URLhaus Database

You are currently viewing the URLhaus database entry for http://evandijk.eu/4fd2c798720871f16/public/dkic042yii-00066982/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438752
URL: http://evandijk.eu/4fd2c798720871f16/public/dkic042yii-00066982/
URL Status:Offline
Host: evandijk.eu
Date added:2020-08-21 22:27:07 UTC
Last online:2020-08-22 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-21 22:28:02 UTC to abuse{at}strato[dot]de)
Takedown time:15 hours, 58 minutes Good (down since 2020-08-22 14:26:15 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-22Invoice 00233459.docdoc d264878eae29d3da022f38e67a38560346ba42cbb6dbebbf0e6c852c666fb1acn/aHeodo
2020-08-22INV #0591077 FOR PO #665596574.docdoc 51bb6063711677f1823d4b10c0ae073a340c8392a7b233485d1e181fab2197fen/aHeodo
2020-08-22Invoice #29371.docdoc 564105a864ba17349c0c70d8c11883b4edaf7b9f653bc074d57ec92e33923d61Virustotal results 36.21%Heodo
2020-08-22VE-080120 DZNW-082220.docdoc 817fd6335b92d0b8ab452cc5d00decd2e0919a8fb5b6dbe0730a19432ef5b731Virustotal results 36.21%Heodo
2020-08-22Payment.docdoc 88fafca4b3195bc1843721aa1d78221a5d05be8d88f43ceb0e85aab917c67a43n/aHeodo
2020-08-21CNR-080120 QYWR-082220.docdoc b199113c89d1f14f205054c9a7cce7b661199224054e035b6f5044205dc27cf8n/aHeodo
2020-08-21Electronic form.docdoc d09a4703239b8dd258d5174bc65647fa6b951cecfcb7c2f9c46a29a061a7a769Virustotal results 36.84%Heodo
2020-08-216179732637CU.docdoc 31ef2257cdb7b9006892fb9754673511beaf648f6c3a899b9bff3031310a9acfn/aHeodo
2020-08-21Payment status.docdoc cd51eb10684d011728e273a115ce4655403d5a5fb2d0ddf0d015e93aaba39852n/aHeodo
2020-08-21Invoice #16911910.docdoc 2d4370eba117c88617870ab941572195d2facde4eb4e1d768507d37840812da2Virustotal results 33.33%Heodo
2020-08-21invoices 816 & 33781.docdoc e5c9f8c0ccfa47835d30be512636ad1b0e40d75587d5a309f586b67796aae5cdVirustotal results 33.33%Heodo
2020-08-21Form.docdoc df8d09457a129b57c4740b237ac226b0e0245d035dc20930563bab681e98e8c9n/aHeodo