URLhaus Database

You are currently viewing the URLhaus database entry for http://woitl.de/cgi-bin/https:/Overview/i4LejrfHLZK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453204
URL: http://woitl.de/cgi-bin/https:/Overview/i4LejrfHLZK/
URL Status:Offline
Host: woitl.de
Date added:2020-09-04 10:31:14 UTC
Last online:2020-09-04 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 10:32:16 UTC to abuse{at}strato[dot]de)
Takedown time:7 hours, 1 minutes Good (down since 2020-09-04 17:33:19 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-046158DWX 20200904 6956087.docdoc ed63266e67ad9944d1501d2221c8390e1585ed5aed9397212441db07dea0b7e9Virustotal results 25.42%Heodo
2020-09-04dat.docdoc 70cc4a26d40d9e224b57ee8a33fcdc4d45006e8d9c3fba8a851d735ae5cc1bf3n/aHeodo
2020-09-04Attachment 90034.docdoc 22541ac301b5c8fdf15f74cc06df0c5a237bfe5593f910699acdaa3ae869edd9Virustotal results 25.42%Heodo
2020-09-04Dat-2020_09_04-38974.docdoc 6ba1180f37e95dd4238a52435a56d2cb1483ed9a34af53b44e0fecd5863244ebVirustotal results 25.86%Heodo
2020-09-04list_347.docdoc 52a1f3085fece2adb5e447183da5a37ab0c90019b2237702ce65ead6ba03cf96Virustotal results 23.73%Heodo
2020-09-04arc-2020_09_04-F866.docdoc f7347d7eb634ea2c2bdeb69d026c099ca12acf563a5b6681e6467ce9c7260619Virustotal results 22.41%Heodo
2020-09-04ARC_20200904_662160.docdoc 0b32acf0a3322fe655fc8ea7251ece0b782a819ae84d5819cbd4f1e2ce7fb031n/aHeodo
2020-09-04list 20200904 5773756.docdoc c737b9843d1bd4e6071bdecec3832cb009922c322cb71ca5b8fb1f3af0febbc1Virustotal results 25.42%Heodo
2020-09-04dat 2020_09_04 201572.docdoc 1c67628b01a329488b609ce13ceba3610a0d79cfe6bdb3d6750f714ffc97f27fn/aHeodo
2020-09-04ARC FS883.docdoc eb2264ac02ea6f6ca9efed74315f140e86357be821112bba1c3b3a1f8b70e8c5Virustotal results 27.12%Heodo
2020-09-04List.docdoc ca900ae40752b2a78feb23b6d8c3f29f674621fc5a6d90b99c3f2f2c6efbe075n/aHeodo
2020-09-04Mes_20200904_949.docdoc fe091cf9eba180793119db32fe94d4816c743d95fe73f73f8f8a11df2cd0aadeVirustotal results 27.27%Heodo