URLhaus Database

You are currently viewing the URLhaus database entry for http://sub.mannheal.com/cgi-bin/rNJVhe0SR9O7AS9KwFHnFM64M/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:972787
URL: http://sub.mannheal.com/cgi-bin/rNJVhe0SR9O7AS9KwFHnFM64M/
URL Status:Offline
Host: sub.mannheal.com
Date added:2021-01-20 23:52:06 UTC
Last online:2021-01-21 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-20 23:54:15 UTC to abuse{at}publicdomainregistry[dot]com)
Takedown time:9 hours, 41 minutes Good (down since 2021-01-21 09:35:31 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-21CFCWIDLKTMS0X.docdoc 3a0235b5137c1d8dffa67e97c6dbe13cfc7117e3c62dfee05d8897acdea83b5cVirustotal results 40.32%Heodo
2021-01-215J1MHPIK6XCIMH.docdoc 54385e84d22e522ecf660abd63e8cdc132b0ad766af8d7c589b13f7be5371c2dVirustotal results 39.34%Heodo
2021-01-21AYVZOWNI9NZM.docdoc 920fac5b7032800366dc97b32e8ecde37c1432a99f3e2eac1d3d36ff62ad85f1Virustotal results 38.71%Heodo
2021-01-21B7AYF3GOV.docdoc fe4636a4066b3525d7bc3a58f2a3ac8c430e3bb88f0e975869c95e7cdc91aa5cn/aHeodo
2021-01-21RVTU6QT.docdoc 7b84f2501e9b8aaa56422e3bbd5742f0e1ef38d318c28d689ed5662e85a65cfdn/aHeodo
2021-01-210WGGN3N.docdoc 734760f1587fe2caa03e721fc7f70c74e90517fae7f02f75ca4cf60cfa2c947cVirustotal results 41.94%Heodo
2021-01-21JFC6A8SX2ZPI.docdoc 64a17440d41fd8eae4685249c345b5022f4e690183200645ff1e6f7f804159ben/aHeodo
2021-01-21VSIQJTY.docdoc 4142cfc2bb8a067a21c0439bef1d08e1742025b00b3cb1c9619ff7bf0a2b42d6n/aHeodo
2021-01-21YULKVW.docdoc 5194a406cd4f741d308341f531f690bf966b451f01de1fbfbb604dbefee7c8efVirustotal results 35.00%Heodo
2021-01-213IIF37R.docdoc 1fa18e851ad74226caf71eaca19ccba3ba2b1457521c4a4fbe6ba07fb3008333Virustotal results 37.93%Heodo
2021-01-21ANZHQOXDE593.docdoc 17420055c7c1b85137e8f5e78a7eab811ae1b4f00b33ce05590e19399286fe2fVirustotal results 37.70%Heodo
2021-01-21N8CM37LTXRG0P.docdoc fef516c40db60794e220e323bd96e2a26f5808d97ac911e2bd4afc4b0cd756bcVirustotal results 37.70%Heodo
2021-01-21MTO0M6D3JT.docdoc efefc84243ccc08a0c004247847a2e7c55dc7559eaf302919c40085ff83f5c4cVirustotal results 37.10%Heodo
2021-01-21DP3SIZNI1QP7.docdoc 8d7efeeb6526c1ce01dd7d5a75a5f9c22d9ef5dec9e19d6504cc1d073cf8c864n/aHeodo
2021-01-21UHCCD4KQTG2.docdoc f1b16a95d60e942f2ca4724096a5a078f74d16d045da8ebf4cbd11d1fcb25322Virustotal results 36.07%Heodo
2021-01-21SXJ3DU5.docdoc 34f009842068cfd83b7b0048deb0698f8647a41889d562c9314a7b4665c073beVirustotal results 35.48%Heodo
2021-01-21FQAAYJILU0FBBFM2.docdoc 1ade51b62019cdf1df087f2ebf35d2d5fe4aa1bc5a03d76324ff346bfe5d7953Virustotal results 35.48%Heodo
2021-01-21LJUW83OW8.docdoc 50b410f2af280b1a288a0f94bae66b4db4278e307b1461a93a231a2ca715cb53Virustotal results 36.07%Heodo
2021-01-215HU4035HKH9.docdoc 2d75bc655ee87200243a8c0f383323e49eb31a7b0cc6f86e4376c41f83e0f542Virustotal results 36.07%Heodo
2021-01-21H800CL0PY4B.docdoc a1adbad4bcb1cff2e45b7b7e7be4838dbf2133df86b768c9a1d9fa056b5b5d39Virustotal results 34.43%Heodo
2021-01-219VY0LED8.docdoc 2a4e442727def25a8ce8ddc73ffa52be640dd1f1016dbc26e3157f361936aa88Virustotal results 34.43%Heodo
2021-01-21DIYETRK66MUPZ.docdoc 2f36085ea2e5a9e6a5d22b533c206be9bb1d3c71ee4c910ae165e54b053c0ec3Virustotal results 35.48%Heodo
2021-01-218HI1XKK98BEDDJ.docdoc 0852348c68997bc5f4ee1ad2fce794f15198b36f41818a23b69e787f4cece095Virustotal results 35.48%Heodo
2021-01-21RMFUTEU.docdoc 32167ecf841806dea1958fe7d8c1fb145323fd98c3412b55fce4e0680f3f8ae8Virustotal results 35.48%Heodo
2021-01-21IDS32IMJZRVHVIH.docdoc 46512d0921fb5626d9080c7f3930e3b4ffb9cd15bf20c8554f150e7ff47b951en/aHeodo
2021-01-21ZFEU3H2LQQWJBLM.docdoc 2b74e583a0148f1e5f2c91424947740e520cd67c66c78bc6a20c22fbc34b83d6Virustotal results 35.48%Heodo
2021-01-2180JA7Y4TTE.docdoc cc9a98243c5e282cbde25cdda1b4510e22afc3a444e07d97c8c9ffef7ff45463n/aHeodo
2021-01-21M4OABMZHYV4R.docdoc ba3aa81154976cc9bdd719ecce4a925b513892f51cf40a1f511d77d1c180f1deVirustotal results 35.48%Heodo
2021-01-2194W043Z6XJME.docdoc 1849ce13b6b8587273a6ba9558bd63b59ccef9a7c8b25c01c14253a34da481c6n/aHeodo
2021-01-21U90N5FIAI.docdoc 75d4b326ca471055fba9d3e4dfbb994e191135130d15f7f1e75fa6a8346bf89dVirustotal results 36.21%Heodo
2021-01-21UBNTR3B.docdoc 1b2b0f6f229f819f49cefa1af565aa4e83bf8b1f9df047bebfa9143dbebbb349Virustotal results 37.10%Heodo
2021-01-21HFNBXYZ731L15M8R.docdoc 9675b2f426b45cf771be7405a1b50bb1f2625f5be481848e4df2fa7419fc36acVirustotal results 37.10%Heodo
2021-01-21Q0DH906F680MT6US.docdoc 1df953e34823f8351e1702bcda5b4b75887620f2ce403968f4cb0524e89bfa65Virustotal results 29.03%Heodo
2021-01-20A23AOA1CJ.docdoc 019f04b6b435d65725a7fea600c318e96d64c945fbf8ad3ee2f67d05900a27cbVirustotal results 29.51%Heodo