URLhaus Database

You are currently viewing the URLhaus database entry for http://deheld100.nl/WIRE-FORM/UOS-1299/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry

URL Status:Offline
Date added:2018-04-06 05:42:03 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Abuse complaint sent (?):No
Tags:doc emotet heodo

Payload delivery

The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2018-04-18INV-FR-777108737956.docdoc14b5e36e66e149a4c2abe4c4d6a9d0c5f02155b4f47778fb228f2c325dd8e3a2Virustotal results 34 / 59 (57.63)Heodo
2018-04-06INVOICE-KVC-69996939.docdocb17d906024b15f1e0998c7eae0adc8afb537bd6b21fbd757369312a681cbfc23Virustotal results 5 / 58 (8.62)Heodo
2018-04-06INV-RBP-16165734627597.docdoc3fa491121719371e32e5bc30bad48ba40966df9288c37e3c6ca379a09ee4a3c0Virustotal results 10 / 58 (17.24)Heodo