URLhaus Database

You are currently viewing the URLhaus database entry for http://lagershop.rs/cgi-bin/statement/d0ysm1r/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431173
URL: http://lagershop.rs/cgi-bin/statement/d0ysm1r/
URL Status:Offline
Host: lagershop.rs
Date added:2020-08-12 17:46:08 UTC
Last online:2020-08-13 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-12 17:48:03 UTC to abuse{at}hetzner[dot]de)
Takedown time:19 hours, 0 minutes Good (down since 2020-08-13 12:48:06 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-133041644220.docdoc 430d07c2162af45022115ce4b557ab182afc95143b698568d50c41832c6b281bVirustotal results 29.51%Heodo
2020-08-13W_31382347.docdoc 5b2909f926cbc0853f5384da19ca46d5b9d49877e6d7ad354fc11906ed3d527bVirustotal results 26.67%Heodo
2020-08-1351430696.docdoc 0c4015de45653ee2f8fc6e338461a2377e14139b1ff879df5a2fe1d3c200a15eVirustotal results 28.33%Heodo
2020-08-13K_30230108.docdoc 33dcad34dd7bf732f89c6d54880f01b2f952fd6f08f89062109af185e73d0e22Virustotal results 27.12%Heodo
2020-08-13GCDKV8KON449W.docdoc f1194d491ba7c0f8f39b1c0b9d47c4324742b324adc2e4a3feba13f77e9b40feVirustotal results 27.87%Heodo
2020-08-13DN9079630685SH.docdoc 1a457779d9b645e40120f23efa5aef5b0b97308f610fea5a06377c0603636f98Virustotal results 25.00%Heodo
2020-08-13FILE_2166609236858407505.docdoc 0652c184cccfd772644a2b72467b93f57ee93b1095894cc08ab3a9d9470fbac9Virustotal results 26.67%Heodo
2020-08-13LQS_080120_RRY_081320.docdoc e1bf8d2efe529d4cbe16fa5c6f747b604e88d6ffbeec9742a7617aa8617a9133Virustotal results 26.67%Heodo
2020-08-13M_WXL_080120_GWF_081320.docdoc c5a0eac9aaeb84217b16d894a11fc533d9125f2c70cecb67dfd600b798295e1cn/aHeodo
2020-08-13DOC_PO_08132020EX.docdoc 9806f54f8d2769646e6a9caee3f1c15a1b47f781be6eef64c390d6e9ee867bd4Virustotal results 26.67%Heodo
2020-08-13W_PO_08132020EX.docdoc a99686e4cf6cd2b9bfb9973bae227ceb986133378afa5f42d324a4879f4ef6ceVirustotal results 27.87%Heodo
2020-08-13DOC_EHO_080120_JMQ_081320.docdoc ba510b5a0f97430a09efbd12acbb4c1be869e71e678adf5fa0b5498fb477068eVirustotal results 28.33%Heodo
2020-08-1364347731.docdoc 6550fdf4a650ec2917c0b2fc6c67f8c51beff7636703f7730b0da66be006d78cVirustotal results 53.33%Heodo
2020-08-13NN4467902810BM.docdoc 5ec2a412f6729dbbd84453b84c85ac56f93e865a1900eb514efedefedc56467fVirustotal results 50.82%Heodo
2020-08-1240701711.docdoc a9af06ae735677ec282b4a66f7bc85a343dc7c71491658673fed6150e05ef3c5Virustotal results 50.85%Heodo
2020-08-12493332252075390.docdoc d0ecee1cad0e97af4b127dc23861ffbee329ef4a465840447b48e554801e6081n/aHeodo
2020-08-12DOC_SNF_080120_BRI_081320.docdoc 77b30bd340e5190b08a7d94df99aa81a4aed0b89711a543fa9f87bb83fe3a72fVirustotal results 50.00%Heodo
2020-08-12UWG_080120_XFH_081320.docdoc 29c5831f071871eed50e5f9e8c02779dedc26d8d1b5485a57cef2f7dae79c9f0Virustotal results 50.00%Heodo
2020-08-12O5I9J8HNE.docdoc cfec1c4aeca2bf10496b8ae3be0b77a9dfade44f1503c09398114731db0e92b5n/aHeodo
2020-08-12DOC_86587292.docdoc 44d9b68f5aefc2eef02bbb78ffdd24d10ff0097705b179cd623a8833dc64ff89n/aHeodo
2020-08-12B_QYR_080120_YUK_081220.docdoc 81b56737e0ebf1766ee14ae1a7c022da0208f91ddbae7d06bee3cefbbf3b01a1Virustotal results 48.33%Heodo
2020-08-12QDFJ_9RO6K46YVKTI.docdoc 86a7080b18d0d16fd7b1505799c006382ff034fb5dbb65b0e933ab56cee84215n/aHeodo
2020-08-12U_A0ECFNK6Z3LXV1.docdoc 42784e0de01af05a046c1361a8e58eeb1d7eb88b72badd646658090e49a54939n/aHeodo
2020-08-12DOC_MSD_080120_VSU_081220.docdoc f19b16a6b70c8cb1df5f029983b5176588645914bead2d0b21292174bf7d0839Virustotal results 45.00%Heodo
2020-08-12REP_DB6745951579UU.docdoc 97feccf3c91f6d0275ecafdf2bb2d3a869dbd30f1ed7e87db533ac6a63678fb5n/aHeodo
2020-08-12FILE_MD5307768373IL.docdoc 000aead7b794677467a325c4ce004ee4411f2217ed69454545202dc9577191f9n/aHeodo