URLhaus Database

You are currently viewing the URLhaus database entry for http://uhren-lehmann.de/cgi-bin/http:/paclm/kPJNTV2KSva/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453088
URL: http://uhren-lehmann.de/cgi-bin/http:/paclm/kPJNTV2KSva/
URL Status:Offline
Host: uhren-lehmann.de
Date added:2020-09-04 06:59:06 UTC
Last online:2020-09-04 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 07:00:12 UTC to abuse{at}strato[dot]de)
Takedown time:10 hours, 53 minutes Good (down since 2020-09-04 17:53:35 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04file-20200904-952.docdoc 403170a4ca043be478bde432c994bc04e0ec0bb95f4d457928890829a998e46aVirustotal results 35.00%Heodo
2020-09-04Dat-0352161.docdoc 5f507662f25de9c594d9c295a8fcd49bab262c3b83c2a470ca2a0303834b57d1Virustotal results 35.00%Heodo
2020-09-04rep 2020_09_04 K8574.docdoc 4f574c1f2f33241e9d1d44b74075d96778a9a152808b8c397f19a51c1b16ab2dVirustotal results 33.90%Heodo
2020-09-0445818VQ_2020_09_04_VT903.docdoc 0beda050f3d53272adb6212a1cb59024a6b126a0dfe9cbf0e8f5ec32b133a8c9Virustotal results 35.59%Heodo
2020-09-04List-926459.docdoc fbaa65a02cf8c771c0cf3656084a8b4168750f336ef53130fc96a219ce9dc121Virustotal results 35.00%Heodo
2020-09-04Untitled ME544122.docdoc 7ba727e56ef8d6bd90965dcbe4450880fd516019d4c10f8a5d101541aa883dfaVirustotal results 35.00%Heodo
2020-09-04921 2020_09_04 2431.docdoc ff21a2ec6d99469e4b92b0e12a00fde35952edf0f9d9d296eb4a9f5ec13d2a49Virustotal results 26.67%Heodo
2020-09-04MES-20200904-164.docdoc 088de2c93ca2a5d1c4e17cab469aa2ea619a58e4c03c744b338f74787e4dca86Virustotal results 30.51%Heodo
2020-09-04FILE_5650334.docdoc 9b5118c972be1fdccab96caaa3644530d5a73cefcb8b7a048497c43b3e1867dan/aHeodo
2020-09-04Untitled 86332.docdoc 2b92a083d78d4854c3fa6ee427357e1a0c4f3b5fc4b22546712e350870b77c45Virustotal results 28.33%Heodo
2020-09-04REP-QY199.docdoc d7452abd23b4d0a252d67436bea5f98b177d6d4a707ce10ce71852940cf97a3cVirustotal results 29.31%Heodo
2020-09-04rep.docdoc 7160ce21f102d1b919bee53947094d83fd11055b2eadb90b11d5923498d504c3Virustotal results 29.31%Heodo
2020-09-04Doc-2020_09_04.docdoc fe8b0f5cf9354ea102596195bbbf5947c2103a393c585873166112b4734d3169Virustotal results 27.59%Heodo
2020-09-04dat_20200904.docdoc 794287d8176f07c6943cc4ca303d03de2ec84b37ff7262e148c0451087177c86Virustotal results 27.12%Heodo
2020-09-04Attachments_20200904_1803626.docdoc ed63266e67ad9944d1501d2221c8390e1585ed5aed9397212441db07dea0b7e9Virustotal results 25.42%Heodo
2020-09-04MES-089151.docdoc 22541ac301b5c8fdf15f74cc06df0c5a237bfe5593f910699acdaa3ae869edd9Virustotal results 23.73%Heodo
2020-09-04216SWR.docdoc 05d812b5dacd80bc461304d3f5e745b7522bf28e626b1e1e5ce3b864ebf64f35Virustotal results 25.42%Heodo
2020-09-04LIST-20200904-10744.docdoc 2e6992209a57f96c89556ed36c0e872bf312cc0e79e673c6888fe3b263c1ce06Virustotal results 23.73%Heodo
2020-09-04file 2020_09_04 W60886.docdoc f7347d7eb634ea2c2bdeb69d026c099ca12acf563a5b6681e6467ce9c7260619n/aHeodo
2020-09-04ARC 20200904 WT918.docdoc 0348b2d84a9245b99853803db4a5d8a6bb6b89ba2b30d2d201dffbe97b718d82Virustotal results 21.31%Heodo
2020-09-04LIST_CP664280.docdoc 5e01f376491f37354db3791f6ec1c53893e852d5874971655f2b8c0c9bfa35cdVirustotal results 20.34%Heodo
2020-09-04LIST-20200904-HJ0679.docdoc 1c67628b01a329488b609ce13ceba3610a0d79cfe6bdb3d6750f714ffc97f27fVirustotal results 27.59%Heodo
2020-09-04Arc-2020_09_04-3410.docdoc 1fd6598e530c78964c40e2d283b7eb345c92f4c161ca5f5254ec469366603439Virustotal results 26.67%Heodo
2020-09-04doc_418.docdoc ca900ae40752b2a78feb23b6d8c3f29f674621fc5a6d90b99c3f2f2c6efbe075Virustotal results 26.23%Heodo
2020-09-04Mes-8938448.docdoc 9896f6412623c9c75887ccf147bc7461f10527fbfb3463272f2086e56cc0b645n/aHeodo
2020-09-04list-20200904-6582575.docdoc fe091cf9eba180793119db32fe94d4816c743d95fe73f73f8f8a11df2cd0aadeVirustotal results 27.12%Heodo
2020-09-04Mes_20200904_641392.docdoc 9da9e2af16844a3b0fc49e496b6a88773ebb122ac1471d654d696c4417c6c5d7Virustotal results 26.67%Heodo
2020-09-04Arc_Q3214.docdoc e514ee40aaf58363f83b55c5bb9e01e591be5d5fbea0402363bfe659405e331aVirustotal results 25.00%Heodo
2020-09-04arc 20200904 LHE981592.docdoc 35eae4bf4a4e774e6e01de12b1358e0b431ba0b625952ca4b650849e31cfb1f8Virustotal results 23.33%Heodo
2020-09-04140P_20200904_4859.docdoc 2f0f9e8cde5b53aa80b32d713adc28fff055196706c5e13da4e760a06873daffVirustotal results 23.73%Heodo
2020-09-04File-2020_09_04-Z738691.docdoc bfc004f7ac8d0c2e241dc8086e3e58fb542fcc47b5114ab614fa893199328acfn/aHeodo
2020-09-04inf-20200904-J799731.docdoc 6e80f8c0bcada5875b9aeb8c66983961fcf02d5d34173f58dc2a8834db676703n/aHeodo
2020-09-04doc_330.docdoc 741df8375c604df23cb9cc5bdbc6373f0b74df334fe2efd60bd6df7c5a398b65Virustotal results 22.03%Heodo
2020-09-04Mes 20200904 407417.docdoc 47942152b879136b37f93a091fdc0995ae8dc63870ec7644620fc97205c8aa51Virustotal results 23.33%Heodo
2020-09-04Rep_JCW74658.docdoc d9c975b6db619552db6df9461b3c0947dbeb829698591386f2c86994a414e005Virustotal results 23.33%Heodo
2020-09-04MES-20200904-0738805.docdoc 8b8167f9f9f0fb034acba8cfca499300531ee06a2c9ee705d976d007bb636f21Virustotal results 21.31%Heodo
2020-09-04Attachments_2020_09_04.docdoc 970e16cc8aabea583a577bb3ca6a50b795357231ff02822fafb8aa7dd143667fn/aHeodo
2020-09-04MES 2020_09_04 267561.docdoc 59dca4cb54c947789abfb907c7c1ac28d15ad9883a693d5d3b56654c75bd5d8cn/aHeodo