URLhaus Database

You are currently viewing the URLhaus database entry for http://berith.nl/default/US_us/Past-Due-Invoices/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:57490
URL: http://berith.nl/default/US_us/Past-Due-Invoices/
URL Status:Offline
Host: berith.nl
Date added:2018-09-18 15:36:04 UTC
Last online:2018-10-10 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2018-09-18 15:38:02 UTC to abuse{at}axc[dot]eu)
Takedown time:21 days, 20 hours, 20 minutes Bad (down since 2018-10-10 11:58:22 UTC)
Tags:doc heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-19Invoice # 7RY87818.docdoc aa81494f5a31cb8f9ebbb71476f2baf8e1ce0c7ddc17ce6e2305ed1d481dd19fVirustotal results 25.00% Heodo
2018-09-19Outstanding invoice.docdoc 086c567118851a68bb669dec660860681a9e1379038f61ec3a71f7ae335fa362Virustotal results 26.23% Heodo
2018-09-19Month notice.docdoc 2a62f453555053cafa8d3ecce082c0bcd83171be76d79e9177b9bff70be01195Virustotal results 26.67% Heodo
2018-09-19Accounts - Invoice.docdoc 225b8bc347307912cc0da70b1060fc2962839ba08a21ca3a2476ab2bc7400928Virustotal results 46.67% Heodo
2018-09-19Accounts - Invoice.docdoc 225b8bc347307912cc0da70b1060fc2962839ba08a21ca3a2476ab2bc7400928Virustotal results 46.67% Heodo
2018-09-19Invoice as at 19/09/2018.docdoc bb8f4ec84bd958bef701ed23674fb0e7d60bf8ae0ddd802f0928ed2a0fbf92c4n/a Heodo
2018-09-19Customer No 393297.docdoc 82b649d074063f4e07887337e94459474d0cbee28627802c8f2022c58fa8414dVirustotal results 46.67% Heodo
2018-09-19Billing Invoice - Job # 7850455.docdoc e8025adabc32213ac3b761dbfc6d13eb0e0a66cf9f7ed26d32fd97063c09c968n/a Heodo
2018-09-19Inv. no. 128L2059364.docdoc b0f529669e720e5288d97e9b9a8359cc4dc54d859f5504a336d03e965252877an/a Heodo
2018-09-18Invoice as at 19/09/2018.docdoc 32c8ab0b2762bb7c2ed5510280c9d880aee17e46f46bf652a12b6568de97fe8eVirustotal results 45.00% Heodo
2018-09-18Statement as at 18.09.2018.docdoc 11c4c9955d77e8c297320755568bfeffd73e77b2f8f6d516aec73bfdcb4ae5c5Virustotal results 42.62% Heodo
2018-09-18Inv. no. 658X01661.docdoc 9261dc4ae5f52e5bc5763d6b19d3f6dfc1b477443a529be859b5768c5a5d0645Virustotal results 39.34% Heodo
2018-09-18Billing Invoice - Job # 975245.docdoc ac7bc7c46c9a390b9fee9aaa11c54c1176815f67018e3a7ba7cf12ed496245d3Virustotal results 37.70% Heodo