URLhaus Database

You are currently viewing the URLhaus database entry for http://learnbuddy.com/Telekom/Rechnung/11_18/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:92778
URL: http://learnbuddy.com/Telekom/Rechnung/11_18/
URL Status:Offline
Host: learnbuddy.com
Date added:2018-12-11 03:26:57 UTC
Last online:2019-02-09 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-11 03:28:26 UTC to abuse{at}webhuset[dot]no)
Takedown time:2 months, 0 days, 5 hours, 17 minutes Bad (down since 2019-02-09 08:46:09 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-12-11rechnung.docdoc 071da6eddd102473494cdf495c3526abb0325ff999725fec276439ecd8b1cd1fn/a Heodo
2018-12-11rechnung_11_2018.docdoc 14189cf7847135fba2eb68d4420b07ec51b43a8210fb4bf36e3c0ff99b4a7700Virustotal results 34.48% Heodo
2018-12-11rechnung.docdoc 0031b50822f6773844ef1e5393571bbf5ca23e11d02c58c6340503ecab775f2an/a Heodo
2018-12-112018_11_rechnung.docdoc b26443f2ac3d9d18f9ebd8ff1d007cddd24b11c0e619efc298dc0871021ff715n/a Heodo
2018-12-11rechnung_11_2018.docdoc 71f5172915f4754b4d65518c98ff95193a1722dbe51f6fd8d76ce12a7c2f2d11Virustotal results 30.00% Heodo
2018-12-112018_11rechnung.docdoc de08a0eb8e2c716cb05fa39139d63efae52943c5c9d2ae4682c0530d45bbc8bfVirustotal results 28.33% Heodo
2018-12-112018_11rechnung.docdoc b607f1257e688c74ba288659b8271f4ae57e187b92e499e3672a89ea8ad31ef4Virustotal results 31.15% Heodo