URLhaus Database

You are currently viewing the URLhaus database entry for http://ultimate-24.de/logon/common_309164691697_XwyCmGu8xWHReZw/test_portal/vivyywa_46358/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429774
URL: http://ultimate-24.de/logon/common_309164691697_XwyCmGu8xWHReZw/test_portal/vivyywa_46358/
URL Status:Offline
Host: ultimate-24.de
Date added:2020-08-11 23:25:35 UTC
Last online:2022-03-22 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-11 23:26:03 UTC to abuse{at}dogado[dot]de)
Takedown time:1 year, 7 month, 17 days, 20 hours, 14 minutes Bad (down since 2022-03-22 19:40:26 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13List 2020_08_14 FUY154.docdoc 49bec245edf7c3ddaaa75cf115aa3fecafa8e263ddf50c8370239411e00de596Virustotal results 37.29%Heodo
2020-08-13Rep_01064.docdoc 96171866f817967e4fea70064e3c1521651d2c1102b254aaa2d655e1a5f7b1f6Virustotal results 33.33%Heodo
2020-08-13inf 2020_08_13 O71597.docdoc ee74aec4dd2a3d709923eb45510d6a2e75a83c4c86e2fc4ef03b99240975d1c4Virustotal results 31.67%Heodo
2020-08-13REP.docdoc 1aacda32cfc9842059b8027e3c060e0618f4d53d17e35bf2e46ed4508bf68098Virustotal results 30.00%Heodo
2020-08-13Inf-2138817.docdoc 764307084ac62f0f93eb1af151418ca65b0a225868b196247e1cd6f04cb740a1Virustotal results 28.33%Heodo
2020-08-13Inf-2020_08_13-UWE090574.docdoc 646c649d5a2f5ce95b1786afce717859e792a5ef3aae5b5ddd382874755e6350Virustotal results 26.67%Heodo
2020-08-13Mes BRK060254.docdoc e9cb882590b439f538e076ca9eb7a270735d50b940661f17932d4fb75693f536Virustotal results 26.67%Heodo
2020-08-13mes_WB2777.docdoc 57fcedf7b710607daf3ff9d1d3f81b02e5597d6a760e10c3af3805702f2e2ec5Virustotal results 51.67%Heodo
2020-08-13inf 2020_08_13 5597.docdoc 0453fae20f8759d4b93663ba58ad3a923f868ba094decd801c43eb9d270f3d8aVirustotal results 50.00%Heodo
2020-08-12ARC_QCA863.docdoc 508b0f1d8e5ede23aa2da775ab08b29c3be1fea89e1d2646c00c0b3c3570af5bVirustotal results 50.00%Heodo
2020-08-12Doc-2020_08_13-BS94667.docdoc 986acc515daf31c8bd8d424f27e1307eab1f51a043c896ffeb2cd94df1eed8a1Virustotal results 49.15%Heodo
2020-08-12list-4599.docdoc 821518f4bc7fe660a254118cf984e5166801904f39769314d230bdd98e69ae6cVirustotal results 47.54%Heodo
2020-08-12Doc-2020_08_12-IN4305.docdoc 9a747b94af3b1fd16e015c6dcb20adb1517dcfd21e7ba2886ebf39d2c0cc7a94Virustotal results 41.67%Heodo
2020-08-12DAT_730996.docdoc 19a0b43438b15957a52c653d27778c90008ae27821fe97db817356de978f063fVirustotal results 37.93%Heodo
2020-08-12Dat-20200812-823890.docdoc a5ce7c141cf42b88969840733ad4c75043727f228bc874f55788fe4d8ea17039Virustotal results 40.00%Heodo
2020-08-12ARC 2020_08_12 VN6270.docdoc 5ea80c59d4629ef6a11ef42c5a585fc6c263cd78ce8876440df9193182199ef6Virustotal results 30.00%Heodo
2020-08-12DAT-20200812.docdoc b4bf6e6e6eccfbddd61630876d0209894b69e9b122939c029d31b8b8b627d478Virustotal results 28.81%Heodo
2020-08-12Arc_20200812_22386.docdoc e43bee7af8123de382fd32886e7ddd9a114de8c6d4276b848d35ebdcfb049564Virustotal results 28.81%Heodo
2020-08-12dat.docdoc c3c294923b097cfe13d18c61ec3f8862ad52e37a5f0e416399f16db51af7de25Virustotal results 28.81%Heodo
2020-08-12arc_2020_08_12_6235.docdoc e9e73551b173018c97ccd712ad5590dad7d9a180b3a4d70750d5c56ce4ad282bVirustotal results 28.33%Heodo
2020-08-12Doc-20200812-C48041.docdoc 08e063ffd684f75a775f7dc074dc7ff0c06ed18b48ac1c1caaf8adb80363b9cdVirustotal results 51.67%Heodo
2020-08-11LIST_2020_08_12_86451.docdoc d91d2770d960e452517e8429c80a8149a8712d7fe90609b16b869379189cb8dbVirustotal results 49.15%Heodo