URLhaus Database

You are currently viewing the URLhaus database entry for http://keelsoft.com/De_de/ICFWUMMN2168085/Rechnungs-Details/RECHNUNG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:121387
URL:http://keelsoft.com/De_de/ICFWUMMN2168085/Rechnungs-Details/RECHNUNG/
URL Status:Offline
Host:keelsoft.com
Date added:2019-02-11 09:42:04 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@spamhaus
Abuse complaint sent (?): Yes (2019-02-11 09:44:02 UTC to abuse{at}unifiedlayer[dot]com)
Takedown time:2 hours, 58 minutes Good
Tags:emotet heodo

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-02-11736846173154958.docdocd6a3b6a5d6b6ebf87ce75d0851355a31351df20df1268ae35283a43b39eacdadVirustotal results 18 / 56 (32.14)Heodo
2019-02-11X474620250897832_2019.docdoc06c42235a3ff621a78a0825032ef9df39f25a6a1608a32881a151519f97556e8Virustotal results 15 / 56 (26.79)Heodo
2019-02-1159806305682.docdoc2b7ae3407d29c271431a2c36b97e4ff532b683308a41cae4c6a8d16de83da8b7Virustotal results 15 / 57 (26.32)Heodo
2019-02-11254521964565.docdoc1c8a9bb7728ee219c41e8cc6dc3649c919499788e538252d3e317c882f3eab2eVirustotal results 16 / 56 (28.57)Heodo
2019-02-113906638438969598.docdoc024733144341126a04610c276ab04356cfa2cc7eb50401b6818ada0b6b09f0a6Virustotal results 16 / 57 (28.07)Heodo
2019-02-11788505834966527538.docdocf234b55d79b64b287c3f67148225629dff8f86c3b71de21e3b6bfd4ffffaaab0Virustotal results 16 / 57 (28.07)