URLhaus Database

You are currently viewing the URLhaus database entry for http://stefan-els.de/cgi-bin/attach/GxmkA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:451952
URL: http://stefan-els.de/cgi-bin/attach/GxmkA/
URL Status:Offline
Host: stefan-els.de
Date added:2020-09-02 21:39:38 UTC
Last online:2020-09-03 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 08:42:54 UTC to abuse{at}strato[dot]de)
Takedown time:2 hours, 9 minutes Good (down since 2020-09-03 10:52:15 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03jH7.exeexe d87366a3c21d3cc452c0315a07c2fb87c985dccdbae2316ba42ff0bbced4b769Virustotal results 17.65%Heodo
2020-09-0376905565325AUvoEZ.exeexe 6922f6a1adc40640599928c43e6f3222f48662b9f44e7936ae913ca3eaeb3111n/a Heodo
2020-09-03036179472.exeexe b158373b5086b5ae0e4d5878331166af485115c67a0c967d388c46f0f0bae1edn/a Heodo
2020-09-037K2ZwP42329519398.exeexe 678e885e7c8838415d5973cb76b7d441b80d3447fd4834fa67f97af4f2eec46dn/a Heodo
2020-09-030000141415379322.exeexe 877ac42c0253b8f84c29214e82e26bd89a2a6bb4ce22543d43cbd2f63d3f8d68n/a Heodo
2020-09-03009950586257.exeexe 5adf66d74f7c4236818bf69f75ce123f7d5c64a7037364dac22b2a48e8f4f261n/a Heodo
2020-09-03000069724.exeexe e2541a8ea6db16dda988e75e7c34278a2da30d74caf4df7416392abc6ea57951n/a Heodo
2020-09-03sLk.exeexe 3cc25dab5de6544f6578a1f1976edacaf291db9d76773f8a61a216f6d9655833Virustotal results 10.14% Heodo
2020-09-03000539242977cDLQRiu0j5V.exeexe f99f93140cba2327b6bfc365085bea95ba24108ab5c5fc492b5f4fa8d3a02dd3n/a Heodo
2020-09-034wFTffc9wN00794567128765.exeexe 97ca32857e6856c2c7f55dbf1b428b444e04bf5ba8aacd0e96b97abed36be921n/a Heodo
2020-09-03ltq.exeexe 25d22776a454737d711ff1d104442f849de77abfe91001ebf98605933115cad7n/a Heodo
2020-09-03qtyj9caObX1831320257052.exeexe a4705750dcbab3894198372099b222d0da1df30e8b9137cb9608066c9f446819n/a Heodo
2020-09-035322144416115vv.exeexe b9b587a2c3e10bea51847dbd5bf34f9ebb928a07f1217d2b30ded2a374ddf134Virustotal results 10.14% Heodo
2020-09-0300529224.exeexe e2da5b71cf953ae3bb4ea061c02118ddb04397924cfd7c746f801aa64dd7702fn/a Heodo
2020-09-03pGY0ucWo0L000056590650.exeexe f24d2ef4c86a57733373be5972dcd2cdf6ef7062c28a8c2473ae1e72512c2d27n/a Heodo
2020-09-03PO796066871316.exeexe c7391712a56b16dc6b03db880bfa01184e134bf6b83107131c0f044ef2a08465Virustotal results 10.00% Heodo
2020-09-0304.exeexe b8a86b765f814f95df830cfb1e4ce4fe726b3597cbac8c4db38426484e8c2e7dn/a Heodo
2020-09-03gA7hRAxOx1W.exeexe e36083a7b4bed8b4ef8f350a6e3d30996a9c09fe2b14a46e126a9ed812e37288n/a Heodo
2020-09-03qlL73.exeexe bd3eac1c9ebb8b70317cfb177a8093146873a0e4fd205c7c554c91d83525d8c9n/a Heodo
2020-09-03BWrwo.exeexe 89755216eea650ad68fbd0d099bba826c3e0ce58c8b84f1e613e5a58c4ee8ea8n/aHeodo
2020-09-03MM80000410079980.exeexe b4b8ad51f0ecd1e0dc84bedac3615efa959603c030f74e770e2cc4c6e3545e55Virustotal results 33.82% Heodo
2020-09-03o3SZ.exeexe e850ee78038edc6ec6ad27b58cfa6777d93ab550d6afc7d3bba91cca412253c0Virustotal results 34.29% Heodo
2020-09-03sLaZHasOlBH000412545440.exeexe fa9803abb6315c37014d60438d130a3d34b02bab84a8e3983e934dcd74a48b4an/a Heodo
2020-09-037t7q1C6.exeexe b014b98b2694028a6c42af260ef4992eec4ec7a3d51a4ce4814603fbb3e04f02n/a Heodo
2020-09-03e58y245018245223.exeexe 8bea249759bb64923034bb8d8bb9b9bb3f9f0d121515dd86e6df5e707fcc122cVirustotal results 33.33% Heodo
2020-09-03855960594492Z6PjSZNkD0.exeexe 55841a722d23a6daae8e29be4ac1c56c33437c9fe38f11fcae20dc41957f7292n/a Heodo
2020-09-0396MAoMr3pIK.exeexe c4240b3f237807ac221c4b1595ee38922141538014b27671fc9d1e6dad13def4n/a Heodo
2020-09-03ROf.exeexe dea31242ede71fbf80ec10f48932c773b90b86d0a5b51beb41e940c8bb1847f0n/a Heodo
2020-09-036ONv4yx7Fw261969826.exeexe 97005b67fb9bee65990a4802844d9b20c658b107068ea9121a0ed7cdabd82ad4n/a Heodo
2020-09-0300008pT.exeexe 53e0e35d233753ed05db2e0fa7140c582cbf23e4540fafd7966914ccebd4b7b8Virustotal results 31.43% Heodo
2020-09-03000071.exeexe 2dacc9fb493e5225f7aa09d9dd41daf8c3e93b069c3322a8bdc245ebad05070eVirustotal results 30.43% Heodo
2020-09-0300367062JEm4.exeexe 4fdc54d9a159e830d05b2b585af06d64982b945b1d102a331e2f6aa714a44ffan/a Heodo
2020-09-03024.exeexe d823e30d0d0dd9327077475f6231452b2f7aac7acbdc95ad52b1f5a6a3438d88n/a Heodo
2020-09-0300284688685.exeexe 1448b7dc25a62aab3e05f3eb716ab7723b382beb6702eb8407359e90732027c5n/a Heodo
2020-09-03rr59759537049.exeexe 7d8bfa17fa0b9a45f1e7198fc71baddf2dafef9b352e6d45daca3a163f7dee2cVirustotal results 28.99% Heodo
2020-09-03UwwS9tN.exeexe d22c1fea1b411eb4f8c92ba020186527b28881bf901f44f1e26c0fcdf47a5ce7Virustotal results 28.99% Heodo
2020-09-03000086128041415.exeexe 69031c514464a2d2b0040fcf428e9995b1fd9ca056b4286ea0d6bb1fa83377c0n/a Heodo
2020-09-03002943325365972xjUFtKUz.exeexe 69e2818d7adab8a4f4b9de94db7bebb898a4d0aa176d4be5eec0770570325f61n/a Heodo
2020-09-02000060760672ZWocF2hOQcq.exeexe ac581db458dad160f81ac43b0ab27dc6445cf411c3d1cad0a0397198d8ba2c07Virustotal results 30.88% Heodo
2020-09-020093241.exeexe 988b7c3918a42d8a86f58ddc4332750bfaf80f7dedb4ad3a8a7f62018215f38fVirustotal results 29.41% Heodo
2020-09-02AlVZZ1.exeexe 3324faa9d649b375a8808b69095606a3e5d1ce1514cfa86ea715e3a7fcaa5d0aVirustotal results 27.54% Heodo
2020-09-026727262673.exeexe 4a74e8f1dfa65a658da5a5ccffd32cc9c98e6e3554310f0396720b9a044b1ee6n/a Heodo
2020-09-027icO2531868573365.exeexe db9718eaf0dfd9ba194b9eb008474672ed306ebb9530c67b7a7504724fb8b149Virustotal results 27.54% Heodo
2020-09-02V1EpQ1245110815.exeexe 73556ce84f1d35b2ecb9c4939ff13fde209cc45415173f07cb7b6853ff85111aVirustotal results 26.09% Heodo
2020-09-0200037210.exeexe 6a1da6a5706b1f765213e5ab953dc0660182779020292504ac6e8a25a5e7786fn/a Heodo
2020-09-02Vdd0002491106.exeexe 36a1192578ed59bd36231b348605f893af68eb5cbedf38320f51e6e32fe845a1n/a Heodo
2020-09-02000203701378iIfE.exeexe 1543c372390667f06577153eec5bde38d515d0230562209bc46fffa7752b5d8fn/a Heodo