URLhaus Database

You are currently viewing the URLhaus database entry for http://witje.be/dutchphotozone/LudZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421730
URL: http://witje.be/dutchphotozone/LudZ/
URL Status:Offline
Host: witje.be
Date added:2020-07-30 00:17:33 UTC
Last online:2020-07-30 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 00:18:02 UTC to abuse{at}axc[dot]eu)
Takedown time:10 hours, 1 minutes Good (down since 2020-07-30 10:19:05 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30INVOICE_P62-85555896.docdoc a12c802c14ee523d5fe6b5ececa5018201d45d0f57281b23593be0117029d867n/a Heodo
2020-07-30INVOICE XLJ93_43698071.docdoc 099dbabbf2a1939ad6103ee587d3777e00c2d83f0d0f4e2343191d546dc349abVirustotal results 40.98% Heodo
2020-07-30invoice-166{:REGEX:.docdoc c171e3eb929b57d92d6a1a2e4e81a36dc1233be6abf5dce5e51dac677ec50017Virustotal results 40.68% Heodo
2020-07-30invoiceVEY813-6326793.docdoc b831558e10d067342a4e9ac952a95de0a3054302bc7b79610b6649784442e013n/a Heodo
2020-07-30invoice5-41044041.docdoc 84f1793acc6d7c229aed03c0334fcb223eb89415c1d96b08822e988c1a5652afVirustotal results 45.90%Heodo
2020-07-30INVOICE-3{:REGEX:.docdoc 12d1ea6204e341522115a4cd2fe28cfe7bdef98bfdc7acd4be32e011346efc60Virustotal results 45.16% Heodo
2020-07-30INVOICEG867{:REGEX:.docdoc 72e418e68d70107f35d0b84311d2fe8e97b317936f99994e6cbb0567b9931275Virustotal results 45.90% Heodo
2020-07-30InvoiceJSYZ9 0941767.docdoc fd4e7761b18405677fc5c8737a34ace11283a0c1503a19a20120c9f36af7c004n/a Heodo
2020-07-30INVOICE-D15{:REGEX:.docdoc 1bb56e849596fd788a8c9905d08684f8043a4cc4e72209d9978d78aa4f9f6f22Virustotal results 46.67%Heodo
2020-07-30invoice NX6{:REGEX:.docdoc e4253aa05a6d37a3938d0a58becfa9533a305a661d68cefd0c7aa37561fa5c41n/a Heodo
2020-07-30invoice-M63{:REGEX:.docdoc ecf4ab854d4a1e6a7ba13db64e46d84063213d4f414e2306bcf480eeac13ad5dn/a Heodo
2020-07-30invoice-MIPA6621{:REGEX:.docdoc 7579d4a1d6d4da73019950ba9cd7de417560465889ccbc12fffbebff6b87ca3cVirustotal results 45.16% Heodo
2020-07-30InvoiceNXG40 7250299.docdoc 1a9250e336b85ed5971242f5611efb67fa4554cc3354854fea2052257bbcec08Virustotal results 45.16%Heodo
2020-07-30Inv154_425107.docdoc df7de8a45da98d24665a7c9c5457068fa727454bed406b47af9803d36b46b7a3Virustotal results 45.90% Heodo
2020-07-30Invoice-OJU09-063566.docdoc f6e93dab00f7bdbe24a8c69f83230bf76e626abc42f83f0065cd99b483bdbc06Virustotal results 44.26% Heodo
2020-07-30Invoice-AZ0_20659581.docdoc 133d58f3c65e1886b5480e277bb845f9d97a7177d1da22625c6a977553b374cbVirustotal results 47.46% Heodo
2020-07-30INVOICE-HJ4 573987.docdoc c444016d70224a2cb4808352f39232719d705243dbaf2321c3aed6cee511890fn/a Heodo
2020-07-30Inv-JT11 76021413.docdoc f1761ccaa75c38c0b7a7816b613688bcc01590af8717fef82dc50d9620ff7838n/a Heodo
2020-07-30INVOICE_979 160928.docdoc 47c3d5ad152badf3a17ebce781f3d060a059bdb107a1b8c7726469a95025e911Virustotal results 45.90% Heodo
2020-07-30Inv Y18{:REGEX:.docdoc f514ac7cf2027c38ccb289da23b3c3f22466682e3641843d749e800125c61c65Virustotal results 43.33% Heodo
2020-07-30INVOICELT13-403266.docdoc 0daff577173686557b6c179acf668ffbbc64cfecd2545ded9102108e81b557e3Virustotal results 44.26% Heodo
2020-07-30Inv-O0191 850214144.docdoc 299b8c34cfaa47a3f884d83e3b6ef10c75f0552bf3b16350d44d8ca86f89c8baVirustotal results 44.26% Heodo
2020-07-30Invoice_WTS71-433116789.docdoc e32b2c8e2433ba25e873642b54b3a403953d5bf9fd077801999e5534b4f2b791Virustotal results 43.33% Heodo
2020-07-30INVOICE-URBR530{:REGEX:.docdoc 9073425e395c1b7a8d42cabd461cad86cd0646bd77f042e13bcd2f98979fe12dVirustotal results 43.55% Heodo
2020-07-30INVOICE YT11_17690855.docdoc 9682cb3fed20b168899452201908168de9b2c2d82530d7227a4474b8b2587eb8Virustotal results 43.55%Heodo