URLhaus Database

You are currently viewing the URLhaus database entry for http://adventuretext.com/Rechnungs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:20630
URL: http://adventuretext.com/Rechnungs/
URL Status:Offline
Host: adventuretext.com
Date added:2018-06-18 22:36:03 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-06-18 22:42:35 UTC to abuse{at}networkredux[dot]com)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-19rechnung-CSA-042/3415.docdoc 7b06cc13ebfe530d8bbefe76b4bc8fa512f7f52dc63f114463f09cfba494ac6fVirustotal results 38.33% Heodo
2018-06-19Rech-DKA-074110-75.docdoc a5e5e88268b6edb1fa13cee068f6ecf8b5fb31ada12e9afebb5c2549812c1ef7Virustotal results 37.29% Heodo
2018-06-19rechnung-CQU-05299/63.docdoc 831cddd0a5afab7339d9000049c991d57768959d65a893e344d2c3180f15d7adn/a Heodo
2018-06-19rech-WMU-09113701/4.docdoc 154a8f02df08f96cd8e57cc8d8e89656f9494b6ab8176ef3635bc99bc96f7d3dVirustotal results 35.59% Heodo
2018-06-18rech-DES-054103-6.docdoc 422e2c3cef849047e02f54c63fa5c70322503ae1a2830816af91e943ed20c014Virustotal results 26.67% Heodo