URLhaus Database

You are currently viewing the URLhaus database entry for https://obazda.de/WebCalendar_01/statement/wi6qqc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453433
URL: https://obazda.de/WebCalendar_01/statement/wi6qqc/
URL Status:Offline
Host: obazda.de
Date added:2020-09-04 17:28:13 UTC
Last online:2020-09-04 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-04 17:30:03 UTC to abuse{at}strato[dot]de)
Takedown time:5 hours, 11 minutes Good (down since 2020-09-04 22:41:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04REP_GC9247215196GO.docdoc fab2e15b24926b36896f0aae619e19001af9577998f0e99344f1326faf43d174Virustotal results 23.73%Heodo
2020-09-04LQJ_090120_CTB_090520.docdoc b5533222607313c1e5318c308f318224a53034815f0c64c398f7a47c3a022efdVirustotal results 37.29%Heodo
2020-09-04REP_PO_09052020EX.docdoc b24e807d0df1eadd028e3819c82a02a484506947497651f366a72b832ca55c24Virustotal results 35.00%Heodo
2020-09-0464596525.docdoc bd40eb02dfb6582a0297389d221e0c4e0438e0e49084f6b38a362f9e0ed59d0fn/aHeodo
2020-09-04BAL_8OS1SZP6YP4.docdoc 36175bb468657b427148c493fa79bd8b5a274d61b18bf20ae6de60800a42e644Virustotal results 37.29%Heodo
2020-09-04DOC_WPJ_090120_KMS_090520.docdoc be1651ad8264a417f9e3f2f89df8bbf80e55a587aafa5ede5ac068a3d485d87aVirustotal results 37.93%Heodo
2020-09-04UV0978877743JU.docdoc a2dab076b70c70fc0f7397b689b8f7a756a6379c65f8ea5a327ddcce4e2f9249Virustotal results 36.07%Heodo
2020-09-04OA2929529483GP.docdoc 25dd5ad245a3a2eac82fb0ad2ec67b0baa6c67e01d69e776fafb50eb35f26831Virustotal results 36.67%Heodo
2020-09-041DFN9TW74.docdoc 203b5367b3bf06f1b801c1c3321976fe1fcf2702a2413773b492878d541ebff2n/aHeodo
2020-09-04IW0R40K7QLUN.docdoc 0bf47bcf57e6b6b263747f0fdca169f668074843a9de60c73ebb09da12c05cf7n/aHeodo
2020-09-04REP_151308083636438.docdoc d23faf09d666b06ecc0248933f0050591863e4e0eca630cb4c1be7f58512fb3bn/aHeodo
2020-09-0448689815.docdoc fbd8470b180c9fd6fb38a881fc1a42abc34fade3e3dd008244ca9b64a1504103Virustotal results 37.29%Heodo
2020-09-04O_TVZ73GNY4BLYK6V.docdoc da9a6385696d505459b043b8444346c7faa2614fd5f77a0e0df5110774036e08n/aHeodo
2020-09-04INV_928159572.docdoc 4f6f3359cbdba3072a048313de3684b0c2aaeb1953ba5e0c00eb50559bc8895fVirustotal results 32.79%Heodo
2020-09-047C27IRZ5I.docdoc b704f4df9369996d3f77982e46cd1d4b080de1817ffbd8d68f5f4a82e16b1993Virustotal results 33.33%Heodo
2020-09-04DOC_41015007802743.docdoc 5b90408d4dc272f4943f37e60d8892e8663d56e2b299acec7cc5d8ad5be7a40cn/aHeodo
2020-09-04BAL_86673876370244370881751.docdoc a2fdc9abbb2377b367097472c437e5a8ffedbf8e9b27eaa1e230d8cde71f89f7n/aHeodo
2020-09-04DBVE_IV9222221596OX.docdoc c791268b0a93500d2bf73e476d673bb2f139cbe63c7cdc5fe1f0da8bbfa86f17Virustotal results 32.79%Heodo
2020-09-04BAL_2N1WZBD.docdoc edba780892af9b4115a69bc5a8672c4b09324ecad01675f92a1c8fd4812e8395n/aHeodo
2020-09-04YK1398902192XJ.docdoc 29ce21b8a404f4a438cefc6e06f270a37a526253db6f0e0dd1a4bc522fdbaa2fVirustotal results 33.33%Heodo
2020-09-04FILE_82201106.docdoc cc4eb556c04ba1e96f2e8fd7240565d2b2174baa0d01a4ab3411c71e22e2ac76Virustotal results 34.48%Heodo
2020-09-04DOC_KCK_090120_GST_090420.docdoc 91efffdc36b849d11fed8900519a1ad1033ca1caa5e80a9388f1a7ff3bbe4ee3n/aHeodo