URLhaus Database

You are currently viewing the URLhaus database entry for http://www.reifenquick.de/Scripts/statement/ul397wfyb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:436727
URL: http://www.reifenquick.de/Scripts/statement/ul397wfyb/
URL Status:flame Online (spreading malware for 5 years, 3 months, 27 days, 11 hours, 31 minutes)
Host: www.reifenquick.de
Date added:2020-08-19 17:16:10 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (phishing)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2024-12-20 07:37:53 UTC to abuse{at}dogado[dot]de)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21BAL_94G1BA0C0.docdoc f81e4de8069e9551180db92af779f1c19f7bfef0dde8f9696ae0b242d3fb8f2dVirustotal results 25.86%Heodo
2020-08-21D_PO_08212020EX.docdoc b9867ead986e6afb8337409a0b509cac26e3d383deb83f38f1cfcde8eaf3ab01Virustotal results 22.81%Heodo
2020-08-21REP_47382437.docdoc eb855bb87c7f169f8aaa2bfd0ba1d2866f6098815ac1e5b58bdf85e0b264cfd9Virustotal results 20.34%Heodo
2020-08-21REP_RMA_080120_SWL_082120.docdoc d3e288e78e76e10c2214ea9589c989760fc693bb097650669c7f37b9332698c5Virustotal results 20.34%Heodo
2020-08-21JZ2132423653KY.docdoc a99bc78979b657a1d16c9c3cb64ddfbd2d0317097210ad0dd85088b7a6c1b3ceVirustotal results 31.03%Heodo
2020-08-20UHY_DHH_080120_UGW_082120.docdoc d450de331053e84b06f103ae247fdd8ad2af1cb161c3fd94262071d22e1ed2eaVirustotal results 30.51%Heodo
2020-08-20FILE_53040140900885794.docdoc ea9a29f42ce90bd0cc4aa2b4758dc76ce4a5d639dcbe1ee8f4f0b61632793577Virustotal results 30.00%Heodo
2020-08-20FILE_EL5763669509KJ.docdoc 172af56801cf4f253a30974aeeddb1910408d1417b4d8bffbefe887436c3b633Virustotal results 35.00%Heodo
2020-08-20PO_08202020EX.docdoc 4685f60dcdfb132f5246b79cc2e4f5c0748fc9ef73f54c0f104bbda17ad7b1eeVirustotal results 25.00%Heodo
2020-08-20TBU_XVM_080120_QCO_082020.docdoc 63e9e5abc6b0d9e61f8f83baae44d5028c4c9ebe62e0ee337e3313c1e83841f4Virustotal results 20.00%Heodo
2020-08-20NKI8VH2WPAS9QWO.docdoc 3199024c14912493d637c88ae08b8050bdf85ea6356730c1117850e130d1669aVirustotal results 18.03% Heodo
2020-08-20QEZU_00502082.docdoc bbfbe727d8a5b53456c3b234d64899d7789a885517c719fb9c26c890e009318aVirustotal results 41.67%Heodo
2020-08-20FILE_6794565581804.docdoc 3adba5d0d3b9f8425b3f663d9a4e49ea5d5effd605916f354e932e1fae4486e4Virustotal results 41.67%Heodo
2020-08-19INV_0162098998.docdoc 7e5b76a38e43b23ba86cbd7ce11677e2b6cc5c68fe8566a623bfeff47be9c512Virustotal results 33.33%Heodo
2020-08-19C5JTX12NN93V.docdoc 36a290d9df91c6881e6f23de7e03e02206ef7ca2d8aac9d585308806b6e2b965n/aHeodo
2020-08-19S21H4A99A.docdoc 7f3f68fc29feddc0494e2e4853b7454b5d0cceeabe5e0bcd13029c5ec301e9c6n/aHeodo
2020-08-19BAL_CB6874692469ES.docdoc a882484dd319c7363eab50da170eaf45d0be854d4208c86d3d9fa00621f2f9d9n/aHeodo
2020-08-19S_8F0N9C7PHWF.docdoc 39f8850f02b807a843447f461d3436d67191f0f08709c03d32958988964b5e9fn/aHeodo
2020-08-19BAL_23104189609620588991.docdoc d6d6d04fedae2537ae4cacad5ce33a5b5d5964d22f97c381def52cac01666902Virustotal results 22.03%Heodo
2020-08-19BAL_12141056.docdoc d9d8ec245eab78761795bfab0930cb5dd903e1157eec18a517b867e004191413Virustotal results 18.33%Heodo
2020-08-19REP_PO_08192020EX.docdoc 77834d629af8b45f85ec232e03fab3cf97e78e448b23fe48bc93ad6a391f3c90n/aHeodo
2020-08-196IZKLJU.docdoc a47b7f6d9af6602b2dac196cb0faf5414e8a3d7f94604f937e2e66f19fd17b61n/aHeodo