URLhaus Database

You are currently viewing the URLhaus database entry for http://christoph-oberhoff.de/cgi-bin/attach/xFf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452064
URL: http://christoph-oberhoff.de/cgi-bin/attach/xFf/
URL Status:Offline
Host: christoph-oberhoff.de
Date added:2020-09-03 02:00:07 UTC
Last online:2020-09-11 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 08:43:07 UTC to abuse{at}strato[dot]de)
Takedown time:7 days, 22 hours, 39 minutes Bad (down since 2020-09-11 07:23:01 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-0800097569.exeexe 7330b8140dd5d2f9ffc5aedb2aef2a04d81c9179358771121b9113ed0dac6990n/a Heodo
2020-09-03bxDG0407691315726.exeexe 3255c30ccac5d35d9b074e7d109a023f99e793f4d905d9e74966cce815ea59a8n/a Heodo
2020-09-03ROKxHferzgM000012749630.exeexe c38232d05d928148eed9f9139003cf365bc24ee432ebc17da68dad3cf1edc26cn/a Heodo
2020-09-03LPuxn10431285254.exeexe 48a8d596af2342118b979220429a4e79d1916c041e1b5a031da0dde4270a96dcn/a Heodo
2020-09-03E66E500068883.exeexe 80b60eb5d1bbc0b07062c94b1df5bdf7a8a4c7f7fcf38d53fa30815947d14d36n/a Heodo
2020-09-037UDBZHCguDm.exeexe b5fe7c16349906deb0ce5b6aa42f5eeecfbdc93f0db399bde83ed0416f029e65n/a Heodo
2020-09-0308367wKaFSovkIaEh.exeexe 3ecb2294d4bb9b95cd2cd89ac071cfdb3bbd9fc0381c4bd498111ad95ad86631n/a Heodo
2020-09-03tm0REKlSZB1259969.exeexe c86254204bc7966ec5f765bd6b5e3a97ccda59a0726e73916c167c3f5cae987dn/a Heodo
2020-09-03jllWrlZ703322482431.exeexe 5625226c585273120188b481da0a04e3bd83a4d4fb64cf49d3ccc2415b02d239n/a Heodo
2020-09-033U008.exeexe eaa54d0bb664bc12bf0591378ef05c95c91a358a23e0e840799916ccbacdd08an/a Heodo
2020-09-033584624.exeexe c80fa2b7b4a9869444c65e68998ae5caf3e9f20278cf09b16028aa91b5cc3c86n/a Heodo
2020-09-03V9PtQABLC6ii881895108.exeexe f574ad057d06f6f66ed431cdd2413de3dba61fd5671e2c215282b3d159d6c033n/a Heodo
2020-09-031Y24Tmhw21000478650.exeexe 23c1bb8d2ed794d8c239ba48c96a99510d8888ef03345fe1042a1701c05925f3n/a Heodo
2020-09-03f0p17617.exeexe 55feb60740b43bd1f781fd4c57beca95ea30a561521115bf990ca0077d88ffben/a Heodo
2020-09-030001816115080697w7uJ.exeexe 6c438274684777d0aa4746d23ed6f90e7bb535071563b4909bf9eee317a82b23n/a Heodo
2020-09-03000002724078846.exeexe bb4f7d69ca582ebf3273c5c4f5534e8ce6d3e1b5e0333cbcba70b704f414a70dn/a Heodo
2020-09-03Z5X31J000592.exeexe 54abcb21c73f5d3dc5fa477a5795abd1476d986f245549d7cdbc3119ff71bdean/a Heodo
2020-09-0300003535482.exeexe 90f225c7eabf0b47a3e511d35da96a9d2a8a1b257c11706377d692ca9fde8f7bn/a Heodo
2020-09-0379aG37DTGn.exeexe 96b4ba48a3ac90b31a3579505058f7b33029bf84e43b0956fc7f9ddbc2c5d701n/a Heodo
2020-09-03E68Yd9s001453331901.exeexe 3e2dc0a50e252052b5f8316aab17933aa0adb45eab704418b36a73d2032c1a87n/aHeodo
2020-09-03oNxNvANNzg000447.exeexe d2ab846ee282ed8ace388a5f67f250130bc86dc54465a5e68c5924e49e1ba2fan/a Heodo
2020-09-03PCAy00058.exeexe 08e75a220328ca83e34141eeef1d3f5dd9de06180a4fbc8ff42ae05de33166fan/a Heodo
2020-09-030nlzATUquR56.exeexe eb0a9559f1c34037a21503f02da34de8bc62a89f1f2c8f30da89393ce04dc91fn/a Heodo
2020-09-0300076291348.exeexe 65a86c1027fcfa666719f274549029745bbc53a2249a789b9fc391d1f242e31bn/a Heodo
2020-09-030028206go.exeexe d79bab4a30961ff60d36c0c5556fe5fe5fea12299b3529495747daea52dd5815n/a Heodo
2020-09-03Qds2PbJ0000990.exeexe 58dc457805b2ed04958834fb163c08cda6b021a026a67f6aab6c942fd887ea8fn/a Heodo
2020-09-03Uug3332915703504.exeexe 9ae6195bc25c9592d41121514b83c124415f9b912126dbe7a6e7233a8f6e2969n/a Heodo
2020-09-036BNQq0g127.exeexe 4c16f68e6908b10ff76d137e902724f6e16863bfa7326c743e3f5cebd90617acn/a Heodo
2020-09-03004280157JYXXo.exeexe 23a186c9251ce2920000ea318f6282dcecca6d7a28c535697ddb1f8fa29c05acn/a Heodo
2020-09-03QxgyM6rqs2.exeexe f9d21a020448767ed1e396998a2318ff39400c87e2d3ae9d9d9e54178d096f75n/a Heodo
2020-09-03ixqWfLi264Aa9215300564.exeexe ff93bbc511cf212db35cd6ecde1b3aef2788d60bd0a511e7a15792fa5ff646b5n/a Heodo