173d3a21995aa99dbdbc3764bf9171f4Virustotal results 40.98% Heodo
2020-08-10invoice 78 9426587.docdoc f002170effbdfc2fab7095cea065193c7f70fc4c29f921dfc717667c10ca43cbVirustotal results 42.37% Heodo
2020-08-10InvoiceMP569645596917.docdoc 7b37dad9a66bb5d95cee541830a666771206d8b6b76558b8527e3be957ac25a3Virustotal results 40.98% Heodo
2020-08-10Invoice_430_894492116.docdoc b579309f5fc1facdee46bda7e5f729e9951897bdbbeb2c4804d66b67ce0fe64aVirustotal results 40.68% Heodo
2020-08-10invoice-WDK19-5490389.docdoc 9dee7b99229da39cdbc49e96e13a04cc9830de7c5049cf4b3da0ce59ce9caa35Virustotal results 40.68% Heodo
2020-08-10INVOICE6889525.docdoc baa5032273841510fc30e55fe98c2a295e6c5e0871282e755a8d51a41c553ea0n/a Heodo
2020-08-10InvoicePZJ61401955225.docdoc 751456e4b4b4735d253702ec7bff544209ebda45ccdfdeabb154ee501fd7552eVirustotal results 40.32% Heodo
2020-08-10INVOICEUPVM07321445.docdoc c4a2bae75c280e941ca37cd555c596ade2a07a15b03258f045f333b36c647e3aVirustotal results 41.67% Heodo
2020-08-10Invoice-SXS1-5286516.docdoc af0d5de2d7c042299a5923c3e41fcd47126cc3aef353aa3c5d690d4037af51fbVirustotal results 40.98% Heodo
2020-08-10INVOICE 291 715622.docdoc c3f9b36ddfe1ba36a2e5b01f8f3d08ca49a4b41a30df13f402eddb3436f14f79Virustotal results 40.98% Heodo
2020-08-10InvMQOA5599360585293.docdoc 7fea6c37955941f7d0e3376ac75f94cd3260ebabd7ab79af38066c4a823d5988Virustotal results 40.98% Heodo
2020-08-10Invoice-NQ3-279698.docdoc fed41332f44d68eaf298af68e820e28755d75934d375f489944912de15ffcc5fVirustotal results 42.37% Heodo
2020-08-10Inv-64-16888129.docdoc beee072969002550ae344d89f60fa2fbbeadbe74b97db6a20749b4471ab6f593n/a Heodo
2020-08-10INVOICE371003884.docdoc ca1d19eef36f5b2041a86e5970bb48cd29a172b7b07865692c22ce3ba7eea015Virustotal results 40.00% Heodo
2020-08-10invoice_ESBO01_742107722.docdoc 971af42bd7502e804b863eaa2ebf73d0b693e768e5e6a69ae39c40b73b50a76fVirustotal results 41.67% Heodo
2020-08-10INVOICE42364714.docdoc 4d9722695a297b0deafce38a38f1c8f9866d52cc0451601e9e11dfd5373a3518Virustotal results 41.94% Heodo
2020-08-10Inv TES65 7547550.docdoc d30e7862d95bcf570361724c50526a8e193c4c40b96c6aaba98e4cf3f1ded92aVirustotal results 42.37% Heodo
2020-08-10INVOICE_UB7_01928787.docdoc 837235f4d4509f8d6551f724d18d3a6c133038c7194abb3c65c7364ec33a4a31Virustotal results 40.98% Heodo
2020-08-10invoice_WVRI6350_999729.docdoc 66a1ed24065cfc0f8cf31971c9343ce681c584c27a6967a520bbf5df7fb59447Virustotal results 40.98% Heodo