URLhaus Database

You are currently viewing the URLhaus database entry for https://beletage-berlin.de/how-to/rgrjpl6yqvl1/vp9lg8lwow/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:694733
URL: https://beletage-berlin.de/how-to/rgrjpl6yqvl1/vp9lg8lwow/
URL Status:Offline
Host: beletage-berlin.de
Date added:2020-10-14 22:47:04 UTC
Last online:2020-10-15 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 22:48:02 UTC to abuse{at}contabo[dot]de)
Takedown time:15 hours, 54 minutes Good (down since 2020-10-15 14:42:49 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-15GPE_28383811.docdoc 149107eec47eec15d6160353b5102a17c8b552474e89828511de257fd78d3a52Virustotal results 33.87%Heodo
2020-10-15REP_31476345.docdoc 5d3017d4878e28f04f39fe176de060a002b3f4752644eeb98f04ee2593d259dbVirustotal results 32.26%Heodo
2020-10-15REP_93588213753209484768.docdoc a251d76425f1841e17b9efa9ab58b8a0f26c25f997500348b2c5a7cac89daa78Virustotal results 33.93%Heodo
2020-10-15DOC_732904218312031.docdoc bfa26a715bd9a8a6890d9037bc8c675e67a0a18e04386dc88dfaf89218ab9d67n/aHeodo
2020-10-15FILE_56190299035878489.docdoc 760ea4f40eb97c7d6210b13d52fd6d6159b4ebfc38bec62527ab2931b526cf02Virustotal results 32.26%Heodo
2020-10-15PO_10152020EX.docdoc 80c025b2d6a2583c14ce7a33a18b2925953d29b7809e0ac305b3ccad81d4713aVirustotal results 33.90%Heodo
2020-10-1566793578.docdoc 1cc454d75dc586cd5025eab16ed2a8097e3d412f9efb96ddd568041631aa0ebcVirustotal results 45.00% Heodo
2020-10-15T_PO_10152020EX.docdoc bcd20ead58694ee7adb822b6a4c40c62433fc6ca968f2a728a7e10fd21d0d1b1Virustotal results 37.10%Heodo
2020-10-15LPH_100120_UHX_101520.docdoc 0acbd96443e33ed3c7bb5928e381f4440eb99308be50ab1a869a7bc118e57076Virustotal results 32.79%Heodo
2020-10-15865331477192810797767.docdoc 25aa35b354712a75a1fa86936a9f4195ea8e3c08a6e6f2c3b9820cb4dd28209dVirustotal results 37.10%Heodo
2020-10-15REP_19735814.docdoc 100b400505d67803dd47e7093247e44637dade8df24255e8fd14b80a78f77533Virustotal results 34.43%Heodo
2020-10-15DFG_700759276538154456011277.docdoc fd12780ca0e4c591da35bf3d215c22a47050b1a68e524ce4d0434ee2414cbf3aVirustotal results 32.26%Heodo
2020-10-15T_PO_10152020EX.docdoc 1790c5fab1f40df300b33f400baa6f3981447142c4368a43e01a5b76b1beed3aVirustotal results 31.67%Heodo
2020-10-151607078902256406154.docdoc cca3799a5d79aad049795ea6a869e22d90d248ef1c1193d5d5933237b20157c5Virustotal results 32.26%Heodo
2020-10-15BAL_14909213.docdoc 6d531c0d2bfa18875d304220ef3fc95e74bd8f98c539ceb1755245c2394e0b31n/aHeodo
2020-10-15BAL_PO_10152020EX.docdoc f2749bfcb47ccd5ca2d9a1a0707ed06064ceb9ad0549c3bbff8475d01668d9b5Virustotal results 29.51%Heodo
2020-10-15EXX_DRP_100120_JXS_101520.docdoc 5b4c47d73226347391f06e552ff9caa035e74cdcd652ac424c4364ab6fcca280Virustotal results 35.48%Heodo
2020-10-14BAL_XGX_100120_LOK_101520.docdoc b1380f1fdf3f7636d79043feef8f62d1f57ec8694f3abddce522899895cf4dddVirustotal results 30.65%Heodo
2020-10-14PO_10152020EX.docdoc 9c89c629514bf2387f6c00a5c10903227b923f18741a52982877996be1ea5811Virustotal results 31.15%Heodo
2020-10-14BAL_0NA43R8NXGNGCO.docdoc 0d6731404ab523678e4e70272959a38c04c12861e5d94284b88316c3830f0b9bVirustotal results 30.65%Heodo
2020-10-14BAL_4331486875788535280.docdoc 9c6b0725805166528d2cbc739cc8157205fb247d5775c86058f8037522e235cfVirustotal results 31.15%Heodo