URLhaus Database

You are currently viewing the URLhaus database entry for http://wolfgang-brodte.de/3_jsb_1/eTrac/y40slyxjr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429816
URL: http://wolfgang-brodte.de/3_jsb_1/eTrac/y40slyxjr/
URL Status:Offline
Host: wolfgang-brodte.de
Date added:2020-08-12 01:00:34 UTC
Last online:2022-01-21 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-12 01:02:02 UTC to abuse{at}dogado[dot]de)
Takedown time:1 year, 5 month, 17 days, 6 hours, 36 minutes Bad (down since 2022-01-21 07:38:51 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14BAL_2309958139843854.docdoc d4fade764b1ae03f546843ff7b67176a1d7fca0c1cad66455d0770c364b5746eVirustotal results 36.67%Heodo
2020-08-13U_LC9841558472MX.docdoc 5eb176742446a3e0c9a403d44fbcdc29c1fb4cb7c445de80f174c40d5d096f06Virustotal results 36.67%Heodo
2020-08-13BAL_JVX_080120_RBP_081320.docdoc 1688c4e554ca89ab4e4da29beb1bc0bbd684b61e7aca912fdfa91f3c126728bbVirustotal results 35.00%Heodo
2020-08-13REP_1135640226536.docdoc 575f0ce42ff719dc940eb34657a8e1cafd665fc78c67e7ccd1b4916edfb1f3ebVirustotal results 32.76%Heodo
2020-08-13PUL_080120_QOB_081320.docdoc a10bbdb1aeaf73f5428667df09a171b10525dbe87b6b436d6f93ae27b8568ee5Virustotal results 28.81%Heodo
2020-08-13REP_IGX_080120_BXE_081320.docdoc 5fcf2cc702d0f6bdb1f1dd42dd253eac7bfdc46fdf859229401dab80dedef9aaVirustotal results 25.00%Heodo
2020-08-1342699283.docdoc afc9f012f8c62db57793319b9c54ccebd56180b6a542bca719b93156757c104bVirustotal results 26.67%Heodo
2020-08-13REP_YMB7EVN10QK.docdoc ff2d3e5bbe8b9cc5b8af05387071823a06c6269e9a7595efe0a597915db9ab1bVirustotal results 26.67%Heodo
2020-08-13XPV_080120_ZOO_081320.docdoc 2fd97df1c8ec35966fd5c4d28a87541a90fabc0fadf39b0b63320ac3120c9398Virustotal results 51.67%Heodo
2020-08-13BAL_IY0871257552KM.docdoc c934d43432962505a2f53b7950061889cfaf0d910a603793d8a5a814fe912471Virustotal results 49.15%Heodo
2020-08-12REP_MEPCT7L007.docdoc b09cdb8f91eb70d7f179d304a4585ab2b1867a160d9760ab236065aae029268dVirustotal results 50.82%Heodo
2020-08-1241794760469116.docdoc 77b30bd340e5190b08a7d94df99aa81a4aed0b89711a543fa9f87bb83fe3a72fVirustotal results 50.00%Heodo
2020-08-12REP_XZJ_080120_MHF_081320.docdoc 29c5831f071871eed50e5f9e8c02779dedc26d8d1b5485a57cef2f7dae79c9f0Virustotal results 48.33%Heodo
2020-08-12W_81432421.docdoc f19b16a6b70c8cb1df5f029983b5176588645914bead2d0b21292174bf7d0839Virustotal results 45.00%Heodo
2020-08-12PO_08122020EX.docdoc 271f020cac68ae52e90be9c31c915704b97ef831fde80481314067fe47bb1cdcVirustotal results 41.07%Heodo
2020-08-12FILE_RQE_080120_SDR_081220.docdoc 1b43dacaa3825888c4583607901a5fad687f60840690fa8dfb7b5ab72e28c27aVirustotal results 38.98%Heodo
2020-08-12INV_39143604.docdoc f7839e4820b80184243adc516719a06331ca2214d95f1f803b33f2884cc5cb22Virustotal results 28.33%Heodo
2020-08-12U_ZKP5M5JGEXDLX.docdoc 1f1a6a0dbefcc80a0303cdd5d9efc76784286fe3003a19b0e1ca9e0da6b7d030Virustotal results 29.51%Heodo
2020-08-1279202031.docdoc e4afa41303fdec9692da839c4697bc04c88e9488a1073b7ef03aea715b9b86f3Virustotal results 27.87%Heodo
2020-08-12G_KD3568018183IU.docdoc f3e65ce923f77dcb02b0c58ceba708791ca436bbc17560e262375f9c72fef49fVirustotal results 28.33%Heodo
2020-08-12INV_MZ3076942399AV.docdoc 0f87f594b33d4d92a3b56974f9073f6152c33ada49796983d355434e36b5bc71n/aHeodo
2020-08-12INV_2316084614.docdoc 158658167ef948705d54568c02e4901d9af0371490596d98384a1307dc6f7d72Virustotal results 27.87%Heodo
2020-08-12REP_NEQ_080120_QRF_081220.docdoc 025046a10693eb1c9dca8e64fa2dc55f1ba16ff9c6650493205e2c3af827e1dcVirustotal results 52.46%Heodo
2020-08-12FILE_G28XP6ENE8NEC.docdoc 358176ae69d49cbdc29ce5f8965efe9952253949970d9de4e8f09f46c488e6ecVirustotal results 50.85%Heodo