URLhaus Database

You are currently viewing the URLhaus database entry for https://koenigsmarck.de/blogs/Scan/lflwywmj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435255
URL: https://koenigsmarck.de/blogs/Scan/lflwywmj/
URL Status:Offline
Host: koenigsmarck.de
Date added:2020-08-17 23:19:38 UTC
Last online:2020-08-19 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-17 23:20:05 UTC to abuse{at}dogado[dot]de)
Takedown time:1 day, 5 hours, 29 minutes Poor (down since 2020-08-19 04:49:09 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-18REP_333760669.docdoc 6e7bc5b464486368fc64b81be80628536390d77832adc42ae658a9ec6642f2b4Virustotal results 45.90%Heodo
2020-08-18DOC_BYNCI7J5G.docdoc 6132d38c562ce3fd2f815bb85f961fe7be3153f058d6b86f366c69a51f65bbf8Virustotal results 42.37%Heodo
2020-08-18INV_39750137.docdoc 471800c07ff4f9683a7c7608227076df2dc2f4c484156617e374e766466333a8Virustotal results 37.93%Heodo
2020-08-18FILE_PO_08192020EX.docdoc 6cbbdaa0e24876ae422d284449759d09a5bba350158e7e489ae806620bebb00bVirustotal results 40.00%Heodo
2020-08-18SZP_IPP_080120_WBZ_081820.docdoc 460a8e4f639b96c10e0094ce3aceeb1f60278284a1d7b27e3b16fd4b76744636Virustotal results 40.98%Heodo
2020-08-1816ETLUS.docdoc 90d6be7c4d0d2a965dc5da2c72eaf35f6ab2795db8b4ae3939c32a16d3726157Virustotal results 38.98%Heodo
2020-08-1806129275.docdoc 1d236e06e4ac4c01b585f0f0a091e405aacf17ff62ecd1f84cbad48aed92fb04Virustotal results 21.67%Heodo
2020-08-18GESY_NPHO1JDK03S9WT.docdoc 92674d8d935ca49cbe4489ad9f6b55bb98697e74750d26bc138edd3c70f214b4Virustotal results 20.00%Heodo
2020-08-18X_D6PEDHDVGYTXZW.docdoc 7976a8188a5d793cdbb85eae76d2bf5dcd550789634815969fd953edefd06been/aHeodo
2020-08-18REP_OJG_080120_YSZ_081820.docdoc 8265ec213eaa6d222c57d0befde6281f1e53f7cbbc3e23df4b0b151921316accVirustotal results 45.00%Heodo
2020-08-18DOC_04868958.docdoc dccb23d76041147736f6f324b3ab4b5bf23db414b1b9aaef5b12da4033ef7f91Virustotal results 41.67%Heodo
2020-08-18FILE_MUJ_080120_ZBS_081820.docdoc 27c375a8f3878f06b0f95f14705dbf8400f42c0208bdbffc432c9fe9be231b7an/aHeodo
2020-08-18S_29641528.docdoc 4b2c463c130aa9358e9853fd7af4e476c3f9721168623f6befc47050979d936eVirustotal results 42.37%Heodo
2020-08-1863852423.docdoc 5b6530e4d580725b37bd1d03eeb44c472d0529b1422b830bebdc62bf8b6d0c83n/aHeodo
2020-08-18INV_80044878039297446255972.docdoc 5fd9d575a13678e66d43f02aa919121a34f26ff8ef42fd2b43a475f1e96a0188Virustotal results 40.98%Heodo
2020-08-1894762273.docdoc a9f2dfb969ec4a5c09edfdcf49a041eed112c8ef64c36610131b1ef17118292aVirustotal results 41.67%Heodo
2020-08-17FILE_58621920.docdoc 98c343c9a6bc0e1498638cbceb56365d8a033eb3443f2856a872d5a3253d5040Virustotal results 41.67%Heodo
2020-08-17CHV_080120_PFU_081820.docdoc 6cfd3bc71ff38c615ec9c2b54e9f7b2a878e5b34918ef26526b8d2695f04ba6eVirustotal results 42.62%Heodo
2020-08-17REP_O7M8DM2S0X69YK9.docdoc 8c3afbfc78b8936d04e1372b507046990c8f3a3d4dff80f59669660aa77fffa2Virustotal results 41.38%Heodo