URLhaus Database

You are currently viewing the URLhaus database entry for http://www.etechnik.co.at/administrator/VplQL50_YYXplTShSl_zone/external_352fi_Bd0mshDB3f/FOGG30y6FX_tf7zqJkk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432033
URL: http://www.etechnik.co.at/administrator/VplQL50_YYXplTShSl_zone/external_352fi_Bd0mshDB3f/FOGG30y6FX_tf7zqJkk/
URL Status:Offline
Host: www.etechnik.co.at
Date added:2020-08-13 15:06:22 UTC
Last online:2020-08-14 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-13 15:08:04 UTC to abuse{at}world4you[dot]com)
Takedown time:20 hours, 1 minutes Good (down since 2020-08-14 11:09:16 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14Arc_2020_08_14_981457.docdoc 6af630f2e8eba8699fb72196cd2a2dae2660d9ff10f3899585f70b8a99087838Virustotal results 23.33%Heodo
2020-08-14Doc_20200814_Q596.docdoc e4cbde8feb6610a41b2cc0d01559e7e22640769a0bfd305d097e4a966ce4b504Virustotal results 23.21%Heodo
2020-08-14INF 2020_08_14 WMW348175.docdoc f5b6e7cab4e6364d573ec7c97730ca0e84746b0fcd0b27dc2ecefa2615e8aae4Virustotal results 23.33%Heodo
2020-08-14rep_2020_08_14_H4714.docdoc 2e4a771ea2d138725a219bb3fd2f1a3d9a7461e0b6c57299989296a6084d234fVirustotal results 25.00%Heodo
2020-08-14arc 2020_08_14 4708134.docdoc 0a2dc95d0fbd8d2807c7a36ddc4f5584685be3dc2bdfeb3a1320fb5b93ec6719n/aHeodo
2020-08-14Dat-2020_08_14-QQ2207.docdoc 5b893ad0bb28ffb9c0e56be94c04c05ccd0d26b7abd8bf9b4a01a228df3b5677n/aHeodo
2020-08-14Dat-770.docdoc a2de797ad23c2211a80a0f83b3ee774fa17931ce941a60511d850b1ebd3e4aa1Virustotal results 24.14%Heodo
2020-08-14inf 2020_08_14 6761.docdoc 783a766ff6d8b06f0050f051c16b04cad1298697c81bbaeee5d8fcb014a60a29n/aHeodo
2020-08-14Doc 2020_08_14 BKS286321.docdoc eb8626c09f81f7723ee7afa0cf39e78db7be79b5e5522f82ed7c116eb5fae52fVirustotal results 37.29%Heodo
2020-08-14rep-I5413.docdoc 3dd12ed62a3b89ed3d384f1e58d1ec2ecc0901ef17ec4738002d9da80818e148Virustotal results 39.34%Heodo
2020-08-14DAT-20200814-REJ664362.docdoc 7a37b617ab9dfd1a2b7f090067cde1c83470fd44cd6090994090ac04638304b5Virustotal results 38.98%Heodo
2020-08-14Arc-2020_08_14.docdoc 750f4237628ffd460893c6534883f476f6d461970961beb9c1222b05b59d2c2cVirustotal results 37.70%Heodo
2020-08-14DAT 20200814.docdoc d878e7902f6d8430f7d19f1f9f548c280c1e3789ec3857a5d0c81c9ef2e6edb8Virustotal results 37.29%Heodo
2020-08-14Dat.docdoc fe72004e6a838fcb078f8b14b9e31e68d627ab0aefdf9bd24c5e9db91e96f4f9Virustotal results 36.67%Heodo
2020-08-14MES-20200814-U5820.docdoc 2465fb97adc0bcfd2852bc97bf6a929405c2b0c8abb85b57d294befdefbac099Virustotal results 35.59%Heodo
2020-08-14INF QG9719.docdoc be002af97ec2cdb43edc083f492340be1995195c05bcd860b3268acb96e2c539Virustotal results 35.59%Heodo
2020-08-14Mes_32781.docdoc a5aaa7a63b5ec81fdfe4916e720a21e4df252c2d3823d6558f0593cb1f4f65a3Virustotal results 36.07%Heodo
2020-08-14Dat 2020_08_14 CVK0964.docdoc efd285d45835c318c4e079fae4840399a89ae40bf6134dac6cef9e7483e9680cVirustotal results 36.07%Heodo
2020-08-14Inf-2020_08_14-ILL87911.docdoc 1c09a7e4afcf582fb0ae2170a0375571dcc9ae463e6c9f29770a590039704a44Virustotal results 36.07%Heodo
2020-08-14REP_M09322.docdoc 24cffd9cba643e90804ca8b7c8cfcc717ef8ae85ef64485427c51d320333baa2Virustotal results 36.07%Heodo
2020-08-13DAT-20200814-LK19988.docdoc 96fbcc6247407284134b11eb29a5cb2dd6c00fdb5f500c58b19be4822cd412c0Virustotal results 35.00% Heodo
2020-08-13REP.docdoc d362ed42b7e6383ec272a65b42e23fa00585b6e65640d3e31552777ea6e1e06fVirustotal results 35.00%Heodo
2020-08-13rep_D763.docdoc aa253dd86d00217ef0405e1632fe822af17023b8277078b08be3ecdae72d78daVirustotal results 35.00%Heodo
2020-08-13DAT 20200814 AMZ664419.docdoc faca9557e0e2d11bc5ddfe5cfe01d56b2cf10391636d75a751252ebd059ca753n/aHeodo
2020-08-13DAT-4874.docdoc a9f31f864a6aac450ff2fd5887783360d6bb87da12d94b456119e218f2b99e9bVirustotal results 36.07%Heodo
2020-08-13Mes 96069.docdoc 237d41ad18ee2be761351529e741234effc07815fe555c28df34b8ba3a531f20Virustotal results 36.67% Heodo
2020-08-13MES-2020_08_13-616.docdoc ef8a7ad093c46e235cebedb204846c09c5024e5cb2c8bb81750d2e5007323c1an/aHeodo
2020-08-13mes 20200813 QV289.docdoc 5bb4b84296ec60184ea017e657bcea6f6d3acaa986abdfd64cecbbd4ee027731Virustotal results 37.29%Heodo
2020-08-13mes_A144668.docdoc 147c789ee92535626bf97593edc4cba8eb038bbe791b789dcd5b3bd764422ab3Virustotal results 36.07%Heodo
2020-08-13ARC_20200813_B544.docdoc 46927454721c5e3fd90b2fee4870ce3ed1164f837680278f19478136a5480023Virustotal results 33.33%Heodo
2020-08-13inf_20200813_1590.docdoc bc3aa97485e4bbecd952323d02d50454d068b495627ba1c321823455b2851de3n/aHeodo
2020-08-13inf_20200813_1590.docdoc bc3aa97485e4bbecd952323d02d50454d068b495627ba1c321823455b2851de3n/aHeodo
2020-08-13Inf_KBJ412223.docdoc f4ec266b14464dadad86630e4f028e4e59dd7e7b806925e1ea65fa9e277abf11Virustotal results 35.00%Heodo
2020-08-13inf YS655494.docdoc 502df3593c8baaf12f4fe79b927203836c872f0b7d6f11b7084cca840dc05255n/aHeodo
2020-08-13File 20200813.docdoc fdf01790e32780da83434ba20976bbb51b54fadee6bb76b399dac783936926a2n/aHeodo
2020-08-13List LJ0818.docdoc 92ef252d93dc57fe3b08c5ae7b0d8a6054d85e3b6f378af68a5c184099aa75e5Virustotal results 28.81%Heodo
2020-08-13dat 902.docdoc f3a8e7b9b6078f48976580a7ae7ea2e3ffb077b9d68285f6ec7de8e3972a9d92n/aHeodo
2020-08-13Inf_OFX298786.docdoc e946007ca584996c15a16e621741968ac65868ef3d76a451669f37f0d0be1d8fn/aHeodo
2020-08-13FILE 20200813 CHZ095.docdoc f67568f08758378dc851f5550899115ef41b18c6a7e92facb84fd0a33a2af287n/aHeodo