URLhaus Database

You are currently viewing the URLhaus database entry for http://team-stark.de/cgi-bin/http:/Reporting/wfVSQbkjB9S5gcyLY/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453388
URL: http://team-stark.de/cgi-bin/http:/Reporting/wfVSQbkjB9S5gcyLY/
URL Status:Offline
Host: team-stark.de
Date added:2020-09-04 15:43:33 UTC
Last online:2020-09-04 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 15:44:22 UTC to abuse{at}strato[dot]de)
Takedown time:3 hours, 5 minutes Good (down since 2020-09-04 18:49:27 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04MES.docdoc 380c46aa7a6ebfb32b4e005930aa368ca90386ecf02e2587a0c6f035569df404Virustotal results 35.00%Heodo
2020-09-0430138 ZKS2413.docdoc a49d6ff985f57e4d6e09893b343f97b9da664ae8c0b7c0e95f18f1a8f119f1a8Virustotal results 35.00% Heodo
2020-09-04file 674393.docdoc 8a87e7dcaf07545941e8f4859526c55f0b840dc1d051e86b09200a3a49ba5c01Virustotal results 35.00%Heodo
2020-09-04Untitled 20200904 5234197.docdoc ad900916e28aeb4c2f84553981f044e225eb4864a9551af10c38733d1f13b7a9Virustotal results 35.59%Heodo
2020-09-04930446 B46773.docdoc 403170a4ca043be478bde432c994bc04e0ec0bb95f4d457928890829a998e46aVirustotal results 35.00%Heodo
2020-09-04KM160_A650.docdoc 530c8a300c489e40c554fb9c0be1d28633675699b2a84b520ff020fcebcf964dn/aHeodo
2020-09-04doc-E9950.docdoc d21d369a575521b056524693121464f2aa51cbbc0790a6b01069bae6bb4dbb32n/aHeodo
2020-09-047034-604965.docdoc 0cac10e553ca0da14b7f6e1bf4c0586be92226b4edb922d9d7a79fd366142df8n/aHeodo
2020-09-04dat-575666.docdoc 00a7e0634054721fe9f4467f8843d3558c3694215da05f6027c8444786c55d21Virustotal results 35.00%Heodo
2020-09-04Inf-4286320.docdoc 8272ec5255ec5c1be616ff13df325ee1016d5d40bb129a6687709dfadcc1b3dcn/aHeodo