URLhaus Database

You are currently viewing the URLhaus database entry for http://osberatung.de/cgi-bin/http:/esp/HM7r90NdRX3oWK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453094
URL: http://osberatung.de/cgi-bin/http:/esp/HM7r90NdRX3oWK/
URL Status:Offline
Host: osberatung.de
Date added:2020-09-04 06:59:11 UTC
Last online:2020-09-04 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 07:00:15 UTC to abuse{at}strato[dot]de)
Takedown time:15 hours, 30 minutes Good (down since 2020-09-04 22:30:42 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04inf EH591953.docdoc e4006ffd7617f48dca3ed5e7220e159de2160b07f86452e1fcb7fa0f27ed1d9aVirustotal results 35.59%Heodo
2020-09-04Attachments-20200904-DVJ1975.docdoc 24401840c0ce4a3b8e35bdf4f126f227be7487c4747c57f1bea55e0d488ade46Virustotal results 35.00%Heodo
2020-09-04Arc_20200904_5179339.docdoc d4416a6ff0dbbf8a60d1df15030c7eeaf6be3883b9f4df72bd6312eb84caa672Virustotal results 35.00%Heodo
2020-09-0485978571_064.docdoc 0fd7dcfa200a1b0da02cc3578b15e97fdb192f4085d66ac383db864551155bffVirustotal results 35.00%Heodo
2020-09-04Rep-UW845841.docdoc 60417a3fac59e91bb0031c7e6fc97a808021296c159f11631bc3ac3e34ec5603n/aHeodo
2020-09-04file LOL399.docdoc 36ffaaac1fb3d49840166459ad272836f1add6d89d8733c4245582048c7b55d3n/aHeodo
2020-09-04Arc-20200904-9505175.docdoc 3616487fc9577f23d340266d9936a2e2553b1b9c340d3217345e74a4af603666Virustotal results 28.81%Heodo
2020-09-04Rep-20200904-UO396856.docdoc ac6a5c2f72c10af857d73db327000d07f01f791fe6638c339362584fe1293a4fVirustotal results 28.81%Heodo
2020-09-04list_975.docdoc be6a2393d8d58557a21737649e0977851d793862f1b80f1d27a1ee2ee70b3154Virustotal results 30.00%Heodo
2020-09-04160_2020_09_04_834.docdoc d7452abd23b4d0a252d67436bea5f98b177d6d4a707ce10ce71852940cf97a3cVirustotal results 28.33%Heodo
2020-09-04REP 2020_09_04 0031160.docdoc 533b65838696f229623a8367b9367b80001a7af8125899e324d550f4b4c64456Virustotal results 28.81%Heodo
2020-09-04mes-7806078.docdoc 794287d8176f07c6943cc4ca303d03de2ec84b37ff7262e148c0451087177c86Virustotal results 27.12%Heodo
2020-09-04Arc 2020_09_04.docdoc cba83b613d73f634da924685c3cfdd701edddbc80bd28399548cbdee1e5f4df1Virustotal results 25.86%Heodo
2020-09-04Untitled-2020_09_04-MND031.docdoc e04a181d4f71e29d0e1dd60e7ddaa50e20047dff94667fefcd0f582f5e3203a3n/aHeodo
2020-09-04File-FAA8050.docdoc 3b8964cde0e41b835a06f77a2d1834dac132f78cdebaf8b6e89214daf39b8752n/aHeodo
2020-09-04list_639.docdoc c27583344f73b13cb65d7c3cd67e313618cc794ef5b48f1db3e39adde0dd90c9Virustotal results 25.42%Heodo
2020-09-04Arc_2020_09_04_827352.docdoc 52a1f3085fece2adb5e447183da5a37ab0c90019b2237702ce65ead6ba03cf96Virustotal results 23.73%Heodo
2020-09-0422158605_279.docdoc f7347d7eb634ea2c2bdeb69d026c099ca12acf563a5b6681e6467ce9c7260619n/aHeodo
2020-09-04Attachment 2020_09_04 1663.docdoc 6b6138015363422437174a3e66d6fe9830722c6af61b695c5bef3200fe97a98bVirustotal results 21.67%Heodo
2020-09-04INF-21037.docdoc eae2a3c4e7a60e5476ac2c92926540cf3c70568a318f1a20a996ebeb53e8749bVirustotal results 26.67%Heodo
2020-09-04YQ7611-2020_09_04-1204729.docdoc 8f5f4ee85f4ddec3e575c12be4dc7594cb6d941c85bd06c9467e917a9d6a04f4Virustotal results 27.12%Heodo
2020-09-04arc_20200904.docdoc 8c4a8a1c7d4ddbfd0b727a5f169b6bc78e7997fd2b0947299d663a215bb3a9d9Virustotal results 27.12%Heodo
2020-09-04file-AHW78453.docdoc ca900ae40752b2a78feb23b6d8c3f29f674621fc5a6d90b99c3f2f2c6efbe075n/aHeodo
2020-09-04DAT_20200904.docdoc 9896f6412623c9c75887ccf147bc7461f10527fbfb3463272f2086e56cc0b645Virustotal results 26.67%Heodo
2020-09-04MES-2020_09_04-5396372.docdoc fd0d939541eb264d595d05201e003f4665e42c0066e74a244579ea23b2b9deeaVirustotal results 27.12%Heodo
2020-09-04file_2020_09_04_CO028860.docdoc 76edab16c0826931fc12090a44f6f773625fba9165acd2459a0e27eeabe00ceeVirustotal results 26.67%Heodo
2020-09-04DAT 2020_09_04 C9243.docdoc 4dd07b5f70becd9fa1cd8ebbb833f449c200db06f39d962f13d96d55f4e61802Virustotal results 23.73%Heodo
2020-09-04UNTITLED_2020_09_04_658329.docdoc e514ee40aaf58363f83b55c5bb9e01e591be5d5fbea0402363bfe659405e331an/aHeodo
2020-09-04file.docdoc 2f0f9e8cde5b53aa80b32d713adc28fff055196706c5e13da4e760a06873daffVirustotal results 23.73%Heodo
2020-09-04Attachments 2020_09_04 XDY13568.docdoc bfc004f7ac8d0c2e241dc8086e3e58fb542fcc47b5114ab614fa893199328acfVirustotal results 23.73%Heodo
2020-09-04rep 20200904 U72963.docdoc 6e80f8c0bcada5875b9aeb8c66983961fcf02d5d34173f58dc2a8834db676703n/aHeodo
2020-09-04mes.docdoc 47942152b879136b37f93a091fdc0995ae8dc63870ec7644620fc97205c8aa51Virustotal results 23.33%Heodo
2020-09-04Attachments.docdoc f372c016209e74fc743edffac2666aff370e45615c65b28ec1ddb77efcbd87a0Virustotal results 23.73%Heodo
2020-09-04dat-90629.docdoc d9c975b6db619552db6df9461b3c0947dbeb829698591386f2c86994a414e005Virustotal results 23.33%Heodo
2020-09-04arc Z66399.docdoc dd4feaa43e89898264a8512b2339c67fb1207b97e5c6c216fe656ff6234c0098n/aHeodo
2020-09-04list-2020_09_04-B7370.docdoc d38918707adc1b43963df18c7c3483e35cb906f58221fbe54adcbf770706feafVirustotal results 21.67%Heodo
2020-09-04Rep-20200904-W841846.docdoc a116a068131b7ef0d015c07614c3e6f346f604fd7d9b5b974b9f09a997916732Virustotal results 44.07%Heodo