URLhaus Database

You are currently viewing the URLhaus database entry for http://gonorthhalifax.com/ffmoJjv8/de_DE/IhreSparkasse which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:86338
URL: http://gonorthhalifax.com/ffmoJjv8/de_DE/IhreSparkasse
URL Status:Offline
Host: gonorthhalifax.com
Date added:2018-11-28 14:38:12 UTC
Last online:2018-12-07 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-11-28 14:40:01 UTC to abuse{at}athenixinc[dot]com,slindsey75_athenix{at}endurance[dot]com)
Takedown time:8 days, 16 hours, 4 minutes Bad (down since 2018-12-07 06:44:14 UTC)
Tags:emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-302018_11Informationen_betreffend_Transaktion.docdoc df62074f9201f6fe22b46fd438e1d1c278abfa734c0ff1ee924ace6d8855f5a4Virustotal results 16.95% Heodo
2018-11-302018_11Details_betreffend_Transaktion.docdoc 6bb7bf4d9bf2b0efd07cc078147f5e3f1e7e6d5c8d1b697256606f8c9ccdc92dVirustotal results 18.97% Heodo
2018-11-302018_11Details_betreffend_Transaktion.docdoc b6d3058e363b65703e89c1aeb02325f4a97b80b3644e2a6e134870adba3e86caVirustotal results 18.33% Heodo
2018-11-302018_11Details_bzgl_Transaktion.docdoc 757d3ea2fb4738eecb9e1d5aef27caff8d8597827bc02432b9682d9417fbfa15Virustotal results 18.33% Heodo
2018-11-302018_11Details_zur_Transaktion.docdoc d4b4601cfc978c22e9dcfecce1c3cadd6a35635186db765bc6290489598a4171Virustotal results 18.64% Heodo
2018-11-302018_11Informationen_betreffend_Transaktion.docdoc 45fe9365c786331ea52949bae26fd31cd74f6f1db3f0067377d22a05780f26acVirustotal results 16.95% Heodo
2018-11-302018_11Details_zur_Transaktion.docdoc bebff34c7cbb71086bcb0cdf8dfe4809c41c1a1d74f680af20832576bf4c4ca2Virustotal results 45.00% 
2018-11-302018_11Details_betreffend_Transaktion.docdoc 5fd05e7184dd9f5f57f55045f913857c8ba685e6f7437eb4f686b698260e4563Virustotal results 45.76% 
2018-11-302018_11Informationen_betreffend_Transaktion.docdoc 11bdab3a7f77838f1cee08ad8086db5a25e595105a7260985cf63d03bb3dfdc9Virustotal results 38.98% 
2018-11-302018_11Details_zur_Transaktion.docdoc e447bcaa90e4f3db4965ed59e55af92bf6f3c04c085dd0984192fdb5ac6450d5n/a 
2018-11-302018_11Informationen_bzgl_Transaktion.docdoc 70e52537a63e738b195e15cd5159fc7b41f5e9f2fad02743ef5e7431e12fcb90n/a 
2018-11-292018_11Details_zur_Transaktion.docdoc 36898538bf6a588d12f24df31313711fb26ce9da29facd3115f3b1b76a53e1deVirustotal results 26.67% Heodo
2018-11-292018_11Details_zur_Transaktion.docdoc 2b1c0c05d34f81c4c0ad1413a002cdd3f1d8d772f6fb32e736a7843507b477c3Virustotal results 23.33% 
2018-11-292018_11Informationen_betreffend_Transaktion.docdoc 3719f74e13249e6c3e366f97812c5fb5d1c3198bda1aa703fe41c1005cb6b870Virustotal results 20.34% Heodo
2018-11-292018_11Informationen_zur_Transaktion.docdoc 316f4a0b942371c65df0a9921f49b3bb39c7bc04581d3db46511c230e19907f5Virustotal results 21.67% Heodo
2018-11-292018_11Informationen_betreffend_Transaktion.docdoc b08b72d570139625787523f88badee9b0c09d2a539c738287ab8222841c24c56Virustotal results 22.03% Heodo
2018-11-292018_11Details_zur_Transaktion.docdoc 68f11b75182d6e23bd24a23904a7a67d7f0160a61a1c43aacf5f0cd95c0bba87n/a Heodo
2018-11-292018_11Informationen_bzgl_Transaktion.docdoc 6e4426d0b509170954d62979cc981ae4a1bce0fb5011ff60ce2e7d8b1068f0c6Virustotal results 45.76% Heodo
2018-11-292018_11Informationen_bzgl_Transaktion.docdoc 9b64eb80e2ac4c1b6a75894dc46023480ee9e469e0a4020bdd5136fd9464f6aaVirustotal results 23.33% Heodo
2018-11-292018_11Details_bzgl_Transaktion.docdoc 787f15153a853931e8adf9cbc828896f6cd56add50dd1c1c9914159f0ae20244Virustotal results 25.42% Heodo
2018-11-282018_11Informationen_bzgl_Transaktion.docdoc e1f4790668195b3a49c022614f3a1c8fe95dac4b75e9039f7ec3c982223384c4Virustotal results 23.33% Heodo
2018-11-282018_11Details_betreffend_Transaktion.docdoc d39aab4321080093f8fcee9d4418d9618c97506549cea5f69016ab305add3cbbVirustotal results 20.00% Heodo
2018-11-282018_11Details_betreffend_Transaktion.docdoc d40edfaead94f7a35f4b442cf66e31f5501c8e93aa2aedabe3d7d2156af7f8ceVirustotal results 22.41% Heodo
2018-11-282018_11Details_betreffend_Transaktion.docdoc 2397ebffa634bb7e9eedc0ecb267f8bb717a18ce2ec59c7ad72c05adfe9dd9c3n/a Heodo
2018-11-282018_11Informationen_bzgl_Transaktion.docdoc 246e1d21b2ecadf897a9bfc3e94a0f60f225858db4f293bc9d3153a6dc175848Virustotal results 22.03% Heodo