URLhaus Database

You are currently viewing the URLhaus database entry for https://recrugenie.cm/cgi-bin/Zz21uNtPOe96wvZwutG6nmzRc2h3brWX/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:753677
URL: https://recrugenie.cm/cgi-bin/Zz21uNtPOe96wvZwutG6nmzRc2h3brWX/
URL Status:Offline
Host: recrugenie.cm
Date added:2020-10-26 22:57:04 UTC
Last online:2020-10-28 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 22:58:03 UTC to abusencc{at}interserver[dot]net)
Takedown time:1 day, 15 hours, 50 minutes Poor (down since 2020-10-28 14:48:31 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28file_ON1146974902RC.docdoc f976e3edc1892c2009a8000edb80c5329f8ca920af116372b2a274488ddba5e8Virustotal results 17.74%Heodo
2020-10-28file_PO_10282020EX.docdoc c7a9fcbd5e7cf2f7c00c2ce737e5f37d79fca2af4840700fbec2812fe888df80Virustotal results 16.39%Heodo
2020-10-28inf_YN5408991854ZO.docdoc 3a80f65b200ea7247726fab9a6a422ee11db27f16b629823f536e69e6b534f76Virustotal results 17.46%Heodo
2020-10-28doc_PO_10282020EX.docdoc a35f0fa4b2082b66755f87c30fdb12e922d177ae2a22ea0289e2e292042817edVirustotal results 17.74%Heodo
2020-10-28LIST_52210759.docdoc 778c2b97449426c3f3827a8041a05fcbb0e648267612cde21370c9f152bcf255Virustotal results 16.39%Heodo
2020-10-28Attachments_83326527.docdoc 4c8c238793080292318a1698f8e3bb506d63d0e1335171fb6ba9ce1369c5daeeVirustotal results 17.46%Heodo
2020-10-2856502956.docdoc 320e1d251976122a8a99eb8cea6215aff119aaa931d99ff58c30e220a062044fn/aHeodo
2020-10-28Inf_PO_10282020EX.docdoc ca886c353a653f94a89591b19f4830ea563abdb93c949b8bd4872dbbb65bc02aVirustotal results 19.67%Heodo
2020-10-28ARC_PO_10282020EX.docdoc b2a8f6bc160f4536d6be6a9e5ef41244a96a2bf0de49f9d088c5d68853f2d69dVirustotal results 20.75%Heodo
2020-10-28Mes_08416234.docdoc 2871ff5b986f5c582a3468cf2a6210dad8216a164b0affd7c6b11e8ef69761ecVirustotal results 32.26%Heodo
2020-10-28MES_PO_10282020EX.docdoc c88a8bfd26b88fe11810b85a6ced566f6ecd9c06b535f98d8c7451c66c1716d2Virustotal results 28.57%Heodo
2020-10-28B_PO_10282020EX.docdoc 33c735ac2d43594d1fb25ef35adae90aef216e70c30065596ad24ffb5299de94Virustotal results 28.57%Heodo
2020-10-28List_JPT_100120_WLD_102820.docdoc 3b2703a8136146bb26f76cf8aeb05e347c77170c548c652fdc716a1df532a920n/aHeodo
2020-10-28FILE_JAR_100120_RZT_102820.docdoc 5acee595ee1bc75adea710f92e969aa5c62d0a2693b6dc8c678b2bff8a4a7e51Virustotal results 30.16%Heodo
2020-10-28REP_YI2D898K9ZIYK.docdoc 16b04fec1fdcdf3e7cd7b256ab6d5eb83277fc58d66fbea24c54202ce5fcd96dVirustotal results 28.57%Heodo
2020-10-28REP_WQVRJLOT3JISYGOJ.docdoc 783e3178de387969ad58cadd83de2b88c6cffa406063d2f66e5ee8b67db11b4aVirustotal results 28.57%Heodo
2020-10-28PO_10282020EX.docdoc 520ca27ad3a13618d306b397f83a91daf238997358520459895991c6285328e5n/aHeodo
2020-10-28INF_673720062929012468.docdoc b5967d8f6f4eff72fd314911e828c2376081aa4d190afacbbbfa0fb390f13e4aVirustotal results 31.48%Heodo
2020-10-28LJW_066775306570293105090.docdoc ed9cfc1c33944c034d599ffe6b86bbb5629c22af3213560f5782e96dbc3d5fd5Virustotal results 28.57%Heodo
2020-10-28Rep_032605655908704.docdoc e2f58ed91009de4f156ecdfb6fb04401ce82b2281242941e3a80fa9fe451cfcdn/aHeodo
2020-10-28MES_9265981779.docdoc baa9e0e0224c23762409491f8a638b5ea9d725bf6f13ff26904c1328476402edVirustotal results 32.08%Heodo
2020-10-28REP_EF9531873802ZE.docdoc 923249c0d4dcc2113d70d2a97c0f28d9667690185c9e5a0d9161408d5277acf5Virustotal results 38.46%Heodo
2020-10-28DAT_PO_10282020EX.docdoc f605f4309f21e3797ba0f7b9440dbd45fb913a363be8a0e774040e92e05418fdVirustotal results 35.48%Heodo
2020-10-28Rep_PO_10282020EX.docdoc 9c509bf6c3b7824436cb299b2efffd013f3b0b156e9398a6975b71b50152cac3n/aHeodo
2020-10-28file_71753011.docdoc 0250f0fd12c78f615ebd384a8bda63e6ff45039b0005ab5211ae72a4ab4b97d1Virustotal results 34.92%Heodo
2020-10-28MES_CJ0798197559AV.docdoc 553f438bc1486ee99b764c15bf3caa7e8fc1b49c48ace061dbd07220a7e56eb7Virustotal results 27.87%Heodo
2020-10-2880170396124871468.docdoc 2a87dc4a8eb48efe3380d6d3fa99507c81bb9356c90ea39b1156d82f32396c18Virustotal results 30.65%Heodo
2020-10-28Doc_FI9269184322AT.docdoc f43cc95ed3a2f8900938c6a240d69a2de909494821ee8308e740e2cda2fd31d7n/aHeodo
2020-10-28Rep_57849895535.docdoc 1371c2d34a1e3ad727d60804b08ef021e7568a841acc95ce5cf1773149657ea7n/aHeodo
2020-10-28GKQ_100120_BCB_102820.docdoc 7f286766434b67cb7ea25119d469c086c70807bf665e8e373acb472ec284a72en/aHeodo
2020-10-28703998818969480613998.docdoc f3caca68ae462481d5bac777996fa838a0dce95c7eb782713404fa5e3712a2abn/aHeodo
2020-10-28DAT_XX239YDWD.docdoc c3e8b7bf6e9c96cf2335ab8c491d537cf81a2c322e9b305fd0545d051c613a83Virustotal results 28.85%Heodo
2020-10-28list_32001260.docdoc 25578de149cb4dddcde0db6ab49f1ef760faf659fee06a0b86d0fe095cc438e6Virustotal results 27.78%Heodo
2020-10-28dat_V7061LIWOM5.docdoc 384f0ac6af41ed895424d29854b510286d7b1c075150dbd313f8682f26eb4249n/aHeodo
2020-10-28rep_PO_10282020EX.docdoc aeb7e85b2cafde9f05807a7b77f48f79c431e3c6cdaaaea539d2fb42a7ed47c4Virustotal results 26.42%Heodo
2020-10-28Mes_RF8021951541OO.docdoc bc8c74e5b69ba384b49d43f30b6707c6982c97d843cbc3771fe0027cc844869fn/aHeodo
2020-10-28ARC_PO_10282020EX.docdoc 42437dded751c17d78164701713e5a181726b5fa47472556a1eaede5aac86c17n/aHeodo
2020-10-28FILE_47345900.docdoc b1667802a4201e50d756b921bd73789dabdc6e0ead93ccde248f9634cef63d6an/aHeodo
2020-10-28FILE_9EATAP3ZFIO.docdoc a30d2b343e3646a2a05e98c5b7f976a1f67e12574ecb880a2a460bec35735f6fVirustotal results 27.78%Heodo
2020-10-28List_HEE_100120_EEU_102820.docdoc 555c444da12ef92c155597ec6fb707163898e7bc70247e493e627c319f122a36Virustotal results 23.33%Heodo
2020-10-28Doc_PO_10282020EX.docdoc 6310463115ebc704a66281738da24d3ddc5e2b7142db330ffc61d25899c74869n/aHeodo
2020-10-28inf_PO_10282020EX.docdoc e6e605ad811f416df52bdd27b76218c84b0f27c3ce272e28b373c86440fb089dVirustotal results 22.95%Heodo
2020-10-27Dat_20473375948618188278.docdoc 90f1f20d90c0a5c6c32d6eca01833ff1db7b1325a5db427d7c5871fe3d5096f3n/aHeodo
2020-10-27Mes_30362534.docdoc 51dc9e5a948487f714ef9600e3188b99aaebca09db45c0cd628d561945767476n/aHeodo
2020-10-27TF_TQ7895410758HH.docdoc 6d8117453777b13dbab5c583bdcb52b56cfc5dcdba308238eda98a5bbfd95495n/aHeodo
2020-10-27Mes_932778861196186811948.docdoc 4791b5ee50085457d0dce59a52da9717357b5112a9138b69ff60bc3003f32e25Virustotal results 22.22%Heodo
2020-10-27ARC_PO_10282020EX.docdoc 03fa3f0006277ab4660e041c87d11e9ff66fd8e504b0b94aae7f579ac9d6a998n/aHeodo
2020-10-27DAT_98720170.docdoc 1db431c17705bc1c2fee12058ed445716e38f8e65de2b269114a9c9fd9be40bdVirustotal results 20.75%Heodo
2020-10-27Untitled_MPKJX8KK8GNYSF.docdoc b01b01566c73b1c2ecfd4f04bda6c7cc3c1c12646562ae1f615733fb1cc89b37n/aHeodo
2020-10-27inf_HCX_100120_YTI_102820.docdoc a972fb1281a3d74bbf2194996a6b7af6b95eb98b1111573562958b4235e71d93n/aHeodo
2020-10-27arc_UI0FS9WSQWE.docdoc ef29a8422b09e506af3affcef90be9236f769d51ce6a686df8fb8dfc6fcd1284n/aHeodo
2020-10-27NMW_53007127.docdoc eff4ff103b1930c43c7f0ae267a43b853c4cc734db4c80473d028efff6e8f7f2n/aHeodo
2020-10-27DAT_7779235065556559998667.docdoc c648fbdb326aab7ad03eb32dbe84421e283c66f1f7d21f8cf8a392332669b8faVirustotal results 50.00%Heodo
2020-10-27116080348610.docdoc 31b23d9a8a18a659b89c36b6b116aa8f28579df18ff6d5f81e557ed41c1cc271Virustotal results 47.46% Heodo
2020-10-27DAT_PO_10272020EX.docdoc ae384ef3ae1439be7fd5e225e356f5869d208e2bde0bce02a81e75d56239d985n/aHeodo
2020-10-27rep_SU1697113058CH.docdoc 1ad28606bff91478a2383c7deb56c563f2c3912df1f1ae81b0fd16892f3842d4Virustotal results 46.67%Heodo
2020-10-27Mes_51931455.docdoc 42c0ca75903e2ecf17a86645e72752d15c47d76bbb5bdb0c7fb5493f8939d952Virustotal results 50.94%Heodo
2020-10-27MES_PO_10272020EX.docdoc 53dfce57e9c5c4d1fa5dbfde99dffd5cccf677f96b297a5a517d86f93cc81bbfn/aHeodo
2020-10-27Inf_Z4KIEIA8.docdoc 8d2d00b851dd74708e5e2f6c4858dfd28cbbee583526d5cfdfef4b00f44077c4Virustotal results 50.00%Heodo
2020-10-27FILE_HKN_100120_DMB_102720.docdoc e2e08b8d13ee2f3b74b54ec4de5892a941e2a274e8c0117d86a7dda62c0dcdd8Virustotal results 45.16%Heodo
2020-10-27INF_PO_10272020EX.docdoc 8e2379ffe37bd31c9d501b4fea3ae2e28b59f933520d89a5fae9580c3bfe9368n/aHeodo
2020-10-27File_AWM_100120_XVM_102720.docdoc 962fbbf94c656f8adb7fbc7ea014c1d73a53e89da111f32496bdf5c1cd019738Virustotal results 37.04%Heodo
2020-10-27DAT_67086475.docdoc e9ed0e2383e743b2c64d4c7a9dfa27ef8352ca6b03cbc8b606f72368c42c0196n/aHeodo
2020-10-27ARC_53260182.docdoc 859b4eefcb2d29d6d47108ec6fe5463bf11a5345be824a956aaa125ac3bb6372n/a Heodo
2020-10-27FILE_PO_10272020EX.docdoc 53c15a0758065226ff440e2d77fd9566797ad3e8ab328de743a0fc0e63c54799Virustotal results 40.74%Heodo
2020-10-27ARC_JPA_100120_XSK_102720.docdoc 905ceb0eff34fd8a2396baf84fc27ea60aef1d231965ccb9dc63875a8674c070Virustotal results 36.07%Heodo
2020-10-27B_UVH_100120_DOD_102720.docdoc 1f2f51694630787d01ae02ff2756114d0d9e38a8de09470e63aae9dbfc0fcf69Virustotal results 37.10%Heodo
2020-10-27Rep_HYN_100120_KQK_102720.docdoc 822b7150456ce4824d3136d2b173e2981a20870b8533b3379c2feb83f55288ban/aHeodo
2020-10-27RG5751732826AQ.docdoc 901b7928cfb286b90c7bd949481eeb663937cedfe0dc36b49fd069dd437717c3Virustotal results 34.92%Heodo
2020-10-27File_ZF1389755838PL.docdoc 9ef432b9526e75b9aa481ba043077d6ffefb4a706388c90fd002e320dac8520dn/aHeodo
2020-10-27file_13227616.docdoc dfba0c0279ce312703161fc36a706210611ed837313ae97396607890e243f668Virustotal results 32.26%Heodo
2020-10-27MES_PO_10272020EX.docdoc 63b071aca88485607c94bfbc6f4afaf604a04cf316431cc9375016c853cb363aVirustotal results 33.33%Heodo
2020-10-27PO_10272020EX.docdoc c7a43f32ed239f55b870956822794d73441e158496f1ffc8cc99be7913381e76Virustotal results 33.33%Heodo
2020-10-27KZB_5851909832843600.docdoc 9a25919303a6d0b1210df01ae35bc7d31040fb1463dc977b75c5f7f11170a42fVirustotal results 38.46%Heodo
2020-10-27Untitled_TOA_100120_HEG_102720.docdoc d0b2630b796df661789e540ba6ca88de07b43f58bebf9f911c9985b4c4cdd0a0Virustotal results 34.43%Heodo
2020-10-27REP_758103961111441.docdoc 568a352a99c7d13f8738d6cda1e312b1d7788cf46a1b392755bf34ddcdea64dbVirustotal results 34.92%Heodo
2020-10-27doc_PO_10272020EX.docdoc db8c10dd3ab28c896b921d720da5b91739c6f990bfef2f4026dce156e231fa0dn/aHeodo
2020-10-27Rep_CHW_100120_KNW_102720.docdoc d5aaf8e25239f9afc06dd64b24324b6a12c43fd6ef863b33e602425aba4960e0Virustotal results 35.19% Heodo
2020-10-27UNTITLED_5828595931476.docdoc e76793fb9b8a242cfa95dc549c57e5d3887843aa25b6c235e4fcf59ebf1fac2cn/a Heodo
2020-10-27ARC_PO_10272020EX.docdoc 7d2f13626cd91555d5f9cbdef3a3c17f832e03fc8dc38afb61822dfa3aa37649Virustotal results 31.75%Heodo
2020-10-27FILE_JKI_100120_MQN_102720.docdoc 36178a3ed3f924fd1a1b08abb9f65e5adc5c7e46ecb8c927f993de6dbabbee47n/aHeodo
2020-10-27List_GEL_100120_GHY_102720.docdoc 4d1c9d926e790dcba4a18230f0ef11f5550dccea472300ac8d5cedb064e6e573Virustotal results 32.26%Heodo
2020-10-27VGBS_91NH38A32GXJ.docdoc 31df94b9e288094e3f9106856f7d8180e8f927b4b8fe99f0aef1bb04089c673cn/aHeodo
2020-10-27doc_UET_100120_FXW_102720.docdoc d7c6815a6c9839cb6e4c7b87dd865a478181918dea81112af9afd68e330837fan/aHeodo
2020-10-27XXVD_GD5193508330EP.docdoc 99dcbef73f8e02416896cdc9204b4ee7249131cea8de9baae8bd7f40985c7d5bVirustotal results 31.75%Heodo
2020-10-27ARC_YKO_100120_PBL_102720.docdoc 7691240314f7a2c8bb746a2d3177cd6854f21ffe7ce02228138b0c64a3346915Virustotal results 32.26%Heodo
2020-10-27LIST_PO_10272020EX.docdoc d08d1bc97690cb1259689a27c633a98ca69552fd2f3b80f940ce0c9b4a168364Virustotal results 32.79%Heodo
2020-10-27LIST_PO_10272020EX.docdoc 24766703c0713e30ba3b3667a3e220f3d909b86f5566ca06a66f97a7f181715cVirustotal results 35.19%Heodo
2020-10-27ZO3352783328SB.docdoc 9585baa7e3cea40736c5c909141cab11285345fa112ea2ca8438dda57091a96dn/aHeodo
2020-10-27INV_HUZ_100120_HMQ_102720.docdoc cd0b23d03029fe913a9d2f52d14b0703f4a6f6a4cbda6744a455fca3373d3ca2n/aHeodo
2020-10-27REP_S3FQAWZE.docdoc a9670ebc9a9410fd8afc7de53381f501601ca3566f19e9177a79ba8a1b6b93e6Virustotal results 42.31%Heodo
2020-10-27BAL_JV2803569558QD.docdoc 86b0701737b73d1713cc04f83dd9e1d5d8dcee914c007cca4d5a6a1870f7b067Virustotal results 41.67%Heodo
2020-10-27DOC_98827303.docdoc 3fdc33083e4013b835f32c8870989125fe433607c29000ea8c994f0105ac07f0Virustotal results 43.55%Heodo
2020-10-27BAL_DIF_100120_HGT_102720.docdoc dcac3f433bca625d1c831d29f00d254dcc6740ca1779ebf9f6483ab6fe431c21Virustotal results 40.98%Heodo
2020-10-2709537684738559.docdoc 6f039a653dd4edef8c16347acc26f36a9b283bdeb9c8fb6ce48faabd9f67f5e2Virustotal results 43.14%Heodo
2020-10-27DOC_3608321762.docdoc 59b0501c2684432b625387c70e6ba5db3ebd84b77d24b11c744db3b3c48d3561Virustotal results 38.89%Heodo
2020-10-27A_YZT_100120_FIE_102720.docdoc 4fb9d273bb087c7c0ff482f77af8b41047e57e10e452d9d4b873e89afcfb9624Virustotal results 38.89%Heodo
2020-10-27JUW9MH00L4AW29.docdoc 56672b95281d04830b996e84df9edadf1be30650c9e410f25dd4596927d71d7bVirustotal results 39.62%Heodo
2020-10-27REP_FME_100120_IPU_102720.docdoc 44193d99f4f6240603cde0c68693a415a4ada0d769001572a4b84f503df3569eVirustotal results 42.59%Heodo
2020-10-27INV_1A3KEXS4A8HMH.docdoc fef9e77f6d9e84345a020f567b892fb4718af268465b5a6d505a6f2bbfa19e92Virustotal results 39.34%Heodo
2020-10-27INV_IKD_100120_BSX_102720.docdoc 26086ff8825a2c550cc802f2574dd9a8730c972ed3d1c704d863fc74e8dc082cVirustotal results 38.89%Heodo
2020-10-275WQWUOXSUTY.docdoc b9efcf9bbdfee20efe56047ca5810ea88974d9e7b9ec968a57f814842c7946ecVirustotal results 39.62%Heodo
2020-10-27FILE_TFR_100120_DRR_102720.docdoc f60367a56f63f15b4be7200e8bb78d410ba5408cd0615bf5fa390330b4aed1e6Virustotal results 38.10%Heodo
2020-10-27EU169HWU8MIPR62L.docdoc 946439b363272872ced4c20d04dac453397ef429b301ef0a947f9d4ca1f95d48Virustotal results 38.46%Heodo
2020-10-271L6JYFT8.docdoc c8b394c2d8b83573eba859ba30101e535e3795cc846b6f21a09c3653cae36981Virustotal results 38.89%Heodo
2020-10-27DOC_79387834.docdoc 9a5ff2d10eb6a49a82083f2f52e3daba519399794197d526ab76a68dd6849e69Virustotal results 39.62%Heodo
2020-10-27FILE_9BXSMXZ.docdoc 77308b34c7f167510dcdfc5e0de665824b0826603235b32f2c644ddf354cf6fcVirustotal results 36.36%Heodo
2020-10-26REP_32952344.docdoc 99f4e6496067c7a7b9d8cd390470315cc63c4f3adb23c3d885b886f9d86786edVirustotal results 38.10% Heodo
2020-10-26DOC_29392585066037.docdoc e00856eefd86441efa639a6675303e9ae04abe216e730a24429423b46f48426fVirustotal results 37.50% Heodo
2020-10-26LAG_100120_YJC_102720.docdoc 9ba569c1504543ac41bb2308f0ed322542bdec567e0588185603e500cd37f68bVirustotal results 38.89%Heodo
2020-10-26H3X7SD6L6ON.docdoc abfcd6342895929d5baf093e13140d0b37f8e97da0253480aa94ba5e78bcd1e1Virustotal results 37.04%Heodo