URLhaus Database

You are currently viewing the URLhaus database entry for http://s-b-b.de/buehnenscout/invoice/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453426
URL: http://s-b-b.de/buehnenscout/invoice/
URL Status:Offline
Host: s-b-b.de
Date added:2020-09-04 17:04:35 UTC
Last online:2020-09-04 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 17:06:02 UTC to abuse{at}strato[dot]de)
Takedown time:4 hours, 25 minutes Good (down since 2020-09-04 21:31:48 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04REP_DW8756117279PV.docdoc a7680798d59287fd95857a80ad4476ee4e1a98ed04c97a6afcfa5f523ab1ecccVirustotal results 36.67%Heodo
2020-09-04R_UHK_090120_YLT_090520.docdoc 5ca09a4a4928ed469d1e0eb9dacd92fe2003d0551aeb380a0c662ced78d6fa25Virustotal results 36.67%Heodo
2020-09-04DOC_56573529.docdoc d63243bbf6aaf08d0f887d546e29bac2af6459e3439674829c8e7afc06c08741Virustotal results 36.07%Heodo
2020-09-04BAL_KQLERU32VR5TFDKO.docdoc 0ccc2086f49d393bf08092469d40a557d9b68c3653500e5826e7479b69b84c6an/aHeodo
2020-09-04HSL_090120_DRX_090420.docdoc f8a398d3de41f9168cb0da770bf87c578c800d80be14d824aa4ec8eb682cdd56Virustotal results 36.07%Heodo
2020-09-04REP_I6TF7M7LQ01YF.docdoc 07389e60fd9ae8ed3322e4d0d71325e58d8beabc1b3a0e18bbcfc7984505e598Virustotal results 36.67%Heodo
2020-09-04BAL_7ULW4GGVV49XJWC0.docdoc d6a1d2e702932301249df94cd301c2dac672fb7ccdf1185b69666fc7e19f1839n/aHeodo
2020-09-04REP_UI5PY8X3T.docdoc f620c586dfdb89cf767ff4c3141fba1c805a020c930f90abdc2858d99e71ee3fn/aHeodo
2020-09-04INV_09922360.docdoc 0a5690b216f895e3721c8a4309a53c779fa420b6f40d510309d69d27ffaa84a7Virustotal results 34.48%Heodo
2020-09-0459105095751579.docdoc b704f4df9369996d3f77982e46cd1d4b080de1817ffbd8d68f5f4a82e16b1993Virustotal results 33.33%Heodo
2020-09-04BAL_IU8102522712XY.docdoc 3c7a208b5ecb94b5f4898a79d64d135bfda7146519b6a41921f5e1261ffe35fdn/aHeodo
2020-09-04INV_50853972.docdoc 5b90408d4dc272f4943f37e60d8892e8663d56e2b299acec7cc5d8ad5be7a40cn/aHeodo
2020-09-04REP_ANU_090120_CSJ_090420.docdoc a2fdc9abbb2377b367097472c437e5a8ffedbf8e9b27eaa1e230d8cde71f89f7Virustotal results 33.33%Heodo
2020-09-04E_CH3254755524XC.docdoc cfe4b358946c9eef325f5aa66f80f7db38ac84fbd985117f1bbf039bba8a3d9fn/aHeodo
2020-09-04REP_PO_09042020EX.docdoc f265c11e67bd9353ca8c6d02ba6c752387a993a73e75006a6b28857634c8b7cbn/aHeodo
2020-09-04BAL_VHL48GB32.docdoc e518aef76084cd1d89c2f34eb4960ee623c0f2f87dd31121f0f4f70c376753f3n/aHeodo
2020-09-04N_PO_09042020EX.docdoc e627d5445b586181f22e9b1c5890b35c8ec027b86c72566fb2b9a685c10727ebn/aHeodo
2020-09-04INV_AUO_090120_KVJ_090420.docdoc a9ddc5074e8a38aa9ec39846f6c072de90ed94426903fa6d6aefe3d2c9365d69Virustotal results 33.90%Heodo
2020-09-04Y_DN6462858184XE.docdoc a227569c5807e9c5cd458bd007b476f167c46ff6544302690f81d5f50bd39566Virustotal results 33.33%Heodo