URLhaus Database

You are currently viewing the URLhaus database entry for https://witje.be/dutchphotozone/LudZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421778
URL: https://witje.be/dutchphotozone/LudZ/
URL Status:Offline
Host: witje.be
Date added:2020-07-30 04:55:08 UTC
Last online:2020-07-30 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-07-30 04:56:03 UTC to abuse{at}axc[dot]eu)
Takedown time:5 hours, 23 minutes Good (down since 2020-07-30 10:19:05 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30INVOICE_P62-85555896.docdoc a12c802c14ee523d5fe6b5ececa5018201d45d0f57281b23593be0117029d867n/a Heodo
2020-07-30INVOICE XLJ93_43698071.docdoc 099dbabbf2a1939ad6103ee587d3777e00c2d83f0d0f4e2343191d546dc349abVirustotal results 40.98% Heodo
2020-07-30invoice-166{:REGEX:.docdoc c171e3eb929b57d92d6a1a2e4e81a36dc1233be6abf5dce5e51dac677ec50017Virustotal results 40.68% Heodo
2020-07-30invoiceVEY813-6326793.docdoc b831558e10d067342a4e9ac952a95de0a3054302bc7b79610b6649784442e013n/a Heodo
2020-07-30invoice5-41044041.docdoc 84f1793acc6d7c229aed03c0334fcb223eb89415c1d96b08822e988c1a5652afVirustotal results 45.90%Heodo
2020-07-30INVOICE-3{:REGEX:.docdoc 12d1ea6204e341522115a4cd2fe28cfe7bdef98bfdc7acd4be32e011346efc60Virustotal results 45.16% Heodo
2020-07-30INVOICEG867{:REGEX:.docdoc 72e418e68d70107f35d0b84311d2fe8e97b317936f99994e6cbb0567b9931275Virustotal results 45.90% Heodo
2020-07-30InvoiceJSYZ9 0941767.docdoc fd4e7761b18405677fc5c8737a34ace11283a0c1503a19a20120c9f36af7c004n/a Heodo
2020-07-30INVOICE-D15{:REGEX:.docdoc 1bb56e849596fd788a8c9905d08684f8043a4cc4e72209d9978d78aa4f9f6f22Virustotal results 45.90%Heodo
2020-07-30invoice NX6{:REGEX:.docdoc e4253aa05a6d37a3938d0a58becfa9533a305a661d68cefd0c7aa37561fa5c41Virustotal results 46.67% Heodo