URLhaus Database

You are currently viewing the URLhaus database entry for http://www.plasdo.com/Jul2018/Rechnung/Rechnungszahlung/Rechnungszahlung-BOK-50-93017/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:31468
URL: http://www.plasdo.com/Jul2018/Rechnung/Rechnungszahlung/Rechnungszahlung-BOK-50-93017/
URL Status:Offline
Host: www.plasdo.com
Date added:2018-07-12 09:09:40 UTC
Last online:2018-09-08 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-07-12 09:17:56 UTC to hm-changed{at}vnnic[dot]vn)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-13Zahlungsschreiben-JJE594098440.docdoc bf82411af4ed52c270050930c3bee33a983a87e0dba7ce9f3f98442f78254de9Virustotal results 40.68% Heodo
2018-07-13RechnungsDetails-FFM57935515.docdoc 523316f8a759917e64d5de3c5ca63e705d4e22f265d742695611e4388e1d1901n/a Heodo
2018-07-13Rechnungskorrektur-VLY44489260027.docdoc c1884e747e2258db9f159fd1e449603a9ba002ac32d4a3d53f4dd268136fe4e1Virustotal results 30.00% Heodo
2018-07-13RechnungsDetails-BIT4453501544.docdoc 5af29e3885a053a8b36146053b433d92c180033af6fcaaca0d3138adbfb11282Virustotal results 30.51% Heodo
2018-07-12Rech-ZIM89223935.docdoc 060e5717b536fadd73923183b824dbdcd5a3a134cf412502598a77f74789c254n/a Heodo
2018-07-12RechnungsDetails-VEB34825032953.docdoc 748d9be81e5fd689ad13e5689eff60bef52a416494a2046039f2ca437353d39cn/a Heodo
2018-07-12Dokumente-VYA11506896.docdoc 87104ad5763706b17d76c89edb02bcf24f26855b70d81672ae13770d55fd11efn/a Heodo
2018-07-12Rechnungszahlung-OHN275012953637455.docdoc 9bbc1c482d5f8ce77bd2d80dc4ed94c824f5db288bbfc926b83478ef32109d59Virustotal results 22.03% Heodo
2018-07-12RechnungScan-NFH2686867.docdoc b1b0eaac5ad3bfd1c233db2fd7cdc43eb09ccd7d8d41519a79e84c66ddc4aceaVirustotal results 21.67% Heodo
2018-07-12Rechnungskorrektur-ZMO928961365798.docdoc 6d46058f394f1b31f89b3eb9ee5bdf48c69614fe8dc3c6f54092af7dc2c7164dVirustotal results 20.00% Heodo
2018-07-12Fakturierung-LUV5470386340001.docdoc 668bbeef3c73c075b28f0c8441dd083fe979966afa72b89f62de5140820ca68eVirustotal results 21.67% Heodo
2018-07-12Rech-SPF255229579878870.docdoc a15f66b222d6bbbead16f3c7725792a41c7c4a32fbde94443b0e225009b2101fVirustotal results 22.41% Heodo
2018-07-12Rechnung-AIX2074854169.docdoc c3edc524c521abfbc6b205dfade64b4d24a5307f8abaea357c2964b6b44796a7Virustotal results 24.14% Heodo
2018-07-12Details-DLD94635736558.docdoc efdf0763fbc5d2395d4a5eefebd2e2eda4974fcf4346cbd8e5bfbac0fca41137Virustotal results 25.00% Heodo
2018-07-12Rechnungs-Details-XEV1680575859506.docdoc 80272a7b41031178b76fdde2b49ee1a3b1aa6553b259f2f752b94c44b692d484Virustotal results 25.42% Heodo
2018-07-12RechnungsDetails-SEX34725714066010.docdoc 24fb6eece60e8771362ef0cd74ccb2824109124f9d771813b9094936dd8ed311Virustotal results 25.00% Heodo