URLhaus Database

You are currently viewing the URLhaus database entry for http://www.reifenquick.de/Scripts/FILE/21mnqlvi/oz88535657v7rbazasyth9x8i/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:438705
URL: http://www.reifenquick.de/Scripts/FILE/21mnqlvi/oz88535657v7rbazasyth9x8i/
URL Status:flame Online (spreading malware for 5 years, 3 months, 25 days, 16 hours, 8 minutes)
Host: www.reifenquick.de
Date added:2020-08-21 21:18:03 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (phishing)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2024-12-20 07:37:53 UTC to abuse{at}dogado[dot]de)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-23PO_08232020EX.docdoc 493fbab43b8eaf0772394866842fa9474e8e54a84894498828af06590dff1cbdVirustotal results 59.65%Heodo
2020-08-22PO_08222020EX.docdoc 7b5a4402e1296a43956cac33f381c600ff43f8155971e52a214765138128cb08n/aHeodo
2020-08-22DOC_EY3423382177TK.docdoc 875e8c26386ff1c0c8b3678d2bb054d0883fa0eea3868af7f150390cb0ba6577n/aHeodo
2020-08-2206966999082841.docdoc d22cd591ca782f3baf0951d51ef1240685529fa34c5600b9fd14b3a9f81a6ff4Virustotal results 49.15%Heodo
2020-08-22DOC_BZ7613358413IK.docdoc b827ea89c0285f491b5d81e3db08938e1c2c1bca8c6187af15debc415b8ee65dVirustotal results 48.28%Heodo
2020-08-22REP_CY6630892060HJ.docdoc 9d28728ad9b834f59079daf4cb54603a868e3909eccb6ba13e229901a40103c6Virustotal results 32.76%Heodo
2020-08-22FILE_24247541.docdoc 0759e5c471a2092742d96de880d1e5b939fa7fc1bbd839fc5a6f40c79067c24cVirustotal results 32.76%Heodo
2020-08-22P_599636064516009989010.docdoc 845169ecadd97b50576fed0fca204646844a511794662c22fdce0cadc58219b4Virustotal results 32.76%Heodo
2020-08-21FILE_BAI_080120_GRT_082220.docdoc d2d51f795c49460721c9f2c02517db60a6a0739c5121a8b262675fd7070cc0a6Virustotal results 34.48%Heodo
2020-08-21REP_ZIZ_080120_OFU_082220.docdoc 6323c7b4ec8783e51f631813adf56905ab2c875fd1c8f94f58f7b2f98ed037f7n/aHeodo
2020-08-21FILE_61680168445749513253624.docdoc 860c5f447f202c55885fc12b01dae4464cb7a2813113a03099954d6e2487f437n/aHeodo
2020-08-21P_PO_08222020EX.docdoc 7bce0d97de6cec75813a540c08e2d525272f48d346ed73c9c776125fbe166cb4n/aHeodo