URLhaus Database

You are currently viewing the URLhaus database entry for http://qualitysale.de/cgi-bin/invoice/158pglb87b7v/ysmxphb7985149806234i8i7zb62n/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453378
URL: http://qualitysale.de/cgi-bin/invoice/158pglb87b7v/ysmxphb7985149806234i8i7zb62n/
URL Status:Offline
Host: qualitysale.de
Date added:2020-09-04 15:42:33 UTC
Last online:2020-09-04 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-04 15:44:25 UTC to abuse{at}strato[dot]de)
Takedown time:6 hours, 4 minutes Good (down since 2020-09-04 21:49:23 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04BAL_IBR_090120_RIH_090520.docdoc b68a67814fb5dc91945cdd229252bd373e46dc667e3f5c91e37f1ffe0fb546d3Virustotal results 38.98%Heodo
2020-09-04DOC_PO_09052020EX.docdoc 488084a5306809fbf4d102c1b8894888183834ddbd816b9b0b4816e2e062d559n/aHeodo
2020-09-04DOC_002779083229602112563.docdoc a7680798d59287fd95857a80ad4476ee4e1a98ed04c97a6afcfa5f523ab1ecccVirustotal results 36.67%Heodo
2020-09-04PO_09042020EX.docdoc 0fc7be2a9f6e2bd7d080d5d7f6f609dc5281c52980e7d2871d6c8658a9980e83Virustotal results 36.67%Heodo
2020-09-04333059974005644.docdoc 4ef546f286f47adeb1332f3d817a9aaf39d7ecc531a022b9791eb14fc9de79acVirustotal results 36.67%Heodo
2020-09-0492548609.docdoc 0ccc2086f49d393bf08092469d40a557d9b68c3653500e5826e7479b69b84c6aVirustotal results 37.29%Heodo
2020-09-041UFIRVMLE.docdoc 9c3e1b5dbb4688d70bc0ef062f2996d616f5b751f53ef4b38143b85c9fb580a5Virustotal results 37.29%Heodo
2020-09-04PO_09042020EX.docdoc 07389e60fd9ae8ed3322e4d0d71325e58d8beabc1b3a0e18bbcfc7984505e598Virustotal results 36.67%Heodo
2020-09-04BAL_PO_09042020EX.docdoc 0885a2c59985b958177938ea4e58d7fb455576cdb7c36958e0207b29f7f52931n/aHeodo
2020-09-04H_0SEBU5UAT.docdoc 0a5690b216f895e3721c8a4309a53c779fa420b6f40d510309d69d27ffaa84a7Virustotal results 34.48%Heodo
2020-09-04KW6203463958VI.docdoc c0ebd4f4800e02d34a1683ffd2a8cc258fab1c366128b0d215a0e202c09c41beVirustotal results 34.48%Heodo
2020-09-04INV_6608375870541900314.docdoc 3c7a208b5ecb94b5f4898a79d64d135bfda7146519b6a41921f5e1261ffe35fdn/aHeodo
2020-09-0434EATEAFF1W0X.docdoc 5b90408d4dc272f4943f37e60d8892e8663d56e2b299acec7cc5d8ad5be7a40cn/aHeodo
2020-09-04DOC_5DK1QFKRV.docdoc 1ecdc1acc0c1afdbecca2c795c66cf57d8e5ad15c009c5adb31d12cc84b534e6n/aHeodo
2020-09-04INV_PO_09042020EX.docdoc cfe4b358946c9eef325f5aa66f80f7db38ac84fbd985117f1bbf039bba8a3d9fVirustotal results 33.33%Heodo
2020-09-04IGI_090120_HCR_090420.docdoc 3212bb6c80b78835f1e18093791987c2ad8b31e57c295a67264ca87c4edb0ad2n/aHeodo
2020-09-04INV_39737421.docdoc 711a615e79799f24e918d2e3a293d0082ae23fa3851e91ee4957edf5ec2a13d7n/aHeodo
2020-09-04DOC_PO_09042020EX.docdoc e627d5445b586181f22e9b1c5890b35c8ec027b86c72566fb2b9a685c10727ebn/aHeodo
2020-09-04Y_88221013.docdoc d169126647bf6fe90d0e90306d1ae982fec9fef406b5a333cdaae8502061d076Virustotal results 33.33%Heodo
2020-09-04REP_GBI_090120_NBE_090420.docdoc 121bf03a4ab3c4b45e699994504ce2bc327aea720cbac22a23c8b3fbf220e5a2Virustotal results 33.33%Heodo
2020-09-04BAL_CTI_090120_WXC_090420.docdoc 977366194325b4a4c3d8ad98446a5a9741e25eae89523b7e3d1b19696e92ef09Virustotal results 33.33%Heodo
2020-09-04FILE_CZB_090120_WBO_090420.docdoc f19b7c3502d8e70e4a41fc4676cf0ba7a1de47cc19b1e961be4ceb8511119637Virustotal results 56.14%Heodo