URLhaus Database

You are currently viewing the URLhaus database entry for http://photobook-design.de/MGB_01/swift/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453420
URL: http://photobook-design.de/MGB_01/swift/
URL Status:Offline
Host: photobook-design.de
Date added:2020-09-04 16:44:33 UTC
Last online:2020-09-04 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 16:46:02 UTC to abuse{at}strato[dot]de)
Takedown time:5 hours, 33 minutes Good (down since 2020-09-04 22:20:01 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04DOC_FQ2530552907MY.docdoc f18ff8cfb93f2419e011a417660bd7614759b69800071a018b318d2aa29c94ccVirustotal results 37.29%Heodo
2020-09-04BQYY_HZH_090120_OME_090520.docdoc a0f35af9f069a6bbda4bbbe47e5bd86255d33fe49f8c47a25d5895791accdce4n/aHeodo
2020-09-04REP_SA0640269416CW.docdoc 59fdddd7d14174695b3060a24099fb534d15016cfee986d9a0ab15d779102b66Virustotal results 37.29%Heodo
2020-09-04DOC_PO_09052020EX.docdoc 488084a5306809fbf4d102c1b8894888183834ddbd816b9b0b4816e2e062d559n/aHeodo
2020-09-04RVZM_XM2OCN1I4WI2.docdoc b71d3ce293b081d491b3ba9de486a93bba7064927ffb7ca4578925f18f319785Virustotal results 36.07%Heodo
2020-09-04K6PCIP9.docdoc d63243bbf6aaf08d0f887d546e29bac2af6459e3439674829c8e7afc06c08741Virustotal results 36.07%Heodo
2020-09-04REP_72334513.docdoc 0ccc2086f49d393bf08092469d40a557d9b68c3653500e5826e7479b69b84c6aVirustotal results 37.29%Heodo
2020-09-04FILE_JP977ML2N.docdoc ff8230b7f22355e9b7dc756bd91dd70448c5cbf51ea66742d5340cdd588105aeVirustotal results 37.29%Heodo
2020-09-04W71KPKRXX.docdoc 9c3e1b5dbb4688d70bc0ef062f2996d616f5b751f53ef4b38143b85c9fb580a5Virustotal results 37.29%Heodo
2020-09-04FILE_PO_09042020EX.docdoc f6176c22c0dedb27565ce220ac7b9815469179392bb92fbe785be55cd43400ceVirustotal results 36.67%Heodo
2020-09-04FILE_PO_09042020EX.docdoc 02dfcb241425a1573bdaa28cefb98b7ad06913ea17c20ab173ead3402c03e12fVirustotal results 37.29%Heodo
2020-09-04FILE_IQ2163285412OX.docdoc 0a5690b216f895e3721c8a4309a53c779fa420b6f40d510309d69d27ffaa84a7Virustotal results 34.48%Heodo
2020-09-04REP_VB7164632101AF.docdoc 5dd7cb7722d8fbc0dd1e2c9e3faa7f7c0839734b00d04ee5b4fb1a6c09ab77d5n/aHeodo
2020-09-041907020686168.docdoc 97bb1c59501002142251c3e28b9a7a28febcea71e35e8bec59f15296fff0f412n/aHeodo
2020-09-04IT_621494424434375261.docdoc 5b90408d4dc272f4943f37e60d8892e8663d56e2b299acec7cc5d8ad5be7a40cn/aHeodo
2020-09-04REP_KS1082726399QE.docdoc 8e57b65aa7cd3ca879219c76cafd4a747337352074fab3ebce5e8e22e33f2303n/aHeodo
2020-09-04REP_PO_09042020EX.docdoc 47ca2839fce4d38bf92de1f1e4112489433026b8a2622976d5dcfe4115f3d71bn/aHeodo
2020-09-04FILE_FV3629615304YT.docdoc 29ce21b8a404f4a438cefc6e06f270a37a526253db6f0e0dd1a4bc522fdbaa2fVirustotal results 33.33%Heodo
2020-09-04INV_YZT_090120_ELX_090420.docdoc a6179f17ba48ce0db04103f2d85634c0689b34ecefd82041c40a47119d91b4b3n/aHeodo
2020-09-04NYN_NCA_090120_UMZ_090420.docdoc 478c0a63a9f6339a032b46388e0228f0306a3be3f5938e8018e26169347460e3Virustotal results 33.90%Heodo
2020-09-04FILE_DI7363814763SX.docdoc 211a1d1f7c9c1a2dc01d0438bb0aae153f85a084521a19e74c0dfc1cc8047b40n/aHeodo
2020-09-04DNH_WQD_090120_FKS_090420.docdoc a227569c5807e9c5cd458bd007b476f167c46ff6544302690f81d5f50bd39566n/aHeodo
2020-09-04SK8798540278WA.docdoc f7bb8be96294b15193d75301ca597b0d3aa8fab27d68eb008b7ee0b300fe23c6n/aHeodo