URLhaus Database

You are currently viewing the URLhaus database entry for https://www.volvorotterdam.nl/xmlimport/esp/hswwl7d-96954925-648647001-ppr3ij-ejq8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:287802
URL: https://www.volvorotterdam.nl/xmlimport/esp/hswwl7d-96954925-648647001-ppr3ij-ejq8/
URL Status:Offline
Host: www.volvorotterdam.nl
Date added:2020-01-14 08:11:24 UTC
Last online:2020-03-27 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-14 08:12:04 UTC to abuse{at}netrouting[dot]com)
Takedown time:2 months, 13 days, 8 hours, 2 minutes Bad (down since 2020-03-27 16:14:13 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-16L_3600520877759086004070.docdoc 1827154d65be4bbfbe6b4e3de7f9021f69dbdffea84e9d54109219811b01c902Virustotal results 22.58% Heodo
2020-01-16XDQ_010120_LEU_011620.docdoc 771ad3b2889d51eae42be0c3c53f7ab24667105d94fcd6e6dc93bca8ebbfcd85Virustotal results 44.26% Heodo
2020-01-16INV_OUL4XLB.docdoc bc1ee7ea69d36c03a940c29cfce159c7e7225fbe58610eb697e091e0b242c08cVirustotal results 41.94% Heodo
2020-01-16DOC_MAE_010120_PXN_011620.docdoc e7d0fefc64f0b592432592e65cc0ac1100b788dd475993d389a7817382135dc9Virustotal results 41.94% Heodo
2020-01-16INV_PO_01162020EX.docdoc 026422da953eb322a55eeb64ece300246b5afd8b4ef077f946880d0202522fdaVirustotal results 40.98% Heodo
2020-01-16INV_PC4784178807IX.docdoc 61dd0c8d9334a27a9b7f0a93c8c4f922a4f2b54a8678d15849759e3529794560Virustotal results 40.98% Heodo
2020-01-15ICG_010120_PRE_011620.docdoc 8a8e9cf03bf716afc717c9f37e86050a9d95c576836b48423d8c1b495831a54aVirustotal results 40.00% 
2020-01-15BAL_YJP_010120_WKL_011620.docdoc 3b91b18b63fda2d06afc7d6f8bb924da52b9cedb373615783fbe7ab73477ba15Virustotal results 35.00% Heodo
2020-01-15REP_PO_01152020EX.docdoc 5cef7f012587358911420986b0a10b3afc376e71cbcb62ae2369409a2949e714Virustotal results 34.43% Heodo
2020-01-15FILE_LD6160232060YB.docdoc 746e56dfeb31eb76ca54c4260082c53e799a6cb532561b12c98ee1496f3055f4Virustotal results 32.79% Heodo
2020-01-15FILE_D325IDH7.docdoc 3bd995e4229e3d5adb81c3572c5278e730524b0774cc7a8c4ea710bc4be1ae33Virustotal results 32.20% Heodo
2020-01-15DOC_38875324.docdoc 287ae14e3b1562662edbf0da35eff337a49d911c07fb02c48b681dc3cb8aa7bbVirustotal results 33.33% 
2020-01-15INV_QC5497006084PU.docdoc 406d79f865f35a430a3f1fd8693cc48c262626550022635b1aeeb0e4c39711b0Virustotal results 26.23% Heodo
2020-01-15REP_607153554688983015240.docdoc 23f9f4c3fa726a9b81dc0c06b81c8e3424d251dc412c8ccd81a89c7aa269e4d6Virustotal results 26.23% Heodo
2020-01-15BAL_PO_01152020EX.docdoc b936b2575a8eefa3b592b53c6012122e6965f28cdd12ad4d24b9ef2c44b0cd98Virustotal results 22.03% Heodo
2020-01-15PAY_PO_01152020EX.docdoc 2d5822aff83315cc778085dcd69fd73f82a4cfe94592529b93dacb256fb97713Virustotal results 21.67% 
2020-01-15DOC_MJ6799064713VD.docdoc c9368e7d1cbbbc90b37dac429596452e1d0e2905219f252d6a91524fc9a35f6aVirustotal results 24.59% Heodo
2020-01-15DOC_PO_01152020EX.docdoc 2ca72c2d3e5cfb6ea6d21e71bd79055a1018f327fa309037316a83bba6dee090Virustotal results 18.03% Heodo
2020-01-15DOC_PO_01152020EX.docdoc 9982b18660c6aa9b8419bd84843d2d578fd2afb2516782ac69f0e7f8eee4efb9Virustotal results 18.33% 
2020-01-15FILE_PO_01152020EX.docdoc 5ce93c3671dfbeae75d738d2ffd0204b72b6628c8aea98ccda37891eb1414614Virustotal results 18.03% Heodo
2020-01-15EB_10372724252378.docdoc a7d4e714a1656fa280fa345e1956d3b62141ac7b29d8fc4563c85a5616f886aaVirustotal results 37.70% Heodo
2020-01-14X716MEWI32BEFN.docdoc 83e98736700d0a21733cd80313c433dd405251e5dc3f78ef6a8a341391eb6702Virustotal results 17.74% Heodo
2020-01-14FILE_ID9564216059TJ.docdoc 9ee85b399435a194b9b67f49143134a823ef4dc87f95970c3516773b340fe9afVirustotal results 18.33% Heodo
2020-01-14INV_RPI_010120_WTN_011420.docdoc f5f4d5f08a7cb7e623d0bbfae4b90f9cf9151135d1218fc30b351b23903cbea3Virustotal results 17.74% Heodo
2020-01-14DOC_UGQCLUWI3DV.docdoc 2034078fa59ba80aa4ea104fadd6e28f7fdb58220f8a6c434014ec88a007b0ffn/a Heodo
2020-01-14BAL_SO5632723310EZ.docdoc e43c9ff61cb560195d5292e4b9112a9cd911a56bc9e0e75e3d8226e8a47bf60bVirustotal results 14.52% Heodo
2020-01-14G_230206821121627547.docdoc 7fa3aae043b0d7896bfb5202163589944200dd0370c4c92697c0b72ff8ff1cf8Virustotal results 15.00% Heodo