URLhaus Database

You are currently viewing the URLhaus database entry for http://rh-gmbh.de/bin/doc/En/INVOICES/ACCOUNT429137/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:42557
URL: http://rh-gmbh.de/bin/doc/En/INVOICES/ACCOUNT429137/
URL Status:Offline
Host: rh-gmbh.de
Date added:2018-08-14 04:48:03 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2018-08-14 04:50:33 UTC to abuse{at}oneandone[dot]net)
Tags:doc heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-15Inv. no. 49W01475656.docdoc 8c4ce35dda3d110f5e6e6bac50cfbb34751f5db03188170d1680144fcca1267cVirustotal results 31.67% Heodo
2018-08-15Review invoice required.docdoc 74198a4c0c4fbdc5bbac55bd0ce5b08a71c2c3188d1825cfbd08e67cb292cb05Virustotal results 31.03% Heodo
2018-08-15Invoice Query.docdoc bd834ab3ee3ba7fb045ed4aa55a9eac5c9d880f9c269302fad51b47dda6034b0n/a Heodo
2018-08-15New invoice 673ZJ58053.docdoc b3780348a997bf9644df511fc09819640396ae7b5934775a7dae92d1453b9f74Virustotal results 36.67% Heodo
2018-08-15Latest invoice - 911246.docdoc db0486e7fe13763954972e8b29e104d2b9b6f7070f4638d828b707a63c1ecf2bVirustotal results 35.00% Heodo
2018-08-15Customer No 993488.docdoc 1a4ca08fb00aedb3b45ec4418539472eea22761aabe719e0e8021947305c4e6eVirustotal results 33.33% Heodo
2018-08-14Invoice as at 15/08/2018.docdoc 429012f0faade3186f4d5ef455c114ea0cd27973f1a785b4a8f12326f028aa32Virustotal results 31.67% Heodo
2018-08-14Invoice as at 15/08/2018.docdoc 5c6d9f00e6fcf35631b4b45573b5ef3523be605ddb1d3e34213838821686ff2dVirustotal results 26.67% Heodo
2018-08-14Invoice.docdoc 75c75abfb68fa9ad3ba70008aa74974e0125be70764678d86e51f1ca37d0d918Virustotal results 28.33% Heodo
2018-08-14New invoice 665Q8508.docdoc 98d4c036aa8edc94b6e508adcbec57c4c507a5ecdf481cc30aee66f3a9057b11Virustotal results 29.31% Heodo
2018-08-14Accounts - Invoice.docdoc 200f9ce2b352f4cadc07b595bfd5687cd67a942892ea333eec4cf3fe2636874bVirustotal results 26.92% Heodo
2018-08-14Invoice Confirmation AN70421.docdoc eeff30302c60ee1360d9bc061a346778b05c42377236052cabe4855439987911n/a Heodo
2018-08-14Final notice.docdoc e1c7083d6ef5c0eb47b606ef2b331df15d3d77f879d40e4721ed1e0d071c0694Virustotal results 30.00% Heodo
2018-08-14Final notice.docdoc 4ed13b5c46a1f58dd71eadc6da39b9d89dfe3291a99b45aaee64eddb85fc4ae6Virustotal results 30.51% Heodo
2018-08-14Accounts - Invoice.docdoc d9b3efe80a0736cdb64cd29975e21a03e694820936b9798b2de4092cdff10662Virustotal results 32.20% Heodo
2018-08-14Accounts - Invoice.docdoc d9b3efe80a0736cdb64cd29975e21a03e694820936b9798b2de4092cdff10662Virustotal results 32.20% Heodo
2018-08-14Billing Invoice - Job # 503804.docdoc d7049f762912efdc64e4b3a616a9ccbfc99750ec854e8021a37dbf4449a8e7f2Virustotal results 26.67% Heodo