URLhaus Database

You are currently viewing the URLhaus database entry for http://kraus-world.com/cgi-bin/https://Scan/XCAYn3HTTlOhg8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:451831
URL: http://kraus-world.com/cgi-bin/https://Scan/XCAYn3HTTlOhg8/
URL Status:Offline
Host: kraus-world.com
Date added:2020-09-02 18:34:03 UTC
Last online:2020-09-07 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-03 23:54:02 UTC to abuse{at}strato[dot]de)
Takedown time:3 days, 9 hours, 23 minutes Bad (down since 2020-09-07 09:17:46 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04OO877-2020_09_04-L20478.docdoc 6811ea887aa1fb0b0947ae4c101b1bccd01e6be62529652d9a9c70a8879485feVirustotal results 34.43%Heodo
2020-09-04dat 20200904 179.docdoc a49d6ff985f57e4d6e09893b343f97b9da664ae8c0b7c0e95f18f1a8f119f1a8n/a Heodo
2020-09-04mes-7009318.docdoc 113c8c78cdad0ed438501117f87ca9b0d52b672ddd8b015284541ded516827e6Virustotal results 35.00%Heodo
2020-09-04list_20200904_465.docdoc c9b3d60eb5016eb7958189110cbe77208b4099ca5f9f4b71d6170a263905e07bVirustotal results 35.00%Heodo
2020-09-04UNTITLED_2020_09_04_FY97182.docdoc 270c40ed02166b3f9687722a922082abd182688cb3cc27d4f0f27ff8af729b53n/aHeodo
2020-09-04Attachments-20200904-FFH8569.docdoc 3cbc74cc86834166223864b87a975cd733c121faa9d9119b74ab5d27c6a2c687Virustotal results 35.00%Heodo
2020-09-04Dat_2020_09_04_X896439.docdoc e4006ffd7617f48dca3ed5e7220e159de2160b07f86452e1fcb7fa0f27ed1d9an/aHeodo
2020-09-0433606108 8894.docdoc 5234c75f7c7319ead0ebe23478edfa5dc335ceea2205e3d61db96bf6c414e852n/aHeodo
2020-09-04inf_088.docdoc 0cac10e553ca0da14b7f6e1bf4c0586be92226b4edb922d9d7a79fd366142df8n/aHeodo
2020-09-04Rep 2020_09_04 ZQ4075.docdoc 00a7e0634054721fe9f4467f8843d3558c3694215da05f6027c8444786c55d21Virustotal results 35.00%Heodo
2020-09-04Arc 2020_09_04 682.docdoc 482e43557c2b67031f8b9141f11291ebb6d9fa946193ab1287ef2010ab18b462Virustotal results 26.67%Heodo
2020-09-04102-2020_09_04-09180.docdoc 20f0a0ba4cd0dac615e918dd489d36a9dbe9da8eccd28074379ccb9297f44202n/aHeodo
2020-09-04DAT_2020_09_04_WIA34352.docdoc ac6a5c2f72c10af857d73db327000d07f01f791fe6638c339362584fe1293a4fVirustotal results 28.81%Heodo
2020-09-04540734_2020_09_04_6448.docdoc be6a2393d8d58557a21737649e0977851d793862f1b80f1d27a1ee2ee70b3154Virustotal results 31.03%Heodo
2020-09-04Dat-1221.docdoc d7452abd23b4d0a252d67436bea5f98b177d6d4a707ce10ce71852940cf97a3cVirustotal results 28.33%Heodo
2020-09-0461504282 2020_09_04 1439673.docdoc 6fe4e70594d98f07fc43fc54e2e24a57ba80babf404b803336a8c7cca7f4bd70n/aHeodo
2020-09-04mes_2020_09_04_NR756.docdoc 533b65838696f229623a8367b9367b80001a7af8125899e324d550f4b4c64456n/aHeodo
2020-09-04Attachments-20200904-44284.docdoc ed63266e67ad9944d1501d2221c8390e1585ed5aed9397212441db07dea0b7e9n/aHeodo
2020-09-04LIST 99949.docdoc 3b8964cde0e41b835a06f77a2d1834dac132f78cdebaf8b6e89214daf39b8752n/aHeodo
2020-09-049765401_2020_09_04_38048.docdoc d6f3b5795079ed619a19ab306daac9d3fa4c20b2b54ee7e4ca872f334f92ba08Virustotal results 25.42%Heodo
2020-09-04rep_20200904_76392.docdoc 6ba1180f37e95dd4238a52435a56d2cb1483ed9a34af53b44e0fecd5863244ebn/aHeodo
2020-09-04Dat-2020_09_04-DTC51550.docdoc 52a1f3085fece2adb5e447183da5a37ab0c90019b2237702ce65ead6ba03cf96n/aHeodo
2020-09-04DAT 20200904 7346.docdoc f7347d7eb634ea2c2bdeb69d026c099ca12acf563a5b6681e6467ce9c7260619Virustotal results 21.67%Heodo
2020-09-04FILE-20200904-967.docdoc 5e01f376491f37354db3791f6ec1c53893e852d5874971655f2b8c0c9bfa35cdVirustotal results 20.34%Heodo
2020-09-04DAT_20200904.docdoc 50b57183a110a184c3028a10dfc67efbf04a18c1afe062e8ecf4b92694fbad23Virustotal results 26.67%Heodo
2020-09-04List_113076.docdoc feeb5bbd5f395644d93d971b4f704d098364e1ab526f6f0a8ce14d95e5be7a5eVirustotal results 25.00%Heodo
2020-09-04rep EX4178.docdoc 8c4a8a1c7d4ddbfd0b727a5f169b6bc78e7997fd2b0947299d663a215bb3a9d9Virustotal results 27.12%Heodo
2020-09-04MES-07727.docdoc 2ccde651fa61c7cd21ea8fde6ff8dbbd3945693f2e19a1ee1feebf25294199cfn/aHeodo
2020-09-04mes_BO41804.docdoc 24325dc08722e851f6637f34bd024e29a92a95a82f94fd5adf334df561dfd116Virustotal results 26.67%Heodo
2020-09-04Rep-20200904-QGT401.docdoc dd91e0f54696016ac33f44dbbabf15a089d0d2685b7e468529013e86c9522a99n/aHeodo
2020-09-04mes_2020_09_04_950150.docdoc 9da9e2af16844a3b0fc49e496b6a88773ebb122ac1471d654d696c4417c6c5d7Virustotal results 27.59%Heodo
2020-09-04Rep.docdoc e514ee40aaf58363f83b55c5bb9e01e591be5d5fbea0402363bfe659405e331aVirustotal results 25.00%Heodo
2020-09-04file-2020_09_04-50000.docdoc d597b6898060552b878e3f7860261baafee361a89d756cc2e56fe367a3aec042n/aHeodo
2020-09-04Arc_2020_09_04.docdoc 35eae4bf4a4e774e6e01de12b1358e0b431ba0b625952ca4b650849e31cfb1f8Virustotal results 23.33%Heodo
2020-09-04DAT_2020_09_04_W54864.docdoc bfc004f7ac8d0c2e241dc8086e3e58fb542fcc47b5114ab614fa893199328acfVirustotal results 23.73%Heodo
2020-09-04file_20200904_73489.docdoc bfa8973f2e13b6e793f43e4c1d1b68e81e7928903e0f8edf9fd3b146ee1cb9f1n/aHeodo
2020-09-04INF_2020_09_04_U5483.docdoc 12f0fe0be2051b0b2db3468b20798d7813c859384af5be7c18845165d1bc9240n/aHeodo
2020-09-04Untitled-XX40927.docdoc bbb72c4df6c036dd3b187c18c6ba7bf547ed934e658bdcd5d3c23d14d244c2eaVirustotal results 23.33%Heodo
2020-09-04list 20200904 ILY3175.docdoc 566612bbb46f6c6457676b10f1eada04c5385d9b4b7ddac7b97d6ba612793e8fVirustotal results 23.33%Heodo
2020-09-04DAT_2020_09_04_GWF5056.docdoc dd4feaa43e89898264a8512b2339c67fb1207b97e5c6c216fe656ff6234c0098n/aHeodo
2020-09-04UNTITLED-20200904-D7573.docdoc d38918707adc1b43963df18c7c3483e35cb906f58221fbe54adcbf770706feafVirustotal results 21.67%Heodo
2020-09-04Attachments-ZSJ8113.docdoc 2be118d48f3e89cf53df13c43a01cdea40d8ffc9ed68e343636386badff6200dVirustotal results 22.03%Heodo
2020-09-04rep-M088481.docdoc 4e3917d545fe670b0ea8dd1cf91701595c3cbe5ab87b5c53a826514778bad6f6Virustotal results 43.33%Heodo
2020-09-04FILE_20200904_VNR883.docdoc 44bd0a16a6f05906c4a20b9fdb23d798223e07db04cdbc4a4fb1adc219679627Virustotal results 41.67%Heodo
2020-09-04Inf-4824.docdoc 12faca932c77d851b530ebd1ee39f12e9c7b755904fb11fa61fd7acb92afdf62Virustotal results 40.68%Heodo
2020-09-04Inf_20200904_2755.docdoc 03cb9a738ad3ba7f5744d092532b2e578e9ade9b376af945fca5faf115b06c4bVirustotal results 40.68%Heodo
2020-09-04Dat_20200904_469.docdoc 0ff1c95a7d850d74903fb10610c4d99e54fd900d51cad0f2deda82e1122f403cVirustotal results 40.00%Heodo
2020-09-04048 2020_09_04 U87890.docdoc a7f7db7e743de3993fe73005b54d739c61d8b922446cf434ecedcca82c63e922Virustotal results 40.00%Heodo
2020-09-04INF-KR6852.docdoc 05558fbc6250f15d45880b5ebfb3798d415fad3e982b503fd6b61e658d902aaeVirustotal results 40.68%Heodo
2020-09-04Untitled_20200904_394.docdoc ede8d998dc31e2c855d01100bae27909e6fad8672e5bb1e7afced120b025c6a4n/aHeodo
2020-09-04Untitled 2020_09_04 ENW6194.docdoc 7f52e258980628fde30f218b911a2e930d0bb7245dbe6093e35eaf7e61c3e688Virustotal results 40.00%Heodo
2020-09-04Arc_4989890.docdoc 4808444c5d5d505fcdfe5814913d92dea2c41dbd68018cff2817cabd134441a6Virustotal results 41.67%Heodo
2020-09-0419360 8643.docdoc 9a9c96896e784dc4ac0ff44a3052d2ff2d7cb744fcf3255981f30894e95d6c42Virustotal results 40.00%Heodo
2020-09-04728_20200904.docdoc 352ed1583217d011b59331d9df7069fb05bffbee3823ffe2603a5cd74f16b850Virustotal results 41.38%Heodo
2020-09-04file-2020_09_04-248906.docdoc 90d7013803edb798ee2da7fcf3de07420ccd536dd01c96d0c787a80c0923f08dVirustotal results 40.00%Heodo
2020-09-04Inf-2020_09_04.docdoc 113f271d566b508aed976158e057211703fe30c314960665466fe58d9e08e50bVirustotal results 40.00%Heodo
2020-09-042613T 2020_09_04 OR514806.docdoc 2f40ae83dd7e6ea630b731213a7f9629565af65eca2bf9990d77114dc2b441e5Virustotal results 40.00%Heodo
2020-09-04file 20200904 76832.docdoc 3b921395ead4db8129425113780d7d7391058b9a70f1bfadaa36d56c48de30edVirustotal results 40.00%Heodo
2020-09-04file_DV245452.docdoc 595e8a24f2e5e51e56138296f7c6cd58e709e8f532dbacc38ae66f462e0e071dVirustotal results 40.00%Heodo
2020-09-04Dat.docdoc b0eafc0cd064f11cf1aaea20c1f55afc0770f81b4a59723d453b1ea6f6dd276cVirustotal results 41.67%Heodo
2020-09-04arc.docdoc eaab7e71c3da44a79d28d2bef0582eeadb430df7d20febba2eed46323d6dd3eeVirustotal results 40.00%Heodo
2020-09-04file_89072.docdoc 6300e903bf3720bb91e4db31ad186d98f0b8307f0abd3b785145f72f0a89edefVirustotal results 40.00%Heodo
2020-09-04List-KN79387.docdoc c9760ed3a6abb462e2d429280f83f0e912114c2b1923fa1fec74b3ee350afa78Virustotal results 40.98%Heodo
2020-09-04FILE-20200904-477.docdoc 0bed9ceb6c02ac01c38804705e397d72379abfba81c416c2deca29e08e32bd54Virustotal results 40.00%Heodo
2020-09-040481QIP 44394.docdoc 69e91274a22bb98b54013be9509ad757c17fd9ab44d80c5a8585ec639ea6f04bVirustotal results 40.68%Heodo
2020-09-04Rep 2020_09_04 XLS278.docdoc d6da8adc7df4680bdfe56aded8385d20e63b8af6ac83ff2abdccf2910232809bVirustotal results 40.00%Heodo
2020-09-0486210 20200904 HFT51063.docdoc 945f9c6c84eff86e098fcb02268e716fb80f5c6fa8a5e64e08175a306d3c0a2bVirustotal results 40.68%Heodo
2020-09-04inf LT983.docdoc 479a6416cfb665d2d0f0b6e39d11282a0d31d799d87898d50f066e8d564808f6Virustotal results 36.67%Heodo
2020-09-03inf_2020_09_04_1884.docdoc 62f2e2f1e282bf930eaf8a31d9904112fa33e4c5bcb2d14f0efc91df5351ae54Virustotal results 36.21%Heodo
2020-09-03Dat_071713.docdoc e16df740c6b4d003b00ff92bcecbffcee7c2b1beb17d9bdfe388f753ffeee9a3Virustotal results 30.51%Heodo
2020-09-03FILE_20200903_TZD85972.docdoc 10b9c4bca67ace9500467fe62f3f429c09793aad07493bb237def1c168c83000Virustotal results 30.00%Heodo
2020-09-02Arc-TCC837.docdoc 70e1c77b41f017bed49d2fe03acc7b6453a8eba17f25cfb64a6549f34bdbc7e9Virustotal results 24.14%Heodo