URLhaus Database

You are currently viewing the URLhaus database entry for https://elektro-grell.de/cgi-bin/o8Xj1y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452730
URL: https://elektro-grell.de/cgi-bin/o8Xj1y/
URL Status:Offline
Host: elektro-grell.de
Date added:2020-09-03 20:13:34 UTC
Last online:2020-09-04 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 20:14:08 UTC to abuse{at}strato[dot]de)
Takedown time:10 hours, 37 minutes Good (down since 2020-09-04 06:51:18 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-040Ih149RuvLLPmRi.exeexe 658edfb71d28300653be6f6d7cb94db3130db33655cd6b2286d9328ccaf944f6n/a Heodo
2020-09-04ReIFamD3u6cM6NocvrPx.exeexe 73c5217559efea79d4c065824a4fd9082a144dfde3be7cb91df40e6ac6591613n/a Heodo
2020-09-04LZD4qhiMxx.exeexe 1f6b8dd8a8ad08c0262ecfc12fba5a325f08c5c1c9d04030f79073b7ac38715en/a Heodo
2020-09-04ppDMsNaBER.exeexe 739035220619026be0b3e51343cfee8e9b4632bca24ec7f6d1967a755958dc1bn/a Heodo
2020-09-043zR.exeexe b9fd296f08180eae9be3b03c4ba1a72a00e70de61a39fcdafe4587b0a3e802ben/a Heodo
2020-09-04eCeFYY276gdT8WfKs2.exeexe 39dc5f082d4a660dfe2b6042be916f1236981b3a33c4cb6fef08220fa8bda33dn/a Heodo
2020-09-0460zCQ5kckU.exeexe 336d7b2de12d1ed73fcc261fd05e2894d741e7f80ab22c231d0ad3380c9f8d54n/a Heodo
2020-09-04Bi.exeexe e2dfc2694979cdc23aa6b4f80fbb6f03d6d3954bb8486f70552859282add44b7n/a Heodo
2020-09-046Xdk2E7hVO.exeexe aaae661a5406b64de3d94da8641bcb9a0159218b79fa0fa4f7e6697394c4da7fVirustotal results 10.14% Heodo
2020-09-04oWiIbQefpfrL3A3.exeexe 36575a8cb84d5d060825d36088585bd174b20fdc70248d6678667498c438c549n/a Heodo
2020-09-04aSMHsDoMEngNNykzV.exeexe 0ef358c7c47cf5ca375db6b4398fad17e365516bd721eeb21691ff35e1de29f4n/a Heodo
2020-09-04v4IEgqozUtJEiIYe.exeexe 7da68ad7ef24ecca6b1dede54e8c341b6a61f14a4e76ea8619ecae9bdc248d37n/a Heodo
2020-09-049swlmh.exeexe cd57b3bdb0b901114d967f38200ac9286c46b520e2a85f17afe160993114c083n/a Heodo
2020-09-04YlG86.exeexe b34d496aefaebabb69f710ad70df9761834394fec8c686fcd22d86aab3b7231an/a Heodo
2020-09-04Yw8TiKuy8q.exeexe 4142b9e70eda6e285c7eb9e73e7e3fcdf250f659778d99fa5659b76dba3fb33dVirustotal results 7.25% Heodo
2020-09-04T3E.exeexe 28f6da4bb67e485a32582895f25e2429d9982a83b1a9956459e0ad199b26f2ban/a Heodo
2020-09-04uLApX4HhvjBTPq0QcP.exeexe 158ef6c3f3eef158b6c8a0cb69610eaaec23e69446083e0741023349aa4e3301n/a Heodo
2020-09-04pijekdIkbh.exeexe bf4ff4628d52bea4581b07773e8e86718b0cc829b5b40c2dd9a86369e56d21b1n/a Heodo
2020-09-04FBtBTQVoYr.exeexe 560b045e4f5cfea445d63e29937ba9f8b0ff0212ea9458f9516eb6fe1a5b18e5n/a Heodo
2020-09-04256EL4JqUJCyZux5k.exeexe fe90903175d63f5ffe147a555eee450bfb0c970f622bf38827be55f245028487n/a Heodo
2020-09-04zS.exeexe ed71607e4a81d14215c77f0fdc065c80abbd22e5bb9171143d8cee1bc847c4cdn/a Heodo
2020-09-04E7OYWieeb.exeexe 80f8a4f9c8370568c23797efb5f6ba4b523bf4a373c868fdc8c6fadb9230fdb3Virustotal results 8.70%Heodo
2020-09-03kUFvCJd.exeexe 371ff3b74842d6750d7381fb0270231b2257910c2f53b0ee2383f86f4be57db4n/a Heodo
2020-09-03Ai9YQ3JYCJN6hptCOF.exeexe aa8b501b7862da0e31fb5f3d66b16cb994343a3e2d46648a1fb3475a4a010d83n/a Heodo
2020-09-03h8WcFFNoySe1sZTNoC.exeexe 665b1082743ce12ddec15be10d87214ca028599e8665c626289fdb7105f45c38n/a Heodo
2020-09-03zuNuzE1jnLvBM6wVWv3Y.exeexe df1b2bba43b99c20b66afa46113f0935e8ad65961fb55c75790c16089c36f475n/a Heodo
2020-09-03Rr9gCNwoc1Dppu6q.exeexe 85f0f94e1d7557fb384b45d5fdb1d265ae293f5593ea2cdc354bf083b34ca90cn/a Heodo
2020-09-03hXbh.exeexe 3d26b32d0abecba0b58b79502998c7a6785492fd3937f23fdf62802fd9e98ae5Virustotal results 11.43% Heodo
2020-09-03MK6Q4f5hiAFSAfTWsst.exeexe 76124af9a84470716c0109f5a871dff2ccf39338a6d99035a66b598206763bc2n/a Heodo
2020-09-032cB31Q.exeexe 2da2e0dca0678fab043d46ab116b8c443fe6108f32224386dd6b7dc420308761n/a Heodo
2020-09-03j3TSqVNo6OVsZHTl.exeexe a594c4111a076a8c75e2146be3cba66f6c7376bca6300233aed11c39d24fc243n/a Heodo
2020-09-03tYSICEFQ.exeexe 7f6e52dcad5d5a41b5fb16e6c58d9adfa7163e0514e309e333b4c770491de8e3n/a Heodo
2020-09-03bWLmXZW.exeexe 52c198e0124ff524da7aea6cde1ca9133e08518010e008976cd50c7a228a4047n/a Heodo
2020-09-03eQ.exeexe 394cfdfc50b80ef497cec645930960094bed642689988dfb8ed2a3511df98670n/a Heodo
2020-09-03lJy5d7Ow.exeexe 0760647bf8c79c5bb6ad92f3bdc774aa4828bf7edafb479bfea40b9bb0162e3bn/a Heodo
2020-09-03JyG4xNVkZ.exeexe 02ce2451fc313c6626a46f40604786ef19a8510afa4358869dfbbf98713506c4n/a Heodo
2020-09-03Xp00PbBxPHcZlz.exeexe 48075451c6e48cc311bbb839c7ab388eb5ecdf05c02c3f9fdba5b213c3afcb42n/a Heodo
2020-09-03Yoeb3.exeexe f2b44d417ec2c773783866ab010424391c98ee1ab19c47811f06c726739b2a6eVirustotal results 13.04%Heodo