URLhaus Database

You are currently viewing the URLhaus database entry for https://rubenwinkelman.nl/cgi-bin/https:/eTrac/ocAAAtZkwjXalM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452841
URL: https://rubenwinkelman.nl/cgi-bin/https:/eTrac/ocAAAtZkwjXalM/
URL Status:Offline
Host: rubenwinkelman.nl
Date added:2020-09-03 22:28:10 UTC
Last online:2020-09-04 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 22:30:10 UTC to abuse{at}strato[dot]de)
Takedown time:19 hours, 12 minutes Good (down since 2020-09-04 17:43:07 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04mes 20200904 QU192.docdoc 403170a4ca043be478bde432c994bc04e0ec0bb95f4d457928890829a998e46aVirustotal results 35.00%Heodo
2020-09-04978841 MAG5946.docdoc 3cbc74cc86834166223864b87a975cd733c121faa9d9119b74ab5d27c6a2c687n/aHeodo
2020-09-04DAT_20200904_272214.docdoc 791553d28205023fcec3eb1d7b8e89736e5f99b90e7e8a1ddfa4452f1897a74dVirustotal results 35.00%Heodo
2020-09-04Untitled-20200904.docdoc 1be69671e6bec7358d5a7ea5bfe04ad1acad931ee84e73f3bcc53f78d28a7052n/aHeodo
2020-09-04767281 YP207.docdoc 24401840c0ce4a3b8e35bdf4f126f227be7487c4747c57f1bea55e0d488ade46Virustotal results 35.00%Heodo
2020-09-04BE3470-409139.docdoc 0fd7dcfa200a1b0da02cc3578b15e97fdb192f4085d66ac383db864551155bffVirustotal results 35.00%Heodo
2020-09-04file 2020_09_04 89916.docdoc b246ae5854fc909f2e54163de7a8e78ef5de5a8648ec2768c6533c0ad65a15d5n/aHeodo
2020-09-0428445FAI_20200904_BNT119.docdoc 36ffaaac1fb3d49840166459ad272836f1add6d89d8733c4245582048c7b55d3Virustotal results 28.81%Heodo
2020-09-04Arc_2020_09_04_889563.docdoc 088de2c93ca2a5d1c4e17cab469aa2ea619a58e4c03c744b338f74787e4dca86Virustotal results 30.51%Heodo
2020-09-04Arc_20200904_312.docdoc 0568526f45b6dc177cf7e11a8bf286cdd2b253a794da1153795aeec136ba3313Virustotal results 30.51%Heodo
2020-09-04Attachments-20200904-MP31148.docdoc 91e4d3048c32a1e725788583ac764bc6f65819f7fb337f1d0a45cb9ac1f71276n/aHeodo
2020-09-04inf_2020_09_04_146.docdoc c3850d62a95518f0ec62ce9f3f83163aa67b240ac7b21a8b6e1bf5e24005a4d0Virustotal results 28.33%Heodo
2020-09-04List-2020_09_04-DX08700.docdoc fe8b0f5cf9354ea102596195bbbf5947c2103a393c585873166112b4734d3169Virustotal results 27.59%Heodo
2020-09-04ARC 20200904 432.docdoc 3b451d2d28836b979207203baee9be6f022bbe4132ebf4968ae41b510aaa869dn/aHeodo
2020-09-04FILE-2020_09_04-28596.docdoc d0faa29d011a7abe3a5e2d03346780cebd6a5dc766e52241014b96e58b4a99d7n/aHeodo
2020-09-04Dat_20200904_DF1423.docdoc 006573a1a4acf93e1940fd56fea0e62fa51082d6e0209689974721fc1b3f9f7dVirustotal results 25.42%Heodo
2020-09-04doc_20200904_SOF049.docdoc 6ba1180f37e95dd4238a52435a56d2cb1483ed9a34af53b44e0fecd5863244ebVirustotal results 25.86%Heodo
2020-09-04File 2020_09_04 C443595.docdoc 2e6992209a57f96c89556ed36c0e872bf312cc0e79e673c6888fe3b263c1ce06Virustotal results 23.73%Heodo
2020-09-04ARC-20200904-KRM613620.docdoc 7c92d272756fdd2e928979df95e5559a85fac4b8fdd04cb6c475bd102fadebd1Virustotal results 21.31%Heodo
2020-09-04UNTITLED.docdoc 5e01f376491f37354db3791f6ec1c53893e852d5874971655f2b8c0c9bfa35cdVirustotal results 21.67%Heodo
2020-09-04REP_20200904.docdoc 6b6138015363422437174a3e66d6fe9830722c6af61b695c5bef3200fe97a98bVirustotal results 21.67%Heodo
2020-09-04Rep-20200904-ZUQ9089.docdoc feeb5bbd5f395644d93d971b4f704d098364e1ab526f6f0a8ce14d95e5be7a5eVirustotal results 25.00%Heodo
2020-09-04arc_D4883.docdoc 8f5f4ee85f4ddec3e575c12be4dc7594cb6d941c85bd06c9467e917a9d6a04f4n/aHeodo
2020-09-04ARC_AQ438187.docdoc 260fbc9e9fe88d706ff79ffa20f96634ba7aecc723f8c8a0aa23b078a16455c4Virustotal results 26.23%Heodo
2020-09-04Arc-20200904-GK31054.docdoc 9896f6412623c9c75887ccf147bc7461f10527fbfb3463272f2086e56cc0b645n/aHeodo
2020-09-049698-2020_09_04-X0081.docdoc b6c9ea0c6311713092b07d9f28b5b798d84789c78cba9ce6f80d967cfec02942Virustotal results 26.67%Heodo
2020-09-04Doc-743356.docdoc 76edab16c0826931fc12090a44f6f773625fba9165acd2459a0e27eeabe00ceeVirustotal results 26.67%Heodo
2020-09-04Dat_2020_09_04.docdoc e514ee40aaf58363f83b55c5bb9e01e591be5d5fbea0402363bfe659405e331an/aHeodo
2020-09-04INF 2020_09_04 61883.docdoc 4dd07b5f70becd9fa1cd8ebbb833f449c200db06f39d962f13d96d55f4e61802n/aHeodo
2020-09-04LX413_20200904_029286.docdoc e730aaa4c7c10e51b95000fba71c2f93b07283c8b658d353dc52ba467c13693eVirustotal results 23.33%Heodo
2020-09-04Mes_ATX538.docdoc 4db2255d31946791dda100686fe140e9c3b4df0060994abd723c697a68b5819an/aHeodo
2020-09-04DAT.docdoc 741df8375c604df23cb9cc5bdbc6373f0b74df334fe2efd60bd6df7c5a398b65Virustotal results 22.95%Heodo
2020-09-04rep H27676.docdoc f9ea09e0474333e9c3d7ef368863f79db7654109197ee33b969b73757bcbf091Virustotal results 23.33%Heodo
2020-09-04Inf-20200904-R20631.docdoc e265891012d31e17fb6e3c8029d29b874cc7fd9bfd6c0ad065560e291b7eab4dVirustotal results 23.33%Heodo
2020-09-04REP-2020_09_04.docdoc 8b8167f9f9f0fb034acba8cfca499300531ee06a2c9ee705d976d007bb636f21Virustotal results 21.31%Heodo
2020-09-04mes-20200904-BVM751536.docdoc f757b9a11463c3bb26ef5c9486e4ede7cd2899709fbbf17ba17042e2b75109e5n/aHeodo
2020-09-04List_20200904_2212.docdoc 987e6058bcbb6e6830567bcbf092de202f9fc61bc7b1a6f282f6ee741685e442Virustotal results 43.33%Heodo
2020-09-04WA4335 95665.docdoc be658261ea85360800d4b052f23fd96dbadfe7171d308a38dba22b5fe4efadf0n/aHeodo
2020-09-04Dat_2020_09_04_A1202.docdoc d310bc1324e7bd2e09dde5482cc4390a66257737f2da4ce7c2bc2f05d04663d7Virustotal results 43.33%Heodo
2020-09-04Doc-20200904-5743.docdoc 933a5acf70c2c8f24a3d359a43ab898e556cdcae740ddcaf33acbc356ae1d9d5Virustotal results 37.50%Heodo
2020-09-04Doc 2020_09_04 DOP743.docdoc acb81dc6508ccc95393a57308575ed700b2dca51e4f0658f6ce9dacfd214dd3fVirustotal results 40.68%Heodo
2020-09-04File_127253.docdoc ca1b62ba1f6df4e6e7ee6b0ae0cdbf41303c29e916602d32ba15df885ce8d527n/aHeodo
2020-09-04LIST_VAL2633.docdoc e65695efbab165615890ff748629c8f55ca9d41d32545193018429b58b8ca746Virustotal results 41.38%Heodo
2020-09-04inf ZX98416.docdoc ac647d90b3039bce667132dc5186534b23351caaf4e883d9bf6330a66d6d84a2Virustotal results 40.68%Heodo
2020-09-04Rep 468404.docdoc ede8d998dc31e2c855d01100bae27909e6fad8672e5bb1e7afced120b025c6a4Virustotal results 40.68%Heodo
2020-09-04Untitled_2020_09_04_L8699.docdoc 6c3530951ad2bde0a96b5bda4698fb3638e360f5176d3f6aa4f9ea0570a3f45dVirustotal results 40.00%Heodo
2020-09-04Attachments-20200904-54491.docdoc f1d06faa66ff49136e73546caaa462dec1fc01c209288126d019c0c688f6f5d9Virustotal results 40.68%Heodo
2020-09-04Dat 2020_09_04 OVL266980.docdoc 886d63b614006458acc2c30f3864476e896c318a90248243fabf63f0e992f712Virustotal results 40.00%Heodo
2020-09-04dat_20200904_6211284.docdoc b25414b4b759b6517cfc1ce36e58d10a5aac59912adc8230095f50f6659af778Virustotal results 40.00%Heodo
2020-09-04UNTITLED-2020_09_04-27931.docdoc 90d7013803edb798ee2da7fcf3de07420ccd536dd01c96d0c787a80c0923f08dVirustotal results 40.00%Heodo
2020-09-04Attachments-627.docdoc 113f271d566b508aed976158e057211703fe30c314960665466fe58d9e08e50bVirustotal results 40.00%Heodo
2020-09-04UNTITLED-751.docdoc cbf75dba4c6b4f8cbcfb647112f9a0a4f8efb293526aea73ffebcd800379e08fVirustotal results 40.00%Heodo
2020-09-04MES 2020_09_04.docdoc 595e8a24f2e5e51e56138296f7c6cd58e709e8f532dbacc38ae66f462e0e071dVirustotal results 40.00%Heodo
2020-09-04BRF2048_0008168.docdoc ed80367a721e5c5ea3048c5688d5b8446bfed75afd70f06932dd66e94a437a93Virustotal results 41.38%Heodo
2020-09-04FILE 20200904 478371.docdoc 6300e903bf3720bb91e4db31ad186d98f0b8307f0abd3b785145f72f0a89edefVirustotal results 40.00%Heodo
2020-09-04Mes_2020_09_04.docdoc ee7586771fa02df0ef18b9f88c3bb45135371e5f7a16f6304b1b500a99a0ca6eVirustotal results 40.98%Heodo
2020-09-04MES_20200904_NQ11223.docdoc c9760ed3a6abb462e2d429280f83f0e912114c2b1923fa1fec74b3ee350afa78Virustotal results 40.98%Heodo
2020-09-04Untitled 20200904 K77592.docdoc d6da8adc7df4680bdfe56aded8385d20e63b8af6ac83ff2abdccf2910232809bVirustotal results 40.00%Heodo
2020-09-04file-20200904-708544.docdoc 945f9c6c84eff86e098fcb02268e716fb80f5c6fa8a5e64e08175a306d3c0a2bVirustotal results 41.38%Heodo
2020-09-04MES_20200904_IY04052.docdoc 479a6416cfb665d2d0f0b6e39d11282a0d31d799d87898d50f066e8d564808f6Virustotal results 36.67%Heodo
2020-09-03Arc_20200904_N92550.docdoc 5b1c5637bea570eeef52ff79044a41de92de4e33ddffcde3b3611bee6fc8e5b1Virustotal results 36.67%Heodo
2020-09-03Inf_2020_09_04_3114.docdoc d313ce8483aa86f33b4fb8f8eaf32cc9162fea1ecd980baf5fb9ae5ba1e2024cVirustotal results 33.33%Heodo
2020-09-03List_20200904_854.docdoc 9e3d362ff8dc1daec89813f11f73bac91ac2ee3f97f803fd413522874432ebb4Virustotal results 32.79%Heodo
2020-09-03Dat 20200904 DH2747.docdoc dec0fc4e4611e340eb402f29ab07769dcc51d4a2806a8aa520f4332aca26f2dbVirustotal results 33.33%Heodo
2020-09-03Inf-20200904-F919561.docdoc bf1b9f0a76233f9cc5983b3b48fad1f4edff9c94e363dbab7f91cb8050ab315fn/aHeodo
2020-09-0349332_2020_09_04_DQ854.docdoc 2f9910b3fffce2373726bb19cee907def1ad66df1c9210d955647c7a638ef9edVirustotal results 30.00%Heodo
2020-09-03Doc 2020_09_04.docdoc eb96e6409fa3b1e2510201d45d3a629be387c1d50ca84645b13d0614702d7c62Virustotal results 29.82%Heodo