URLhaus Database

You are currently viewing the URLhaus database entry for http://mtk-leuchten.de/bilder/http:/FILE/7NFaogDXWvx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453199
URL: http://mtk-leuchten.de/bilder/http:/FILE/7NFaogDXWvx/
URL Status:Offline
Host: mtk-leuchten.de
Date added:2020-09-04 10:31:10 UTC
Last online:2020-09-04 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 10:32:11 UTC to abuse{at}strato[dot]de)
Takedown time:12 hours, 36 minutes Good (down since 2020-09-04 23:09:00 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04file_2020_09_04_G547276.docdoc 8e545a370b86ee0cd6e5c447811aee200ae42181090a0a262326de62dd93aabfn/aHeodo
2020-09-04File_20200904_60038.docdoc d21d369a575521b056524693121464f2aa51cbbc0790a6b01069bae6bb4dbb32Virustotal results 35.59%Heodo
2020-09-04mes_20200904.docdoc 0cac10e553ca0da14b7f6e1bf4c0586be92226b4edb922d9d7a79fd366142df8n/aHeodo
2020-09-04doc-6626848.docdoc 0fd7dcfa200a1b0da02cc3578b15e97fdb192f4085d66ac383db864551155bffVirustotal results 35.00%Heodo
2020-09-04rep_2020_09_04_33789.docdoc b246ae5854fc909f2e54163de7a8e78ef5de5a8648ec2768c6533c0ad65a15d5n/aHeodo
2020-09-04File_20200904.docdoc 20f0a0ba4cd0dac615e918dd489d36a9dbe9da8eccd28074379ccb9297f44202Virustotal results 30.00%Heodo
2020-09-04FILE 20200904 734.docdoc 9c82f57cbccf6ba04020fd7828aff371796a2f69e908f5ecf8c25d921a13abf6Virustotal results 30.00%Heodo
2020-09-04Inf_GF538.docdoc ac6a5c2f72c10af857d73db327000d07f01f791fe6638c339362584fe1293a4fVirustotal results 28.81%Heodo
2020-09-04file L5065.docdoc 10120ac722ecdac5928884225db5f204e4e339196f5a48027e3bd623cb105542n/aHeodo
2020-09-04Doc_UV984213.docdoc d7452abd23b4d0a252d67436bea5f98b177d6d4a707ce10ce71852940cf97a3cVirustotal results 28.33%Heodo
2020-09-04Inf 20200904 400.docdoc 533b65838696f229623a8367b9367b80001a7af8125899e324d550f4b4c64456Virustotal results 28.81%Heodo
2020-09-04dat 20200904 OZ62695.docdoc cba83b613d73f634da924685c3cfdd701edddbc80bd28399548cbdee1e5f4df1Virustotal results 26.67%Heodo
2020-09-04FILE 2020_09_04 7212.docdoc e04a181d4f71e29d0e1dd60e7ddaa50e20047dff94667fefcd0f582f5e3203a3n/aHeodo
2020-09-04A58568-32327.docdoc 3b8964cde0e41b835a06f77a2d1834dac132f78cdebaf8b6e89214daf39b8752n/aHeodo
2020-09-04inf_2020_09_04_5369.docdoc 05d812b5dacd80bc461304d3f5e745b7522bf28e626b1e1e5ce3b864ebf64f35Virustotal results 25.42%Heodo
2020-09-04Attachments_2020_09_04_PFO4655.docdoc beb360bbf4f0bf929e1a8d6e734b006c12269cf4e034909c884cbdd8a9374c65Virustotal results 21.67%Heodo
2020-09-04Rep_20200904_CI07260.docdoc f7347d7eb634ea2c2bdeb69d026c099ca12acf563a5b6681e6467ce9c7260619Virustotal results 21.67%Heodo
2020-09-04rep_20200904_N731134.docdoc 6b6138015363422437174a3e66d6fe9830722c6af61b695c5bef3200fe97a98bVirustotal results 21.67%Heodo
2020-09-04doc-8401.docdoc 6d83e4ed7a8f8bd079a31dc5f9b7af78e7e0f1db5924c0639be90f94cca00848n/aHeodo
2020-09-04MES.docdoc eae2a3c4e7a60e5476ac2c92926540cf3c70568a318f1a20a996ebeb53e8749bVirustotal results 26.67%Heodo
2020-09-04Inf 20200904 D145661.docdoc 8c4a8a1c7d4ddbfd0b727a5f169b6bc78e7997fd2b0947299d663a215bb3a9d9Virustotal results 27.12%Heodo
2020-09-04937109 817.docdoc ca900ae40752b2a78feb23b6d8c3f29f674621fc5a6d90b99c3f2f2c6efbe075Virustotal results 26.67%Heodo
2020-09-0417182 9116280.docdoc fe091cf9eba180793119db32fe94d4816c743d95fe73f73f8f8a11df2cd0aadeVirustotal results 27.27%Heodo