URLhaus Database

You are currently viewing the URLhaus database entry for http://niebuur.nl/blog/i1h-pn0-8740/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:433378
URL: http://niebuur.nl/blog/i1h-pn0-8740/
URL Status:Offline
Host: niebuur.nl
Date added:2020-08-14 16:27:34 UTC
Last online:2020-08-17 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-14 16:28:07 UTC to abuse{at}pcextreme[dot]nl)
Takedown time:2 days, 15 hours, 42 minutes Poor (down since 2020-08-17 08:10:32 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15INVOICE-BNB827-63785089.docdoc e13d662598bb11ada832746d3255ee48f3b304a7966714104726abf2db3f6915Virustotal results 41.38%Heodo
2020-08-15invoice 287 5050782.docdoc 911f2bfa86abc00f8fc2ea9dfbe597349baff6522fff47de22aa0ae77f31ece9Virustotal results 41.38%Heodo
2020-08-15Invoice 83 2684362.docdoc 3d3319da15a4774593968e93c815aabd17f3ccdd973793e8f372028cf510fbeaVirustotal results 39.66%Heodo
2020-08-15Invoice_EE16_807323040.docdoc bfcccc993aac3e4b5e5bcd112c1b5da71db89239b7158110aa32cf57c90ec112Virustotal results 39.66%Heodo
2020-08-15InvoiceS7520523288.docdoc 850db6418cb343d6e48f82dd435d9aac4459c3fefb9e9fb9ea1e2455a455a367Virustotal results 38.98%Heodo
2020-08-15Invoice78885107.docdoc 608640cc09523824170abe5439a993ab6057204ad82c3c3af46ac0ebcf7cf38dVirustotal results 41.38%Heodo
2020-08-15Invoice-YSPO3280-16295423.docdoc 903b4b0dbf79ba01b1c8a324c887cf2e6e7ddff21d2cb2091ab77cbc6c13b467Virustotal results 40.68%Heodo
2020-08-15Invoice_BOYK116_340151154.docdoc c9692b48a5184a6d4e5b8407d85ead0a011bb4184612d379f44b93f750aafe1dVirustotal results 37.29%Heodo
2020-08-14Invoice PGEV5 83687543.docdoc fb275585028589c232253e318f2e4a1b8944cc529eb29e830047eee4180a169dVirustotal results 37.29%Heodo
2020-08-14invoice-7094-752725849.docdoc 5ac2b940e6a9bb518d04bcaa38e706d0604dd1c60691ebf2730c04e82aa11524Virustotal results 37.29%Heodo
2020-08-14invoice OA10 200596.docdoc b86c240ff73da180f757c89c445ffcabe432f5274d37075086d28f00b41871d4Virustotal results 37.93%Heodo
2020-08-14Inv-FCVD8256-43195048.docdoc 284869d2f6bf8757c4361deba6f72989a57e8fc84c93be00e7d2e9be8b979d61Virustotal results 37.93%Heodo
2020-08-14INVOICE GWUL4999 127945.docdoc 95e040446bc7580c574cbade1439630a10c27643ba7987ac158b8177db45fa5dVirustotal results 37.29%Heodo
2020-08-14InvoiceN19382961487.docdoc 4e4e13b049124c6db74594ed0351792442e0a91a82abc72f06601c9598c241c1Virustotal results 38.33%Heodo
2020-08-14invoiceVDYK3584676650.docdoc 95cc5ce9259454f349e823d4c1e4c546a303dacfd17dd01c60af5f9dfb171cb6Virustotal results 36.21%Heodo
2020-08-14invoiceMR2311959689998.docdoc 4a01c8e6ec280343403441c5e17c55359032885ef2cfae8ad4fc165f3911bac3Virustotal results 38.33%Heodo
2020-08-14invoice-S98-6987953.docdoc 6b5f7ad9df134c6a4892ee11c2b9d5942174a02fa5e8f5f1b6e4e6c40c3583f6Virustotal results 38.33%Heodo
2020-08-14Inv I003 832173059.docdoc c55efd0311de10fc006e138fc287f244e1b942418fca25593dcc9a1f8f5101acVirustotal results 30.51%Heodo
2020-08-14InvHB229483961.docdoc fe6706ad1c92c8c1fbf1bfaf7cdf31f3f58f5a324da318d3b548674c99a770dcVirustotal results 31.67%Heodo
2020-08-14invoice-HWL2677-62712335.docdoc 62693837af831b541e0cd5818e023baee2f0989413d3dd125721114a5b71ff69Virustotal results 31.67%Heodo