URLhaus Database

You are currently viewing the URLhaus database entry for http://www.willow-nettica.com/cache/esp/422207343599363/jahi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:440812
URL: http://www.willow-nettica.com/cache/esp/422207343599363/jahi/
URL Status:Offline
Host: www.willow-nettica.com
Date added:2020-08-25 08:27:05 UTC
Last online:2020-08-30 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-25 08:28:02 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:5 days, 1 hours, 6 minutes Bad (down since 2020-08-30 09:34:20 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-29August Invoice.docdoc 5df4f10d255d1733e9450ecf67d166c73f6f29bb36efe88d6093a31d31ce0ad4Virustotal results 45.45%Heodo
2020-08-28PO# 08282020.docdoc 7e0d6fc8bc7a69d5e27e2130c83b434512af52a5337145098c2426f62abf97eeVirustotal results 38.98%Heodo
2020-08-27form.docdoc 907ddcc7b2dd5151f379c7897b9de25bfcf3e3f5a8a58043b3339a540ee5ab76Virustotal results 32.20%Heodo
2020-08-27invoice.docdoc da24bcf9ae9edfa1f1b02f6edee01e2ccc3b37220462cafa4f4771b3309bccd2Virustotal results 32.20%Heodo
2020-08-27Invoice 00335232.docdoc 5bf845e70cde6a5112d1aec081e98995bc8494ce31682762bad07ec7c92a2889Virustotal results 32.76%Heodo
2020-08-27Electronic form.docdoc eabd205d0597750c6a3f5465e5e597bc6dc1628bdc539cae4cf2dc9cd206cd80Virustotal results 34.55%Heodo
2020-08-27invoices 691 & 0236.docdoc ddff49cf8e07d1993383483d2d6d1b965048988f50a8b7933c4142c8475b5054Virustotal results 33.90%Heodo
2020-08-27August Invoice.docdoc da3b782e6c4b16798bcb8fac5b5492d7cb66148eef2014f9706a9773dc1b19cen/aHeodo
2020-08-27Form.docdoc 6dc1fb576692231c12eaedeb19d6f481586673ad6666e1bfddebd6e0a8a3a748Virustotal results 32.20%Heodo
2020-08-27invoices 41138 & 2273.docdoc 8969e1e9e29920ba44157da474d4851706f1f63a58b7cd36a87845beaea2af9aVirustotal results 29.31%Heodo
2020-08-27Form.docdoc da824fbeb1aca76e08e78a0e568930de8ef2c71147fcdc20943bf61f59e8a477Virustotal results 29.31%Heodo
2020-08-2700237690235.docdoc 8bdcec34c84cc135921583dd376cf67fc6cd99932b93cce14aa3fcfad9a2b0dbVirustotal results 27.12%Heodo
2020-08-27invoices 229 & 83774.docdoc eada7caedda99d532082edadceb81195adb094a6d2b9d284fab4974d8eb8235bVirustotal results 27.59%Heodo
2020-08-27Form - Aug 27, 2020.docdoc de37d3996ded165d226f85b7e9bb64cc5b9682a8d745de87548b0bc5be52cea8n/aHeodo
2020-08-27Invoice 005233100.docdoc 08531c896c900816e373957872ce7e55db50203fd681019719dca8fc27882b40Virustotal results 28.81%Heodo
2020-08-27Inv. 0034719843778.docdoc 8961b61c4631b8c84367078e44fc1066f57830e0bc0622af1de7769f82e6442eVirustotal results 28.07%Heodo
2020-08-27INV #09516074 FOR PO #0338813146.docdoc 2bae2742fb283aa2f35ef1722797919ff00e34f7e1868ca7841fc5baafdefe96Virustotal results 44.83%Heodo
2020-08-27Invoice 867646.docdoc e45a7277159aac8916096aa45b400cdd23c26f876fb6a1753d95e1119c352259Virustotal results 31.03%Heodo
2020-08-27invoice.docdoc a12169bfd5b2999a36e090c627578d1d8c9a00225ae68ec13361f8c61de5cee6Virustotal results 28.57%Heodo
2020-08-26INV #0087 FOR PO #006669316.docdoc b11bd4b83e89bc246bf2b88dba510f02dfbeb9742d55087260bfeb43f0049000Virustotal results 28.81%Heodo
2020-08-26form.docdoc c0b72b161a48dab0be1f4cf804079f65cae5827a62e982b8af3fe00a2281dc0fVirustotal results 28.81%Heodo
2020-08-26form.docdoc 900e897c3d7f08039833fa89748e84c98a62d959e4e8e8cc54c832acd902470dVirustotal results 28.81%Heodo
2020-08-26INV_7021.docdoc 6ed646f54add9ca22852e2fbe34861573a88cadccac53c9ccdaeffe7db82d284Virustotal results 27.59%Heodo
2020-08-26Invoice 3688582.docdoc 89861158cf9124252fbe1391e796281b6339c99c567adbe068f12ef9c084b2b4Virustotal results 32.76%Heodo
2020-08-26AN2512057100VV.docdoc c40321521d2ea19112d0ec97e6d9e721a8aed19d9c699b794711afca783d4616Virustotal results 29.82%Heodo
2020-08-26NYK-080120 XXKH-082620.docdoc d5c549eee018841e8c99ea2b6fdb5d625863689a0758458bed6ce909cf5e3e28Virustotal results 30.51%Heodo
2020-08-25Invoice #5561.docdoc ec5481a4d0c8f1f2fb3fa3b0ef29f2503070792580bf42f1ce5fdd7920fdd600Virustotal results 27.59%Heodo
2020-08-25Invoice.docdoc 34fa72d4ff57cb8e628c79afd9156da3004c48c500775b4acfdbb3eef2ba14ccn/aHeodo
2020-08-25August Invoice.docdoc 0a37a406bb9f11888ea941b2c01af3360399d39bf3e6833cf06b7a5e06504797n/aHeodo
2020-08-25INV #0902 FOR PO #091069417040.docdoc 09d6f5f192473d2ddaa883c105e9c0fdb00487c1b90a0e34094b728229d8b947n/aHeodo