URLhaus Database

You are currently viewing the URLhaus database entry for https://kreckel-gebaeudetechnik.de/wp-admin/http://paclm/TosiYxTjVon8fKBHzOeV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:496437
URL: https://kreckel-gebaeudetechnik.de/wp-admin/http://paclm/TosiYxTjVon8fKBHzOeV/
URL Status:Offline
Host: kreckel-gebaeudetechnik.de
Date added:2020-09-14 13:48:03 UTC
Last online:2020-09-18 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-14 13:50:04 UTC to abuse{at}alfahosting[dot]de)
Takedown time:3 days, 20 hours, 42 minutes Bad (down since 2020-09-18 10:32:37 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14mes_HO656223.docdoc 8014f6ab3e277e6346b2e49fae79962948c0b264e7000be259601b0b715b3e15Virustotal results 25.42%Heodo
2020-09-14Attachments-00647.docdoc 5171e0e602e27c4122239e9c7833c603beebb69bea148c5d29341990af469f55n/aHeodo
2020-09-14MES-4455.docdoc 04c3ce2f282ed4ed9c831c5caff0edc29324dbd2eb39817fc6ed53683c5e0933n/aHeodo
2020-09-14Attachment 20200914 XAN6835.docdoc af97130a26e7f04986307f790831a98329191a9c9464682173a96dc1506af3c0n/aHeodo
2020-09-14File.docdoc 707c1063c30249706f5b47d56c8d6b057f13c1ba249b6fb0a9e86fced1ccc340n/aHeodo
2020-09-14DAT-2020_09_14.docdoc 1b861fc89bf8e49013023f4458519f13803bfabb2b4eff3e63cb209f31406192n/aHeodo
2020-09-14Mes 20200914 HOT700835.docdoc 63ab439cb5788c279996c35d7e41341081f97dadb4b255653cb11194a9368465Virustotal results 20.34%Heodo
2020-09-14doc_122.docdoc c0d7a02d33e12631b692222d46bf3ea21a3a4e6c0964e5508bdb25148af88689Virustotal results 20.34%Worm.Ramnit
2020-09-14Dat-B67416.docdoc 83467069c2ec2cbe80e57095585d63441d9ebb7ade6e634ebc31eab616f5580en/a Heodo
2020-09-146259KU 2020_09_14 9637.docdoc 30dd2df0674e842f8a3bfd8880f538175f2f42045d66060984f720b865acd353Virustotal results 20.34%Heodo
2020-09-14Rep_Q41963.docdoc 63b43136ec0bf182f4b07471caca8638ca1fc5697c472b6ec14bd98cca7f83d2Virustotal results 20.34%Heodo
2020-09-14mes_20200914_6082.docdoc ed2623cbc3ddc280a2d77c1be9f87c90240c7ea5c9a4e9c6dcfa66b3194d1e1cVirustotal results 20.34%Heodo
2020-09-14arc 2020_09_14.docdoc 922d0848bdeb45de8993cf7663e729ccc87c4b6f7c93ece47472e9cd8cce416an/aHeodo
2020-09-14mes 20200914 J94555.docdoc 0cf52559a9a78a8c8be555f2bee5c45e2366e7de21f1864cd8b9ea50e0afac76Virustotal results 21.15% Heodo
2020-09-14UNTITLED_DNJ476.docdoc d79cae016737b238ca078cfa9e76a3e45c70f69f4a9db41d42e9af7d15872892Virustotal results 18.03%Heodo
2020-09-147353KN 20200914 7767955.docdoc 3c58efa8a1ff50a1c91b091da3d10d88c300e014f0685c2d003132d3aa4b4fedn/a Heodo
2020-09-140724591 810.docdoc b7c1d330ae0704a55e88453febc87487493166e74f41e8858126b915c055ed5cn/aHeodo
2020-09-14arc-2020_09_14.docdoc baaec5d00f7f89c68159655fef4d04a1aec9f20f1e49dcbdaa26c1e1ae9e185dVirustotal results 21.67%Heodo