URLhaus Database

You are currently viewing the URLhaus database entry for http://pdftechnik.de/bilder/OCT/1dkqgfa22c4/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453429
URL: http://pdftechnik.de/bilder/OCT/1dkqgfa22c4/
URL Status:Offline
Host: pdftechnik.de
Date added:2020-09-04 17:17:33 UTC
Last online:2020-09-04 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 17:18:02 UTC to abuse{at}strato[dot]de)
Takedown time:4 hours, 49 minutes Good (down since 2020-09-04 22:07:09 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-0416160752200855812.docdoc 76169ff374a9346a75d77ab68b5e4d9565aae56d2b73736ddde1a02bd95dd5f2n/aHeodo
2020-09-04WUM_090120_FDM_090520.docdoc 135937e63e99259fbedd9a7fade8e7735873996e876d16a95e9eb3b634b3e926Virustotal results 35.59%Heodo
2020-09-04REP_665104471094833925.docdoc b68a67814fb5dc91945cdd229252bd373e46dc667e3f5c91e37f1ffe0fb546d3Virustotal results 38.98%Heodo
2020-09-04S_VSS_090120_NEG_090520.docdoc 488084a5306809fbf4d102c1b8894888183834ddbd816b9b0b4816e2e062d559n/aHeodo
2020-09-04J_36672141.docdoc 5ca09a4a4928ed469d1e0eb9dacd92fe2003d0551aeb380a0c662ced78d6fa25n/aHeodo
2020-09-04VQMO_WZ5848815241XI.docdoc 0fc7be2a9f6e2bd7d080d5d7f6f609dc5281c52980e7d2871d6c8658a9980e83n/aHeodo
2020-09-04DOC_VF5950000901AH.docdoc 4ef546f286f47adeb1332f3d817a9aaf39d7ecc531a022b9791eb14fc9de79acn/aHeodo
2020-09-04KSA_090120_GEX_090420.docdoc 0ccc2086f49d393bf08092469d40a557d9b68c3653500e5826e7479b69b84c6aVirustotal results 37.29%Heodo
2020-09-04BAL_58112637.docdoc 9c3e1b5dbb4688d70bc0ef062f2996d616f5b751f53ef4b38143b85c9fb580a5Virustotal results 37.29%Heodo
2020-09-04INV_85404561.docdoc 07389e60fd9ae8ed3322e4d0d71325e58d8beabc1b3a0e18bbcfc7984505e598Virustotal results 36.67%Heodo
2020-09-04X_NDF_090120_TOE_090420.docdoc 02dfcb241425a1573bdaa28cefb98b7ad06913ea17c20ab173ead3402c03e12fVirustotal results 37.29%Heodo
2020-09-04T_NVW_090120_OFE_090420.docdoc 4bdad9499437443baa2a71d4808d355930f5c949852bfec67101ae162a82c7cfn/aHeodo
2020-09-04NL_DMR_090120_HVU_090420.docdoc a14214bead0b435c93476d9245847a8b29a8b8469f46ddd6a6df86bdab98fb13Virustotal results 33.33%Heodo
2020-09-04REP_PL3276YC.docdoc 5b90408d4dc272f4943f37e60d8892e8663d56e2b299acec7cc5d8ad5be7a40cVirustotal results 33.33%Heodo
2020-09-0456752214.docdoc 9e9a89d616455743a0c134eff34320dad3175249759882bc92c74f96870138bdVirustotal results 33.33%Heodo
2020-09-04REP_22898447775109050698143.docdoc 1ecdc1acc0c1afdbecca2c795c66cf57d8e5ad15c009c5adb31d12cc84b534e6Virustotal results 33.90%Heodo
2020-09-04REP_NXE_090120_HBE_090420.docdoc c68c4fb470840f03164aa5305731b0fd436fac4fa91316fa01c9ddd67b462dd1Virustotal results 33.33%Heodo
2020-09-04FILE_14284347.docdoc 29ce21b8a404f4a438cefc6e06f270a37a526253db6f0e0dd1a4bc522fdbaa2fVirustotal results 33.33%Heodo
2020-09-04DOC_VG2940301290VH.docdoc a6179f17ba48ce0db04103f2d85634c0689b34ecefd82041c40a47119d91b4b3Virustotal results 35.09%Heodo
2020-09-04REP_856798981.docdoc 91efffdc36b849d11fed8900519a1ad1033ca1caa5e80a9388f1a7ff3bbe4ee3n/aHeodo
2020-09-04DOC_B0WENXA.docdoc a9ddc5074e8a38aa9ec39846f6c072de90ed94426903fa6d6aefe3d2c9365d69Virustotal results 33.90%Heodo