URLhaus Database

You are currently viewing the URLhaus database entry for http://www.reifenquick.de/Scripts/closed_957176_mxqSdoJ6a4IZ/close_warehouse/ql55hnq09iyn6lm_334stxvw03wyv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:434592
URL: http://www.reifenquick.de/Scripts/closed_957176_mxqSdoJ6a4IZ/close_warehouse/ql55hnq09iyn6lm_334stxvw03wyv/
URL Status:flame Online (spreading malware for 5 years, 4 months, 0 days, 8 hours, 21 minutes)
Host: www.reifenquick.de
Date added:2020-08-17 12:33:13 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2024-12-20 07:37:53 UTC to abuse{at}dogado[dot]de)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19dat 2020_08_19 3434164.docdoc 9d634af91f6a53ac776bd53e7c54fedb5e03e4428401865df1774123fafa15a4Virustotal results 18.33%Heodo
2020-08-19doc-2020_08_19-RBN52731.docdoc a0096856f8887d5cdf7d5f2e6805694ac96da153aaaa326ef25ee058e6c6a683Virustotal results 45.00%Heodo
2020-08-19Mes 2020_08_19.docdoc 4d3b86d9dc87fa84b6283d3c9ef68a508bd41eb8f2930650cecf08f2ae86c2b3Virustotal results 47.46%Heodo
2020-08-19Dat-CY545133.docdoc b0d594dbc4a60fcc97adebefdff05022ee691b07bcab543e700f3a77dc6b09acVirustotal results 43.33%Heodo
2020-08-18FILE_20200819_35407.docdoc 12287b6d9db44cd05ddf4fffca8f6b8cf5eaa889f52305f163cc35bf1ac3ca19Virustotal results 45.76%Heodo
2020-08-18Mes_2020_08_19_VD43298.docdoc d4c93094a5cef205fe007277aced4f5459df2305374302c7651b93e5f77398c9Virustotal results 43.33%Heodo
2020-08-18INF 20200818 L94770.docdoc 81a254ffe9cc5094cfa32cac704d5273a94a9f9f8af621676853247eb6c92be3Virustotal results 44.07%Heodo
2020-08-18doc_20200818_2057.docdoc bdd85a761fef4dd714c4096940648eef52aebea82be3d8c91c0fb5842405f6cfVirustotal results 45.00%Heodo
2020-08-18Rep JWC803991.docdoc c2c31857eddef908bb15ebce07f54e91a068ffff5b92014fd70c1d5ce8f34cd6Virustotal results 40.00%Heodo
2020-08-18Rep G3618.docdoc 51ee6d64df2db865b1124f7a4e7f3e242733a95a11d118282baa2958ee901901Virustotal results 26.67%Heodo
2020-08-18Doc_2020_08_18_Q6234.docdoc debd3a132955964631f1657df3b8c9e598ab9345503d71edcee78234ba7c72acVirustotal results 22.03%Heodo
2020-08-18FILE-20200818.docdoc 77fbb539ddb2abc10dbbd056cd960899d723297cd2a680baba3a8f7180a2c59bVirustotal results 22.03%Heodo
2020-08-18rep-20200818-SYZ681978.docdoc e089c4398a29785bac5080386c2f2259d96ead27d5ebfeeddbf21754cbb635e4Virustotal results 20.34%Heodo
2020-08-18LIST-OE856.docdoc d5af23a4a20609570d4b1cdb956d22513915178d14f35d7fad5dfff86f25c664Virustotal results 45.00%Heodo
2020-08-18doc 20200818 BVY66123.docdoc e976f7e4de4c0bedc4e4bbc27752994f9110c050508b106611f035260551a8e0Virustotal results 43.10%Heodo
2020-08-17arc 2020_08_18 844191.docdoc e997b17d809b4d63590d7b7cca81318d3ecd18b59a46a4e83d88af6dfaeba54bVirustotal results 41.67% Heodo
2020-08-17File_2020_08_18_6557.docdoc 5f0f7cccdbe15b26ad3d18fe0dc9c31aba891cea529b65e56c7dda35fa776c0cVirustotal results 42.37%Heodo
2020-08-17Mes-9254.docdoc 2c9e7a8034c8beec56ee3f61e3e9f4ec9843f443d6df99c206d1840accdc102dVirustotal results 33.90%Heodo
2020-08-17doc 2020_08_17.docdoc 4e222c92dce7f604bdab06a48a8b26d08c4c3ff4e455795f8024e98823f1c13eVirustotal results 33.33%Heodo
2020-08-17Dat-2020_08_17-593002.docdoc a6f0cf28f723e60dd839983a85664defa478b6b54d9acb1f09bc7a4e98802254Virustotal results 25.86%Heodo
2020-08-17LIST 2020_08_17 5204.docdoc f270338465d313eb61ba96fff7969d855bdbd8f547a9eb71f5519e789d8ddcefVirustotal results 25.00%Heodo
2020-08-17MES JRM958779.docdoc 955c1f638a523a970bd12d1759116d5779837c871c77d308a1275129f7d3a53dVirustotal results 25.86%Heodo
2020-08-17dat_2020_08_17_6621528.docdoc df8740ae590def15c4443a1e068954d92bdf4035d39b8250481c07c02ae7c373Virustotal results 27.87%Heodo
2020-08-17List-20200817-PSE41444.docdoc 8a346d540cf74e5dd42aa37659347c7620b972f541ed167bf4ffe7cfcacfe5e5Virustotal results 23.33%Heodo
2020-08-17inf 20200817 IXH0303.docdoc ec67b496d2277674004e1f7a58cf236daa917a0dd4b5bce2f4bb63c00c54d306Virustotal results 23.21%Heodo
2020-08-17FILE 20200817 8179.docdoc 0ffc730b768c45ae0f359cbcfad987af88e15ac6e383857a2d42e7be17d01bf7Virustotal results 23.33%Heodo
2020-08-17REP 2020_08_17 1250899.docdoc ef5b00b9e8e333265ffc4db716209752d6fc5eeb82ca89f7d0643cae2b71e787Virustotal results 21.67%Heodo
2020-08-17list_20200817_Z91980.docdoc dd90e23dd04ffd1b25a1f18be7b336ee6480e86a8b8d187185828c99f7850167Virustotal results 22.81%Heodo
2020-08-17Doc-20200817-YNF4485.docdoc 4c285279481aa35b0feb4f494afe8d4ede33ab56699802a5706920e85f379c5en/aHeodo