URLhaus Database

You are currently viewing the URLhaus database entry for http://henkphilipsen.nl/cgi-bin/report/z4kmvh0vp11/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:271161
URL: http://henkphilipsen.nl/cgi-bin/report/z4kmvh0vp11/
URL Status:Offline
Host: henkphilipsen.nl
Date added:2019-12-18 00:45:03 UTC
Last online:2020-02-21 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-18 00:46:02 UTC to info{at}vertixo[dot]com)
Takedown time:2 months, 5 days, 13 hours, 26 minutes Bad (down since 2020-02-21 14:12:53 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-13BAL_3693781501707861001.docdoc 47059befd95e478f1d955ee0ac2876a3e7a23198b57aab65ef09030da8e994cbn/a 
2019-12-20BAL_3693781501707861001.docdoc 88dea847c0d9ad574162859c94ca13185358866f1ce7682c2c93a3c2c5e6ffc5Virustotal results 31.67% Heodo
2019-12-19INV_06131798.docdoc 6654c36357d506c482c80fadd76c10be4277a27dc8c2a487e3504728d03d5c3eVirustotal results 29.03% Heodo
2019-12-19PAY_FB9607817647KF.docdoc c47565767b41e8ee3afc13533f44790a8d5134d4401fbe561df065d7d34cf6bbVirustotal results 29.03% Heodo
2019-12-19339121847456688102036.docdoc 22bda4cce67bfe9127f137d1ef842bd42ab38bd2832627f30e2642bd678f2667Virustotal results 29.03% Heodo
2019-12-19SW_WRI_120119_GMH_121919.docdoc ad6b961455a212d6505b4b8b903b98a059789e6d046c1c8133b44d6dcae8ccc4Virustotal results 30.65% Heodo
2019-12-19FILE_A83TPQ2.docdoc ecbdfabbe7a27728ab5c593ab914ee50b4b0f84d3bd1ca8bf600c938ca4d2958Virustotal results 26.23% 
2019-12-19FILE_PO_12192019EX.docdoc c79f40cfb009b268e902bea957d269dfa451e71d85b26ea957854bd4bf25e7e9Virustotal results 25.81% Heodo
2019-12-19PAY_95467352.docdoc 3588991c8173834c8c413bbee1c1f5dce7f308ead3e9339e250c75e95459921bVirustotal results 27.87% Heodo
2019-12-1920954000.docdoc 6b73128fead1fc3fd302bdbd666f72664d09c73a2dc65ba765383492a522f88dVirustotal results 25.81% Heodo
2019-12-19REP_TKF8J24.docdoc 680e2b8bdd4e9ff629943f71f9520e38d77b6357396863dc1912acf559f0f181Virustotal results 26.23% Heodo
2019-12-19ST_OIC_120119_YVE_121919.docdoc 1735d3c1c0d1500169d6a078c16216336af67c126f9dc97046f18d8f3c5a7d86Virustotal results 25.81% Heodo
2019-12-19HB1TE0139POA271.docdoc af99044dda284f10eb4fcd1757f0aa82b623b3193b48a5fd3aa1ea0ea19ab041Virustotal results 26.23% 
2019-12-19D_LE9990003950EP.docdoc 6a209d185231e9b9e146b04a44e886d6387f51a8972bcb3f0b492f9c11e8c0c5Virustotal results 22.58% 
2019-12-19G_SV2341542037RK.docdoc f8e09058c07066ec081facf80968b241051ed56f16ac468a976bf07e6e31770eVirustotal results 22.95% Heodo
2019-12-19DOC_JM2989774242LU.docdoc 32b16c30ff6c2a8ffbe3afd1318566c3bda00191296af85b263639d894eb4600Virustotal results 22.95% Heodo
2019-12-19PAY_07089592.docdoc fcdead0b8e8008e8a5e550eeaae038688caa85e88b7108e45b9ac12ed81ca830Virustotal results 21.31% Heodo
2019-12-19W_PO_12192019EX.docdoc ec2cbbdaa442e182f9375cf3860d8ec64897319a62aca277d9f3c2cc5005d888Virustotal results 31.15% 
2019-12-19655337043.docdoc e4cff33774c6680c4f2e21c49fd53035033df8960dcdd09ab257f157f3bdbd09Virustotal results 30.65% Heodo
2019-12-19X_29486433.docdoc 25c2ee71d3634d4faae32d7a915af893e09b1f36fd93acb0b76e310a9c307758Virustotal results 32.76% 
2019-12-19INV_PO_12192019EX.docdoc 8e0c8ce71d167427a04e9522cf9e4ee7f7a9eca9261c0dfa41d4d8f48a265031Virustotal results 30.65% Heodo
2019-12-19JO6418N.docdoc ea610e377fb05e116bfbd7c572a9f17adb6c6a03e7f77a24469f27c3eae9f72cVirustotal results 25.00% Heodo
2019-12-19LNYZJJ94M12.docdoc 22ff57b28ae475c76cda6b53efe3c641c2c32a74f593b7f7a7612cd8e4fea151Virustotal results 24.19% Heodo
2019-12-18UIZIJ7YU.docdoc 2f37a55acc32e7d59e31d6c98effdc3171e447d51f5aceea59451fe493461b9eVirustotal results 25.81% Heodo
2019-12-18QUA_120119_VPG_121819.docdoc 53c21d965d731f212e3c62743ad88519b2a4290af20dfadf8ba74762743317bdVirustotal results 27.12% Heodo
2019-12-1875585170.docdoc 3c343dbc7eda88227ce41d5722e11d89a0c4edad93a4d82a954fce768e563d79Virustotal results 24.19% Heodo
2019-12-18PO_12182019EX.docdoc 8b974a004a4926372021ced18f1b480e32367d38fb9e5e8e29ef08f9b03232f4Virustotal results 24.59% Heodo
2019-12-18PAY_HOV_120119_UUF_121819.docdoc 6f2ee6ab0615008c2f192248ddd134e9128b5c40bcd96650dfd4ae5b971b3dc8Virustotal results 23.33% Heodo
2019-12-18CVH_120119_KEV_121819.docdoc c67ebfab527d11f2dd8e7bd5e2b7ba17304cfd6e8452647b8283a721141940d1n/a 
2019-12-18S_009555231435230279308808.docdoc 171e26e1ed7f8a422b2a0f5098949d0faac6938cabdf6a5ef2aeb95761c92eaeVirustotal results 22.95% Heodo
2019-12-18RP_RTO_120119_IMY_121819.docdoc 1da21161c3b262c0d4ac93cc840d81fd5c11da581f78aacf765c2cf33a2e95dbn/a Heodo
2019-12-18SW_39618794767.docdoc 5757449785632b624ff738f718b04e00758e864f469378b8c513d55346c5d3a4Virustotal results 20.97% Heodo
2019-12-18PAY_VCT_120119_JSC_121819.docdoc d19458049a137e1bfcd3f580aeef39686b6e1ea204dbf4f4a3abf79bcde08016Virustotal results 42.62% 
2019-12-18O_35581890.docdoc 53f9a8929a317cef9ef0be07118146e7ca56149c35b7552645999b1c6ebae147n/a 
2019-12-18PAY_9CZNZMK58VEZS.docdoc 5d06e9b005226160b0e131f85812f4f98077b439baebe2581f27b3678c920990Virustotal results 41.94% Heodo
2019-12-18BAL_OFH_120119_DCR_121819.docdoc d93540d00b3e0df9c0d44218338d46c79dbbe156480a89c7f298ae1ededbc1d1Virustotal results 42.62% 
2019-12-18ST_6631993676884876474.docdoc 7c7fe6921fd0483b165be4f787c8d10c0cc92e33a275dee48ab6454ced2df79aVirustotal results 37.10% 
2019-12-18WS0797436032EP.docdoc e859fef5b3b896160b2e42fb79279fe4e15848fdd74ef37b969c4eb2bf3a558dVirustotal results 36.07% Heodo