URLhaus Database

You are currently viewing the URLhaus database entry for https://www.rechtsanwaelte-international.com/hio9qq/Overview/6b51fmv1073411181512p4yyttc6i8kj4/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:518132
URL: https://www.rechtsanwaelte-international.com/hio9qq/Overview/6b51fmv1073411181512p4yyttc6i8kj4/
URL Status:Offline
Host: www.rechtsanwaelte-international.com
Date added:2020-09-15 17:58:38 UTC
Last online:2020-09-15 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-15 18:00:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 20 minutes Good (down since 2020-09-15 19:20:35 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-15S_96865604458360959179.docdoc 1c6ce51748a1b4bdc97378a6091b03df69c39d6ec6185382608edd0355ae0bf5n/aHeodo
2020-09-15189465733132412184946.docdoc c8410c8dd820bc1e8805ba93260cd2fb0f7707d75573915bdb97ea2a01b66ea8Virustotal results 30.51%Heodo
2020-09-15INV_AS5817258828IT.docdoc 933b3518041b978efa6f14e957c5a72dbd62b3e460129c2eb6904ba09c1b8f17n/aHeodo
2020-09-15WMF_TMS_090120_OFV_091520.docdoc df8e3bb8218a241d663a81c536d1ce5f64b91ade8fb09dbdc183006ab9e901a0n/aHeodo
2020-09-15DOC_632536479.docdoc 4b30a75800dac8e687499541fa381736b76d3f3b69146ea8801962b7eec548bbn/aHeodo