URLhaus Database

You are currently viewing the URLhaus database entry for https://ambulanceservice.nl/export/FILE/nzYn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:610697
URL: https://ambulanceservice.nl/export/FILE/nzYn/
URL Status:Offline
Host: ambulanceservice.nl
Date added:2020-09-24 21:10:07 UTC
Last online:2020-09-25 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 21:12:02 UTC to abuse{at}microsoft[dot]com)
Takedown time:15 hours, 35 minutes Good (down since 2020-09-25 12:47:30 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-257dzu.exeexe afd5a52d8b00adf781118dc7e4f90b71cc4fb685606ec5cfc7cbc8da1c65ff63n/a Heodo
2020-09-256Ii.exeexe bda21933890b2623dbd1d42b9d2e6465243b6769042bb5091519776cc4afcb08n/a Heodo
2020-09-25wVSqF2YkUTw.exeexe 07bfe9a4bef900fb04d55ae45068fc20507ced8837ed6db8033449bb93f55794n/a Heodo
2020-09-25X7AOtJT.exeexe 80b8266e7a9bfa0e0f821c09f82f7197bf69471cbae0b7609a8fa0b059323e49Virustotal results 44.29% Heodo
2020-09-25IQmMkpw.exeexe da457d140b4d1f0ef6b812dbd1dc7f378e50b457a0021e0fc048c08114f890dcn/a Heodo
2020-09-25YgsVuzjDouQq9Fwghyia.exeexe c1c5e72e58b3ae6dbe08bd604b5107c7db4526e9163784e47dadfa14415ce131n/a Heodo
2020-09-25TPkSSQ5gf8t1b.exeexe b34fc494f7f333f3f572fd13d927500b04ad8cbb8cfab422815e1f4b34d2c8cen/a Heodo
2020-09-25Kx2KE.exeexe 1e7157f80fa6da141e4cd5bf5579dba71bb897c8c36159ca8201d868feea1b3bn/a Heodo
2020-09-258xVX0lBFhMPCFnC5pXh.exeexe 75556eb396847e3fef06bd318aff4a69a457081e16139608246c423d406b1505n/a Heodo
2020-09-25GiphaNvvDSTzJx14K.exeexe 31003bd3b7e6f458f49019d10d826d0780e00928f499d28644d3d0a4417eee95n/a Heodo
2020-09-25GBK80t00.exeexe 652a1e14184a56177d95dc4eba7440fa60d4d0fd20dc0b5c40ddf8f71d50ee18n/a Heodo
2020-09-25mldTrp0faquCw7H.exeexe 2ac8b6c6cad026f7d572368a416a16fb63addafba80973b259ffd7449024be32n/a Heodo
2020-09-25UurpADPjyTTBgF.exeexe f6cf098393033aa04c3fc2c573ae814f5506e69052bb832396b7403a8cbe571en/a Heodo
2020-09-259YvKJTzxNBPM.exeexe 6d106d3de794ee7181c3ec1076b749c41c3856a871afebdb880b191aabdf162en/a Heodo
2020-09-25Qon.exeexe 09fb9c4436ba8f1169df22f6ff45003fe9b1cd64fd9646b9e68d367d03593aaen/a Heodo
2020-09-25XCxABvQt5U.exeexe ff765badfe69eee680f384c9249e56711bedac969550a01678789abcdcd1e974n/a Heodo
2020-09-25aIgnhzxx1p3.exeexe 537331daa494258a537ee547b7936e3202c06ed756117d93d2e4a009c3589914n/a Heodo
2020-09-25IZcCEkzXT.exeexe 60b3264cd5e5345410c27217f13e152c82530ebc04a74c4872f80713056c3bdcn/a Heodo
2020-09-25fb7sHcODEPeN3xWh2fE.exeexe 86f4ce0cde8269baefe843dbfa8126978bd2f2e2e0ebd3863f36b2998a991ec8n/a Heodo
2020-09-25bxfhq1QJcac6xCz.exeexe 14444e01436eb1b791ba02b8788a5b199f608abb3dc2a12385b827b344b8937dVirustotal results 27.14% Heodo
2020-09-25s971eV8Ru.exeexe 837fcace6b82ffee25205fe98fc24cc8cb7409b4cbf08a506cc71dbaec7c4ec9Virustotal results 25.35% Heodo
2020-09-25PBTPZF9VfBX.exeexe dbdd620151be1bd6b5bf389d341e36fa0a539bc63781b56f380046cf9fadef58n/a Heodo
2020-09-25inStC.exeexe efb1089e4893c9b982647bb4a9afbe4a496058c88b32680ea1d7604bbd43173fn/a Heodo
2020-09-25HUDxOfv0vvrj9.exeexe c2fb6f99f62c99f7ee39233f8f1e4cc2858751b2f4a3bda5c928fa9a5f89e693n/a Heodo
2020-09-25MU1mI00j3HcQ6PPHHw.exeexe 8b4d43f22644d16c036cafff29942eff8859b14a27f42dc8b3bf56312a0c5f33n/a Heodo
2020-09-25W.exeexe 2b86d2880d38d46590480dd37c21ac44a803a56943fdf762f1c44b6747272bb7n/a Heodo
2020-09-25pD.exeexe c27e8d6882ae462afbd005cbf18ba96ab9328e4a8f52a0eb6c30a456a28a0edcVirustotal results 23.94% Heodo
2020-09-2509v.exeexe 2d0a6fb0b2c1093920d9491c38d6bf81541490b22e50670c4bd056654eb6accbVirustotal results 23.94% Heodo
2020-09-25wdiWwFJ.exeexe 06647e0f810e4ac1208ab1e2c4437b10d382b4a5890379f57f43ecbc79c63ee5n/a Heodo
2020-09-25TTK4FK4uK7fzf59t.exeexe 3c88e6f06ce18b040dcb0d95960756f8b8ed03d878d76f982136b2b46e1f9c66n/a Heodo
2020-09-254p.exeexe 461daae740b6903a1f50f8e8e29f7a4a004312bb398bd373b513392faa28cb6bn/a Heodo
2020-09-25KQWPdcU1TayNBysHx4.exeexe 9e45c1af4b1bd154eec6861b99d2367cfb37672f2f62d4889424de77a69b550an/a Heodo
2020-09-25ktNQp92Ne4T.exeexe 79fc6d8294c4c853e6e2c63493fd3d6acb6fe0b986a989e5135b2f6efa8c220aVirustotal results 19.72% Heodo
2020-09-25nLJ.exeexe 1519af5d599a59b577524a13dc08188d2851f010e901d11ddc6dd7634a72b603n/a Heodo
2020-09-25CWiLoJGz.exeexe 322df1f249b0ad374477445c9141a7b60f1ce3b33f9207480d1c23b80a598cd4n/a Heodo
2020-09-25E.exeexe 111c0702989e324f23973adb20da3ab5b5478eb5bbbb0c4e856edef992941484n/a Heodo
2020-09-25DWFyEmkwEZlFIzngss.exeexe 9ccca60f615ee8e906451c182294c4bab2213b60a306d4d5b378e5f0dfd43b60n/a Heodo
2020-09-25BjzPt3m.exeexe 5a851f1383943eb577054cfc9026d225326fec513dad8a816ea78a3565f76292n/a Heodo
2020-09-25vsJlchmMzHJM1Pc.exeexe 0eec5f0ea99b0de68ffeaa2eff723d3adc4d4e084a44849134ea2ebf5bab8850n/a Heodo
2020-09-25WF.exeexe c01b3c638d8b6838b4c33f56b7229bed791abf63d8d2145cf00a3c082bbbc1f3n/a Heodo
2020-09-25C5oOFheFb1KeEUDfZZ.exeexe d2b7c4563558b2e46d6e796040bb8643be673012ece459967a3dabebb95b58dfn/a Heodo
2020-09-25Dovy2p54FrvyWCVN.exeexe 6d47e78bb37760ae9748357066f8e896880125ff9d515c529ec56a506a790c0en/a Heodo
2020-09-25vl.exeexe 23745136817b29ad122e8abb7b39f33459abd0a64dd5ab15c219988806e3e3ban/a Heodo
2020-09-2589jmuqxgccQ.exeexe 8a9bf74159366e2d9fcabdb95600ba508d2bdee5006fa66a341ab840b0943430n/a Heodo
2020-09-25Ck7lcGHifa.exeexe af705775fe7469221ad82680b5c784b68ca34f203229fc900859753dd13577f2n/a Heodo
2020-09-24a23ZyYjq52a3.exeexe d58a1739f728774ee89a5d10ff21fe88297bd8b401fbe4e6b11e652a7a9477b5n/a Heodo
2020-09-24I3a82c1FNuLBsiv.exeexe 3852073bfcd23b6b08c84e6260c5aaecc0ee67f8fbd37841d223e90b1b4cd9d7n/a Heodo
2020-09-24BVtngwnPcd.exeexe 72d5987213b22cf3a3397bf561efea098cffe7ee61049a37a4034273e5a44e66n/a Heodo
2020-09-24CgQMQWKU.exeexe 8dfa26222428090054d244044efd02f23b972e6a7a34851fc2aa9172990fee2en/a Heodo
2020-09-24b2ufn2X0wg0LfdtLYgzy.exeexe 06b23d51a08a18e8965377917a81c1a9f659a07804444c1cea269582caf191bbn/a Heodo
2020-09-241HpmEn.exeexe e2763865bb51495cfe5ba24dc552afb213453254eb7fd365577d71df72b3d4edn/a Heodo
2020-09-24GOP55BRymSFe.exeexe 852a140fd96b4ddb0d942b4b916f122abb43f64e990934c0df3e4f6426ad7c91n/a Heodo
2020-09-24FCOGsxkd.exeexe 7c15a1936bd87c8cc343464f27a51cbe0aca972212410f06cde47b593610fd80n/a Heodo
2020-09-24aM1rtXO0pdlCXToWC.exeexe 089564cad98c58e2d8b2eeccad800638e99f7572017f1699e4588d228e482376n/a Heodo
2020-09-24ZpuFNGTHpTbgNYNtKNZK.exeexe 87205469c8703ae02a66b479e4ae001205b122d701004ae2aafedd8587796badn/a Heodo