URLhaus Database

You are currently viewing the URLhaus database entry for http://werkhanden.nl/blogs/aKTFjR/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431831
URL: http://werkhanden.nl/blogs/aKTFjR/
URL Status:Offline
Host: werkhanden.nl
Date added:2020-08-13 11:39:51 UTC
Last online:2020-08-13 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-13 11:40:05 UTC to abuse{at}caveo[dot]nl)
Takedown time:7 hours, 40 minutes Good (down since 2020-08-13 19:20:30 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13invoice_8734_266733.docdoc a0174ce27bcb676191641c4b06722c67732d37458580fcda2aca969593f838d9Virustotal results 35.00%Heodo
2020-08-13invoice-ZRJ7-477795.docdoc 5912b8e3ef4983ff2a2edb2097d0149b2828a6d735e579fc964a0a938c0afac7Virustotal results 34.48%Heodo
2020-08-13invoice YK89 5416582.docdoc b38d736d513ae70545b3d388dbbf8e9e327be6276a22fb4e10422991f08dd1d7Virustotal results 32.20%Heodo
2020-08-13Invoice UKQ243 071990.docdoc 9c555a84e2b325b4c2d60e9dba477c087791380312f4c5c664d3ab4f1c47ab86Virustotal results 31.67%Heodo
2020-08-13Inv_YF0035_769333.docdoc 262e07a3ff5ca03cce8ba821a3e2f93960ecfebd9febd42c51621b3edc77fd04Virustotal results 30.51%Heodo
2020-08-13Inv SFN7827 167523.docdoc 8d7640adaf6a576ce6484be49d372141feaf9dd38837bf8da72271ce7ae7e127Virustotal results 28.33%Heodo
2020-08-13invoice_NKND5_159976.docdoc d2cc4f61f498dbddde048bbb918416d73f063a0bb46c960ab7fd6fe671ed9bd1Virustotal results 25.42%Heodo
2020-08-13invoice-SXM543-6245357.docdoc 335ffaa3c9914aabf84fec4cf13a891465b4c0c3700777b1fa2877df708b4c7en/aHeodo