URLhaus Database

You are currently viewing the URLhaus database entry for http://tomreif.de/cgi-bin/http://Scan/7GFnJaPHFU2oaa/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453359
URL: http://tomreif.de/cgi-bin/http://Scan/7GFnJaPHFU2oaa/
URL Status:Offline
Host: tomreif.de
Date added:2020-09-04 14:56:12 UTC
Last online:2020-09-04 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 14:58:03 UTC to abuse{at}strato[dot]de)
Takedown time:3 hours, 19 minutes Good (down since 2020-09-04 18:17:13 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04ARC 2020_09_04.docdoc 1aa05e276c9fc45289cfe940287e1141128258a93052f3ac4d5d7b78c9b0f15cVirustotal results 36.67%Heodo
2020-09-04doc-2020_09_04-9319950.docdoc cc4f7c86201d0618e4cc76f2030913800e738cb4a46496daa65e8f3507b3e12dVirustotal results 35.59%Heodo
2020-09-04REP.docdoc 4caf5eb87b69a8e37c3524c776870ace2c3a187f6d4956a9cf441148c4dc75cbVirustotal results 35.00%Heodo
2020-09-04Attachments 2020_09_04 SPL996.docdoc a7f35b06b6d94b7aacb7aaf4681b81b3373a4051b74e97e01ae6d58a2f052b27n/aHeodo
2020-09-0423510786 42348.docdoc e4006ffd7617f48dca3ed5e7220e159de2160b07f86452e1fcb7fa0f27ed1d9an/aHeodo
2020-09-0470312-2020_09_04-8782.docdoc 10fa2f7a4aa981b8f214a0875399cbb3052961541bc988e45faa9ffa346689c3Virustotal results 35.00%Heodo
2020-09-04dat L019484.docdoc 2de84dc5866a028c50d2092b83ad65d0377d6419786fcd9b87c75a624600ebcfVirustotal results 34.43%Heodo
2020-09-04REP_20200904_ZW935.docdoc 7ba727e56ef8d6bd90965dcbe4450880fd516019d4c10f8a5d101541aa883dfan/aHeodo
2020-09-04Dat LNW591068.docdoc 60417a3fac59e91bb0031c7e6fc97a808021296c159f11631bc3ac3e34ec5603n/aHeodo
2020-09-04LIST_20200904_EQ63022.docdoc 36ffaaac1fb3d49840166459ad272836f1add6d89d8733c4245582048c7b55d3n/aHeodo
2020-09-04REP 2020_09_04 M8867.docdoc 9b5118c972be1fdccab96caaa3644530d5a73cefcb8b7a048497c43b3e1867daVirustotal results 29.51%Heodo
2020-09-04List 2020_09_04 971905.docdoc edbc22e742e12b2af45a775673812f2c751b4f9071a83b9565d3d547fa380655n/aHeodo
2020-09-0473840 20200904 847.docdoc 0568526f45b6dc177cf7e11a8bf286cdd2b253a794da1153795aeec136ba3313Virustotal results 30.51%Heodo