URLhaus Database

You are currently viewing the URLhaus database entry for http://kraus-world.com/cgi-bin/https:/Scan/XCAYn3HTTlOhg8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452166
URL: http://kraus-world.com/cgi-bin/https:/Scan/XCAYn3HTTlOhg8/
URL Status:Offline
Host: kraus-world.com
Date added:2020-09-03 05:04:17 UTC
Last online:2020-09-07 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 23:24:02 UTC to abuse{at}strato[dot]de)
Takedown time:3 days, 9 hours, 56 minutes Bad (down since 2020-09-07 09:20:18 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04OO877-2020_09_04-L20478.docdoc 6811ea887aa1fb0b0947ae4c101b1bccd01e6be62529652d9a9c70a8879485feVirustotal results 34.43%Heodo
2020-09-04CGG79195 CBA970051.docdoc a49d6ff985f57e4d6e09893b343f97b9da664ae8c0b7c0e95f18f1a8f119f1a8Virustotal results 35.00% Heodo
2020-09-04mes-7009318.docdoc 113c8c78cdad0ed438501117f87ca9b0d52b672ddd8b015284541ded516827e6Virustotal results 35.00%Heodo
2020-09-04arc 20200904 CTP732.docdoc 330d4d67d3a359dcef80543042abe21455bb45b35be91af1b8fc33bcea44d03cVirustotal results 36.21%Heodo
2020-09-04dat_HS55341.docdoc ef5176343779eaa99518b910aea7bc09e3f3c68b84d581e4762ede0c68729a0cVirustotal results 36.21%Heodo
2020-09-04IAP54539_2020_09_04_670.docdoc 4caf5eb87b69a8e37c3524c776870ace2c3a187f6d4956a9cf441148c4dc75cbVirustotal results 35.00%Heodo
2020-09-04mes_20200904_UZ9562.docdoc a7f35b06b6d94b7aacb7aaf4681b81b3373a4051b74e97e01ae6d58a2f052b27Virustotal results 35.00%Heodo
2020-09-04Dat_2020_09_04_X896439.docdoc e4006ffd7617f48dca3ed5e7220e159de2160b07f86452e1fcb7fa0f27ed1d9an/aHeodo
2020-09-04arc.docdoc 38723e854156b62f83e4cdcf30c187c9fc432db05f0f55e1c824b40c7d02a489Virustotal results 35.59%Heodo
2020-09-046161M 2020_09_04 G131521.docdoc d4416a6ff0dbbf8a60d1df15030c7eeaf6be3883b9f4df72bd6312eb84caa672n/aHeodo
2020-09-04Arc 2020_09_04 682.docdoc 482e43557c2b67031f8b9141f11291ebb6d9fa946193ab1287ef2010ab18b462Virustotal results 26.67%Heodo
2020-09-04Attachment 2020_09_04 51113.docdoc 20f0a0ba4cd0dac615e918dd489d36a9dbe9da8eccd28074379ccb9297f44202Virustotal results 28.33%Heodo
2020-09-04DAT_2020_09_04_WIA34352.docdoc ac6a5c2f72c10af857d73db327000d07f01f791fe6638c339362584fe1293a4fVirustotal results 30.00%Heodo
2020-09-04rep-20200904-TZL928.docdoc 2b92a083d78d4854c3fa6ee427357e1a0c4f3b5fc4b22546712e350870b77c45Virustotal results 28.33%Heodo
2020-09-04Inf_2020_09_04_0025.docdoc ba82dfa2da1757e5cb6ed6f9bb2d2c820d055dbab664b798475fd4a94d8476b9Virustotal results 28.81%Heodo
2020-09-04mes_20200904_1993075.docdoc c3850d62a95518f0ec62ce9f3f83163aa67b240ac7b21a8b6e1bf5e24005a4d0Virustotal results 28.33%Heodo
2020-09-04KD9878 2020_09_04 Y936342.docdoc 3b451d2d28836b979207203baee9be6f022bbe4132ebf4968ae41b510aaa869dVirustotal results 27.59%Heodo
2020-09-04Attachments 2020_09_04 406.docdoc 1c3e3bdb04dc52f5610c1079242b43b61f136a2a328a6813fe492e4092cd6e4aVirustotal results 23.33%Heodo
2020-09-04Attachments-20200904-44284.docdoc ed63266e67ad9944d1501d2221c8390e1585ed5aed9397212441db07dea0b7e9Virustotal results 25.42%Heodo
2020-09-049765401_2020_09_04_38048.docdoc d6f3b5795079ed619a19ab306daac9d3fa4c20b2b54ee7e4ca872f334f92ba08Virustotal results 25.42%Heodo
2020-09-04rep_20200904_76392.docdoc 6ba1180f37e95dd4238a52435a56d2cb1483ed9a34af53b44e0fecd5863244ebn/aHeodo
2020-09-04Dat-2020_09_04-DTC51550.docdoc 52a1f3085fece2adb5e447183da5a37ab0c90019b2237702ce65ead6ba03cf96n/aHeodo
2020-09-04Rep-20200904-247884.docdoc f7347d7eb634ea2c2bdeb69d026c099ca12acf563a5b6681e6467ce9c7260619n/aHeodo
2020-09-04FILE-20200904-967.docdoc 5e01f376491f37354db3791f6ec1c53893e852d5874971655f2b8c0c9bfa35cdVirustotal results 20.34%Heodo
2020-09-04DAT 2020_09_04 OKB986864.docdoc ef71a4e7c9a6ea0844d8e1e667882eacc23b82d5a49596d4fec7ae808ec62c55Virustotal results 21.67%Heodo
2020-09-04rep_20200904_TR414.docdoc eae2a3c4e7a60e5476ac2c92926540cf3c70568a318f1a20a996ebeb53e8749bVirustotal results 26.67%Heodo
2020-09-04rep EX4178.docdoc 8c4a8a1c7d4ddbfd0b727a5f169b6bc78e7997fd2b0947299d663a215bb3a9d9n/aHeodo
2020-09-04REP-20200904.docdoc 260fbc9e9fe88d706ff79ffa20f96634ba7aecc723f8c8a0aa23b078a16455c4Virustotal results 27.12%Heodo
2020-09-04mes_BO41804.docdoc 24325dc08722e851f6637f34bd024e29a92a95a82f94fd5adf334df561dfd116Virustotal results 26.67%Heodo
2020-09-0490475EZ 37913.docdoc b6c9ea0c6311713092b07d9f28b5b798d84789c78cba9ce6f80d967cfec02942Virustotal results 26.67%Heodo
2020-09-04mes_2020_09_04_950150.docdoc 9da9e2af16844a3b0fc49e496b6a88773ebb122ac1471d654d696c4417c6c5d7n/aHeodo
2020-09-04INF_TV782.docdoc 4dd07b5f70becd9fa1cd8ebbb833f449c200db06f39d962f13d96d55f4e61802n/aHeodo
2020-09-04Arc_2020_09_04.docdoc 35eae4bf4a4e774e6e01de12b1358e0b431ba0b625952ca4b650849e31cfb1f8Virustotal results 23.33%Heodo
2020-09-04Attachments AO4418.docdoc bb45d855066ff6017d80b8b4a36bacb4eb9b6345f1b41ba8301a7588d6532abaVirustotal results 23.73%Heodo
2020-09-04file_20200904_73489.docdoc bfa8973f2e13b6e793f43e4c1d1b68e81e7928903e0f8edf9fd3b146ee1cb9f1n/aHeodo
2020-09-04INF_2020_09_04_U5483.docdoc 12f0fe0be2051b0b2db3468b20798d7813c859384af5be7c18845165d1bc9240Virustotal results 22.41%Heodo
2020-09-04Dat-ML28746.docdoc 52253d5cc807567a8465a7cf37b1101897ed3c19596c3261041ce32593e2f467Virustotal results 23.73%Heodo
2020-09-04LIST_20200904_0518.docdoc 273cf35f21fb5cb9162d3d4a667f96b5f2b93c16327304b5a21c1d51448e0e78Virustotal results 23.33%Heodo
2020-09-04LIST KQB5907.docdoc 970e16cc8aabea583a577bb3ca6a50b795357231ff02822fafb8aa7dd143667fVirustotal results 22.03%Heodo
2020-09-04UNTITLED-20200904-D7573.docdoc d38918707adc1b43963df18c7c3483e35cb906f58221fbe54adcbf770706feafVirustotal results 21.67%Heodo
2020-09-04dat-416.docdoc a116a068131b7ef0d015c07614c3e6f346f604fd7d9b5b974b9f09a997916732Virustotal results 44.07%Heodo
2020-09-04rep-M088481.docdoc 4e3917d545fe670b0ea8dd1cf91701595c3cbe5ab87b5c53a826514778bad6f6n/aHeodo
2020-09-04MES-20200904-787.docdoc be658261ea85360800d4b052f23fd96dbadfe7171d308a38dba22b5fe4efadf0Virustotal results 41.67%Heodo
2020-09-04rep-2020_09_04-957.docdoc d310bc1324e7bd2e09dde5482cc4390a66257737f2da4ce7c2bc2f05d04663d7Virustotal results 43.33%Heodo
2020-09-04RR75468.docdoc acb81dc6508ccc95393a57308575ed700b2dca51e4f0658f6ce9dacfd214dd3fVirustotal results 40.68%Heodo
2020-09-04Rep_2020_09_04_109999.docdoc ca1b62ba1f6df4e6e7ee6b0ae0cdbf41303c29e916602d32ba15df885ce8d527Virustotal results 40.00%Heodo
2020-09-04Doc YI1441.docdoc 2fcecf7ef769ae49ecdf3905e7c5e7aad9a7f0ac4279fe518ed0108f25a0ec79Virustotal results 40.00%Heodo
2020-09-04REP_20200904_IIN1379.docdoc ac647d90b3039bce667132dc5186534b23351caaf4e883d9bf6330a66d6d84a2Virustotal results 40.68%Heodo
2020-09-04dat.docdoc b928a4ea1aae65b1c3ee2634f0d4d3bba7d8f0d7bd647c3befb30ba0f8b6a1abVirustotal results 40.68%Heodo
2020-09-04Inf_2020_09_04_Z712.docdoc 027746c91762be2cd5ecdd301acedfce96399a7961478130a7c6e26d2e47ea3cVirustotal results 40.68%Heodo
2020-09-04UNTITLED-PW7306.docdoc 6c3530951ad2bde0a96b5bda4698fb3638e360f5176d3f6aa4f9ea0570a3f45dVirustotal results 40.00%Heodo
2020-09-04Arc_4989890.docdoc 4808444c5d5d505fcdfe5814913d92dea2c41dbd68018cff2817cabd134441a6Virustotal results 41.67%Heodo
2020-09-04LIST 2020_09_04 LOA614.docdoc 6333175d3560cf42c1b0b3631cfe1302ce937aa2b85c3ecc3407cfde4c9cf37aVirustotal results 40.00%Heodo
2020-09-04File-OV90448.docdoc 8d774a00099efb6bf180d96ed66c4cc234169be46bd45261c06dd8500e0a8481Virustotal results 40.98%Heodo
2020-09-04List-2020_09_04-843147.docdoc 113f271d566b508aed976158e057211703fe30c314960665466fe58d9e08e50bVirustotal results 40.00%Heodo
2020-09-040020_WY88924.docdoc cbf75dba4c6b4f8cbcfb647112f9a0a4f8efb293526aea73ffebcd800379e08fn/aHeodo
2020-09-043453397-O35085.docdoc 1fa1544383bbda2ef984f9c0a8a1e3ec9c37ede4a0e897d8177d7e92d3809ea1Virustotal results 40.68%Heodo
2020-09-04Attachments 0015048.docdoc 9cf29b7fcce905e807fd1e4493af36f7f0e8618912601f1a85cf52af6d38d6b8Virustotal results 40.00%Heodo
2020-09-04inf 9524587.docdoc 41b51c9c72e134b6a5183ee31357d58d19e875c56db068adc0b5f8a3d12bdc3eVirustotal results 40.00%Heodo
2020-09-04LIST-2020_09_04.docdoc 7eba76e504a537e3600311969b0b159744d8f78d48891c9f06dfd9aa9798b9e3Virustotal results 40.68%Heodo
2020-09-04Attachments_20200904_239.docdoc c9760ed3a6abb462e2d429280f83f0e912114c2b1923fa1fec74b3ee350afa78Virustotal results 40.98%Heodo
2020-09-040481QIP 44394.docdoc 69e91274a22bb98b54013be9509ad757c17fd9ab44d80c5a8585ec639ea6f04bVirustotal results 40.68%Heodo
2020-09-04INF-2020_09_04.docdoc d6da8adc7df4680bdfe56aded8385d20e63b8af6ac83ff2abdccf2910232809bVirustotal results 40.00%Heodo
2020-09-04UNTITLED-20200904-197.docdoc f5ace8d328883020ed6b37dfb50687886670fba064afbbbbf6e9e695ce35e490Virustotal results 40.98%Heodo
2020-09-04inf LT983.docdoc 479a6416cfb665d2d0f0b6e39d11282a0d31d799d87898d50f066e8d564808f6Virustotal results 36.67%Heodo
2020-09-03inf_2020_09_04_1884.docdoc 62f2e2f1e282bf930eaf8a31d9904112fa33e4c5bcb2d14f0efc91df5351ae54Virustotal results 36.21%Heodo
2020-09-03Arc_LW21607.docdoc d313ce8483aa86f33b4fb8f8eaf32cc9162fea1ecd980baf5fb9ae5ba1e2024cVirustotal results 33.33%Heodo
2020-09-03668_2020_09_04_HV634417.docdoc 5870705910f4290f13346efd3c9113483974723cc840cd330844efa6f5b3be19Virustotal results 33.90%Heodo
2020-09-03Arc_ZE698.docdoc d1736bb7fba0d5f83c964fd5e9c3d2659a1a1ff6eb178441309a83e9fa00ef5fVirustotal results 30.00%Heodo
2020-09-03Untitled 20200903.docdoc fec90b9f6fbd9d737bfb18e0f1801b841454d1857793a0cb6484f891a1a495fdVirustotal results 30.00%Heodo
2020-09-03449_2020_09_03.docdoc 10b9c4bca67ace9500467fe62f3f429c09793aad07493bb237def1c168c83000Virustotal results 30.00%Heodo