URLhaus Database

You are currently viewing the URLhaus database entry for http://henkphilipsen.nl/cgi-bin/multifunctional_section/corporate_portal/wXJajgjtZv_wMv8c0hb03pm9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:273544
URL: http://henkphilipsen.nl/cgi-bin/multifunctional_section/corporate_portal/wXJajgjtZv_wMv8c0hb03pm9/
URL Status:Offline
Host: henkphilipsen.nl
Date added:2019-12-20 03:36:03 UTC
Last online:2020-02-21 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-20 03:38:05 UTC to info{at}vertixo[dot]com)
Takedown time:2 months, 3 days, 10 hours, 34 minutes Bad (down since 2020-02-21 14:12:50 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-27release 12_22_2019_5FA32549910.docdoc 97952f368a5722f98e993a06c5dcc290d5ab8f65d35bef26e1c6d471638ba66bn/a 
2019-12-21release_6491603479-0164.docdoc 1aadecae9e168d092eb93dbad3f0473f5c2c11233263ed2ace1269ae81743868Virustotal results 41.94% 
2019-12-21last receipt 12212019.docdoc 37aa7ca6a936d76db6e8f8060a5eb4c556339653d6a82c4b11667d28f81af587Virustotal results 38.33% Heodo
2019-12-20newest-89158.docdoc 06e964cd2981bc6abea29dd680ea91ffff97629d97d557f306066da6c354c5c1Virustotal results 32.26% 
2019-12-20final reference_12212019.docdoc 0ddd05f4a301e8919c22f9b5a404d93db3d5aa3e3dcd7b5b3e014e189b297b2dVirustotal results 27.42% Heodo
2019-12-20receipt VQE545734 26779241.docdoc 0a430db8f97c853692ab17929306a7a3ac9523448c878e51c0fe7a1665833f24Virustotal results 27.87% 
2019-12-20instance 12_20_2019-D950503.docdoc 109da0381499feaa9d9bfa202a146781bc1777476841f0c5847015f7a6fa92c5Virustotal results 32.79% Heodo
2019-12-20correct_adjustment-0K4941583701 144987727676.docdoc d4695b412365970f3061a9b994950dfe0309bb4c7bcbdc99c384c02026faa1d7Virustotal results 29.51% Heodo
2019-12-20correct_release_12202019.docdoc e10256aa8460c9c6df046fee0c72c6d41130ea4ff241d3f85eb707d89b812225Virustotal results 28.33% 
2019-12-20last duplicate_Y9394-51615.docdoc 33fd0465cb66a32f30e88e45cad70257f866ed7cff9763293a5894da2b32af7dVirustotal results 25.81% Heodo
2019-12-20GreetingCardChristmas.docdoc 38ccc50635da609242ef8381984b03bd8fa7e79e50c8d62467f8b5e5533b12cfVirustotal results 26.23% Heodo
2019-12-20last-adjustment-GZL42919-48142028.docdoc dc98644b4039cf69b3aeca3e755ea9380f66cc906fe23126044154fd4655be53n/a Heodo
2019-12-20approved info 12_20_2019_6668616895982.docdoc cd7a55ac732ab54dfab8e759c6d2154fe0264126180f22ed51466a8a40ade585n/a Heodo
2019-12-20approved 12_20_2019 72D67074692.docdoc 0d24eb3bc04dd6a7df975e688b8fd13fb4c325e027327c7c278f2ce0b2350f4dVirustotal results 22.95% Heodo
2019-12-20adjusted_notice 12_20_2019_G31994.docdoc db1b7614f7990cf6a79141f12cb65d47eae15099ee14be39f8cfee9872b1bd02Virustotal results 22.58% Heodo
2019-12-20statement-L1Y36319.docdoc 2edacd46f6c7cb24386f8fe787b887d16ea418e10ea242fc4d357dbda24e66c3n/a Heodo
2019-12-20adjustment 12_20_2019 21167418698662.docdoc f2c96c17e9d5ddcc9566bed87b8f102d64e68b1b1482eaddee95106f34a53029Virustotal results 36.67% 
2019-12-20adjusted_instance 12202019.docdoc 50ef9a5f6ef2cd9539a0b58a8f8af3fba684f119fe6ded32b0ec2867bf727498Virustotal results 32.79% Heodo