URLhaus Database

You are currently viewing the URLhaus database entry for http://luckfinder.co.za/de_DE/VAWWVUNE8386207/Rechnung/FORM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:122313
URL: http://luckfinder.co.za/de_DE/VAWWVUNE8386207/Rechnung/FORM/
URL Status:Offline
Host: luckfinder.co.za
Date added:2019-02-12 10:05:04 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@spamhaus
Abuse complaint sent (?): Yes (2019-02-12 10:06:02 UTC to abuse{at}hetzner[dot]co[dot]za)
Takedown time:6 hours, 4 minutes Good
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-02-1250728953941713516780.docdoc 55ebd19889089904c2494e1ec0233a09440d4b8c4943680f1b6b0ea47ffab2daVirustotal results 28.07%
2019-02-125878918565280108915_2019.docdoc 7f2d2be9e8393c8a38c1e3e948b27bb4660bba4623be31894dca25318542414en/aHeodo
2019-02-1284652916341.docdoc 93e7bab5a87110e1ec49b5e2a40b70eab6c53c4a6f42b63b77d472f52f904676Virustotal results 26.32%Heodo
2019-02-12561033731_2019.docdoc 319e696035318ad81de588cb10ae0540adb5a0c841549d3726c72715c6540026Virustotal results 28.07%
2019-02-12QQV7013634120330594085_2019.docdoc 9e500ad2ac11e0f355d7966992ecb085244e777b278f5d8d13568cc4b256e089Virustotal results 25.00%Heodo
2019-02-127320665950364.docdoc ec841b5a6810a726a78d53afac2e809bd0be8758248ec41dfc49424654f45ff7Virustotal results 27.27%Heodo
2019-02-12771638161842418_2019.docdoc 53eca122ec298ea4f73562092ce57e2c8809f9ac46ee2b331be21fab5ac39d90Virustotal results 23.64%Heodo
2019-02-12SL47161473388142831.docdoc b5a0c38797bc6759adb5a0f83f9082f753996e6afd68959d4d49e2efb0e8243bVirustotal results 24.56%Heodo
2019-02-1293941256685234933394.docdoc 2fa71247c8825a9732ab1f9cbb884b16932ac72a89c4e786809862b3caae3791n/a
2019-02-12253071596944159_2019.docdoc 660f59af3b4995bfcd65aa162e38adb7f017a89f1215a0e5e59bb415750a145bVirustotal results 26.32%Heodo
2019-02-124994969066809_2019.docdoc 233b98ead2663e8a2f9b16daeefa134cb0b4f34a83efc98203d50bee258344c4Virustotal results 29.31%Heodo
2019-02-1265046286486799173_2019.docdoc 0d20173df64fdc23a85ab3a0af60c6cecbe277e28988f8f069e22cb7b7e4a9c2Virustotal results 26.32%
2019-02-122995329762.docdoc 83244c85d4d7759b679274ea13747a43cd68716c6f5203e6912007a4b0d5eec1Virustotal results 27.59%Heodo
2019-02-127781600927192946.docdoc 8da9c3b4a4c3685015b16c16b1bafbf03d6a9d570875ab5430438bc84e561370Virustotal results 24.56%Heodo
2019-02-12XW11206281626724767_2019.docdoc a42455b01a8b32430f7a3e777848bf0b1c6e1626c859cfa2bc6486aaa8e54b2cVirustotal results 27.59%Heodo