URLhaus Database

You are currently viewing the URLhaus database entry for http://sayn-net.de/MAF/ajg6m179276615913067228knxo8ec4u10h02d/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453375
URL: http://sayn-net.de/MAF/ajg6m179276615913067228knxo8ec4u10h02d/
URL Status:Offline
Host: sayn-net.de
Date added:2020-09-04 15:38:03 UTC
Last online:2020-09-04 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-04 15:40:04 UTC to abuse{at}strato[dot]de)
Takedown time:5 hours, 43 minutes Good (down since 2020-09-04 21:23:28 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04FILE_JW3607937787SO.docdoc d7f2e39f16e7bf996bc135501fde79fc5150321ac5b286527043ceba49ded0acn/aHeodo
2020-09-0444256036.docdoc 58d07d4495dc0a6bfd46263f25301032d3562ca22a5cf2ea19e557d9e58b89e4Virustotal results 37.29%Heodo
2020-09-04BAL_XP3235613519JH.docdoc 4ef546f286f47adeb1332f3d817a9aaf39d7ecc531a022b9791eb14fc9de79acVirustotal results 36.67%Heodo
2020-09-04JHN_090120_WQV_090420.docdoc 0bf47bcf57e6b6b263747f0fdca169f668074843a9de60c73ebb09da12c05cf7Virustotal results 36.67%Heodo
2020-09-04Q_554473336069450095834.docdoc f6176c22c0dedb27565ce220ac7b9815469179392bb92fbe785be55cd43400ceVirustotal results 36.67%Heodo
2020-09-04HMU_PO_09042020EX.docdoc d6a1d2e702932301249df94cd301c2dac672fb7ccdf1185b69666fc7e19f1839n/aHeodo
2020-09-04GG7973085266PA.docdoc da9a6385696d505459b043b8444346c7faa2614fd5f77a0e0df5110774036e08n/aHeodo
2020-09-04FILE_PO_09042020EX.docdoc be7359d5f34e145487cc45d11a463a8826b0aabbf7a8da0bcd9b4498bd6d3974Virustotal results 32.20%Heodo
2020-09-04FILE_PO_09042020EX.docdoc c0ebd4f4800e02d34a1683ffd2a8cc258fab1c366128b0d215a0e202c09c41ben/aHeodo
2020-09-04HC7875295347QA.docdoc f2bcc6d8340a374e5ab78dc34f0ee3466bf303f6f77532bf94033595f3fff21bVirustotal results 33.33%Heodo
2020-09-04PO_09042020EX.docdoc 3c7a208b5ecb94b5f4898a79d64d135bfda7146519b6a41921f5e1261ffe35fdn/aHeodo
2020-09-04PO_09042020EX.docdoc a2fdc9abbb2377b367097472c437e5a8ffedbf8e9b27eaa1e230d8cde71f89f7Virustotal results 33.33%Heodo
2020-09-04UL8278055612QX.docdoc 4d13bae45c5b53ec799d6cb16c7b8ba1964b3f47d368d5a9a47afa34f682bcfcVirustotal results 35.00%Heodo
2020-09-04REP_3H6ZNE8RFL.docdoc 3212bb6c80b78835f1e18093791987c2ad8b31e57c295a67264ca87c4edb0ad2n/aHeodo
2020-09-04BAL_197825921308721587.docdoc 711a615e79799f24e918d2e3a293d0082ae23fa3851e91ee4957edf5ec2a13d7n/aHeodo
2020-09-04REP_12064506.docdoc 308d65483edaee979e4cbe7b8dcbb65535fdb089adb31687e325468799efcaf8Virustotal results 33.33%Heodo
2020-09-0414676073.docdoc d169126647bf6fe90d0e90306d1ae982fec9fef406b5a333cdaae8502061d076n/aHeodo
2020-09-04BAL_947723328483815766084.docdoc 1f6f3c784ec6ee8969c3aac23ab2148dcf84e02af8cd0902378fab552399f9f5Virustotal results 33.33%Heodo
2020-09-04FILE_60432624501800517618.docdoc f19b7c3502d8e70e4a41fc4676cf0ba7a1de47cc19b1e961be4ceb8511119637Virustotal results 56.14%Heodo