URLhaus Database

You are currently viewing the URLhaus database entry for https://bilhen.co.za/admin/dlEUE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:759817
URL: https://bilhen.co.za/admin/dlEUE/
URL Status:Offline
Host: bilhen.co.za
Date added:2020-10-28 07:14:05 UTC
Last online:2020-11-28 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 07:16:02 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 1 days, 0 hours, 58 minutes Bad (down since 2020-11-28 08:14:34 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30mes_QNZ011UQ.docdoc f4983c5881da987bb4dcca9069e0134657dbd559cf50165c0f35c3f1c4595948Virustotal results 40.62%Heodo
2020-10-30DAT_15052716.docdoc d4acc3a64623dfa14067c44c95b64430f606feb0c118b278da5747c1b0e52da0Virustotal results 41.27%Heodo
2020-10-30Arc_XSI_100120_LRO_103020.docdoc 3619ca27723e87006b7061bd608e1e02d5087392ec513cfe82ecec069074fbd7Virustotal results 41.27%Heodo
2020-10-30Untitled_LX94K02S2D9.docdoc f16118ebe3dbd05212ed3e350e3d509e02c403cacf34497532c50e1be09b7e16n/aHeodo
2020-10-30M_7W5V74WQ1BHC.docdoc 78896f92d061592d98c06fc87245d2cf4074475faf24d2470912e785760c29b3Virustotal results 42.86%Heodo
2020-10-30Mes_79579734865.docdoc 7bfa1640c072951be3fb17704054b151541525eaa8a22606d94fc2d037a6a663Virustotal results 32.26%Heodo
2020-10-30Inf_68236775.docdoc 8cb962ad1798941eefe7a5f826ea5bebc726304af0337e53e6e34d59a7715795n/aHeodo
2020-10-30list_JA9274720746ZZ.docdoc d77f9d8ce192df999a4c7c9564c086962623dc1a6e020f14bf19f264f59d316fVirustotal results 38.71%Heodo
2020-10-30EW_BJ2994849238DA.docdoc b2312b8854268bd1ca23427d7f7aaf8b3013aa1c4ef1d7676e73a5667418b9e3n/aHeodo
2020-10-30BFWA_RM0873254245ED.docdoc b8e37cb47da5ecf96e85afba207c615504c6e0d63335b4d2b9304fda9543eeafVirustotal results 34.92%Heodo
2020-10-30doc_HOD_100120_VHS_103020.docdoc b2f80aa2efc9abdf137f78f830f2366b29e5bba74409138f8db1ed6163e25819Virustotal results 37.50%Heodo
2020-10-30MES_PO_10302020EX.docdoc fc80fc159e39cdd815b9470202534387227e2a22a7ecb333efc5628c4a0f76f2Virustotal results 34.38%Heodo
2020-10-30REP_32949101502195558.docdoc 3d43dc0ac879aea91410f4bd0218c5990f32b7d729897664df7e58a78ac5836bn/aHeodo
2020-10-30SA_67845382.docdoc b33622a59cee3ca443a74701f86f58ee524e9901c05d359270575f52d7d37380Virustotal results 28.33%Heodo
2020-10-30List_PO_10302020EX.docdoc 87582434c0b62f10bd24d5f8fe2636dcef3e0046373b8e05dadb27942be901f0Virustotal results 31.25%Heodo
2020-10-30Dat_PO_10302020EX.docdoc b3f4e1b87633e71363d9e97c4f845e09d36e833b8d170f184946c8764cfc8f12Virustotal results 30.16%Heodo
2020-10-30FILE_HFR_100120_QEE_103020.docdoc 8f0e22d23596c232df3d527d5fb36ca404eb518bbe7c375b7a7cd037354b02d5Virustotal results 28.12%Heodo
2020-10-29Untitled_696460788265148997.docdoc fdd08f8a983b5fc70a146d936dc6ef6d53ae736a3eed003bf193343704e5ad47Virustotal results 34.38%Heodo
2020-10-29file_27MVBYX.docdoc 18456f3c952a94d93064ab5e0fc948f5cf8c35d1615d18886c7ef84d7dc22a2aVirustotal results 34.38%Heodo
2020-10-29WOIZIOFT.docdoc 0b74633d036ac8233bded3d64b518761e82b826a5fc4ed0e71485fd5d8560f25n/aHeodo
2020-10-29doc_9BXLVL8L6YRQFSH.docdoc 6f9552836a90ddea2d599b100ecf6a8cda08714d1f8f7f848cf6684ab9ff6b78n/a Heodo
2020-10-29dat_PO_10292020EX.docdoc 5f1e824d934b11f7e7a92d426e5083d30f51fee6471908f3a6c0a065d46d752bVirustotal results 30.16%Heodo
2020-10-29J_JUT_100120_UFY_102920.docdoc 060a5c65a7cc6ecfa1290f84d608e94a147a447e1dd75ceedd3490ab079b6e74Virustotal results 31.25%Heodo
2020-10-29REP_PO_10292020EX.docdoc 8767bc3debff2695a4cb7dbd39f82b3c021888d7e244ffdc79af9883ce6f3449Virustotal results 31.25%Heodo
2020-10-29doc_94879728.docdoc c864f510cfcaca5ca5acb2a8ef66706e173195d47f0bc0956f1757e9f74325d1Virustotal results 31.25%Heodo
2020-10-29ARC_51195367.docdoc c9c1857a6ae5a7ee50f6b0df9af96ab1f60e60df0bcc86caf0c561838b4eb20bVirustotal results 31.25%Heodo
2020-10-2950822024342920265165.docdoc 1cfbaf38e833a8dcab12a6f7a0c42e5b5033bc4f188f022607c0e3853f92a6eeVirustotal results 31.75%Heodo
2020-10-29Rep_66832083.docdoc 44fd0e531f131ec3393dcbb90c1ac8baee6d5c4438afa02d458e67436af9a1b9Virustotal results 28.12%Heodo
2020-10-29Arc_JN2850848856DD.docdoc c0ed3a0650c71fa45b196ae3af361c4b91d38f00db69b912eaf14f2aeb543affVirustotal results 26.56%Heodo
2020-10-29XS5851823077EF.docdoc bcc7aff4bedea7ed486112d49796a83b2454c034e2aaf534028b904e76c816cfn/aHeodo
2020-10-29Rep_ZNNM8P6SY7.docdoc 75df04fe2bbfe95af6c2ff3ad6beb372645597b0350f6cc16f995a09e27da829Virustotal results 26.98%Heodo
2020-10-29arc_0266791377048.docdoc a8fcf49df55c689c0773566f845a024a59c623ca54feadcee56f76ee362ddb53Virustotal results 26.79%Heodo
2020-10-29file_3983811574.docdoc 4d79f7b9c974fdf5e44ca20f71261e3064ea8bae3f64370f06b74c2bce894b67Virustotal results 28.12%Heodo
2020-10-29arc_86835523.docdoc 5ed767510e9b2630ac3c6ea38470821c0c85acaf712cb5f45eddd5f6e0fcdc17Virustotal results 26.98%Heodo
2020-10-29File_PO_10292020EX.docdoc dd1f36356c3a35bd4fa5c58dbc9798b01714e04d123539649c3932a8164288b8Virustotal results 26.98%Heodo
2020-10-29inf_09960228293.docdoc 6b1f7e5a0f6190b5197e49dc08a98a69963e68443f96780368895b0bffb30cb0Virustotal results 26.98%Heodo
2020-10-29arc_PO_10292020EX.docdoc e134359bfa4a04bffabf20a6522d2a4c8d807619578853ba0387aa395b6495c9Virustotal results 26.23%Heodo
2020-10-29mes_H8WK4ZN0N1.docdoc d7edab7749baa696b995be184437050a249c40992deb7cbd3472cf93fd8a154fn/aHeodo
2020-10-29Attachment_QUO_100120_FUR_102920.docdoc 12c570f649005ea1ae77c36167843e3e87252075b68b652c5f05b0d8e54b2ad0Virustotal results 20.31%Heodo
2020-10-29dat_ZP3RLEKMZQ.docdoc 8e33cf2204f19a828e1018b6ab9c762d52deb1ecd43a920491561fefd654086fVirustotal results 20.31%Heodo
2020-10-29INF_48722730.docdoc cd49f6f6b2b1cbf28331a1eff67e7179731f34a790a1bb69c89b65ffcfc38e01Virustotal results 20.31%Heodo
2020-10-29Inf_885427867.docdoc 35855c53e4677ef830f4c2a2ca571f759e82982ec0314fc0640953857938f216Virustotal results 20.31%Heodo
2020-10-29mes_HYL_100120_CBX_102920.docdoc a372ab149bf1539aadb69ea0484133adaea91b0c000a9bfdafa445dc23230d3dVirustotal results 20.31%Heodo
2020-10-29Inf_WYBZ8PN6C0.docdoc 4105e48c905f55328aa0a89a608c302216a2d4b119573ef85d1e9902d0531119n/aHeodo
2020-10-29arc_RR3958513188MA.docdoc 585ab6cc0502c04dedbca9318f5d7d278050dcfbeb477a09e8fee5b66916e38fVirustotal results 42.86%Heodo
2020-10-29DOC_SY2781928767ZL.docdoc ffa31d45d93161ab298442d4f9d83cf8b0bcead9e50e92a048b6b0900415b59cVirustotal results 41.27%Heodo
2020-10-29REP_PO_10292020EX.docdoc dd50631890eedb25005e6c54404ae0debc8cc80a8fd10b6e71c9251bf760c9a3Virustotal results 41.94%Heodo
2020-10-29List_AUS_100120_WZJ_102920.docdoc 4d660fe18f8a7a46884d491d3bc3632eb0d0de321fe085339324e55175c33ff9Virustotal results 41.94%Heodo
2020-10-29Attachment_PO_10292020EX.docdoc 42a5e4e595594e5e71e067312918e7858011f85588cc04720f4752f883f45b20n/aHeodo
2020-10-29DOC_94979751026502241583203.docdoc 6da55a5f2284d9e01f507160640b2505607f31d11754ba830811661016ff1e20Virustotal results 39.68%Heodo
2020-10-29inf_99669766.docdoc f98cdce14c9b9c64ea8402566c9db1499eb129104bd476c96c503f1a81a858f5Virustotal results 38.71%Heodo
2020-10-29Dat_PO_10292020EX.docdoc 05c77a4eb82d6567c45d34fca723d6397d2bf9eeaabcadc58a402e340657fb15Virustotal results 38.71%Heodo
2020-10-29Dat_9L9RES8CZM8HM.docdoc ae137af1fbae2ee2d0faeba97b97b4b52536f2b6d962c08608fc792f211d3405Virustotal results 38.10%Heodo
2020-10-2944167840.docdoc c848e58e6eda265a519b7b901623769948e5bba84d9d240638af3bb235587028n/aHeodo
2020-10-29LIST_547704736.docdoc 1053508dba9607d8d25a553d3059249c8ff3fc0f143ea47103c1842a20098c2cn/aHeodo
2020-10-29Dat_TSTBAUVFN9Z412G.docdoc 2ce6ab8ee89411f1463ed6831f078e930f121aaa93880728734efa7d25503623n/aHeodo
2020-10-29KN9336934317IB.docdoc f54166916a8e40e0d024df928029c9f35e013fb4b7a39eeb0554e8dc2820dc9cn/aHeodo
2020-10-29VWGJ_135144739698492803704.docdoc 9f2ed62dea3b679b6dfecbb79905a34ef056e81af2e92c4249fe4521711b047fn/aHeodo
2020-10-29mes_CZE_100120_ZFV_102920.docdoc ab7a59b346e75d68ff9a689f85a0d2a96833a3048478fab68af1e8f1bd4d5905Virustotal results 36.51%Heodo
2020-10-28INF_7Y20FMTR948W.docdoc 2a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7Virustotal results 25.81%Heodo
2020-10-28FILE_OGV_100120_EGL_102920.docdoc ff451db73672e713a3b5a30084d42b5d09a39ca3651cbb1b3c15ce4b18234592n/aHeodo
2020-10-28Arc_PO_10282020EX.docdoc 8adec8b07c6dffa1c8019b0076e0ae870dbfa2a40941b64f4bdb96adff5e0b30Virustotal results 26.23%Heodo
2020-10-28Rep_DAE_100120_OFO_102820.docdoc eb056d51f99a6aeefbd8db271b24784e988b456f939812f40b9b6108a4805941Virustotal results 22.58%Heodo
2020-10-28Untitled_ZH6157938894SI.docdoc ad10b386d964b6056e529c2bdb70ccb19ba21b3b0a59ac606113fedc49626b81Virustotal results 22.58%Heodo
2020-10-28Arc_470A35W6XE.docdoc aa5e7414db596bbbac651408e85b19557a2415a2e42a4a2689cf37c1f3dc1c10n/aHeodo
2020-10-28dat_56420528.docdoc eae43aeb02650178d0fd02ed1c824f36d89c2a2950399621c4a7c29ecb8d7e73Virustotal results 19.05%Heodo
2020-10-28Attachments_OEN_100120_EDF_102820.docdoc 5da940231b1ebc70e4c974d89da825e72365c081f4b224b0308a7298de66a788n/aHeodo
2020-10-28CR5764235157PU.docdoc c0a2014dfca67b622a9a96e4d169601563264a29bb55b9e9b8f1934d610183bcVirustotal results 17.74% Heodo
2020-10-28FILE_PO_10282020EX.docdoc ac9272ebdc022c3e93ef6dff217e30a0434094ccb3b6c5ab79cc97a94cf1825dVirustotal results 17.46%Heodo
2020-10-28Doc_190732330136545656.docdoc b1bc33186fb8cfcd82b5c2472804eb7ef43ae164d2879c71d0c38ddc5f9ecf61Virustotal results 17.46%Heodo
2020-10-28Dat_XP2261316277NK.docdoc 783f27e26d14d3995898c2e135fa9944d4015481789286efd92026c7ef2ffdbfVirustotal results 18.03%Heodo
2020-10-28JQQN_92814244.docdoc 6db32dbb0eafc0f691a50a4632adf82b9e0206663e1b82259542e8eecdfae00aVirustotal results 17.74%Heodo
2020-10-28Untitled_Z8YCW79F1H3.docdoc 972396084dfd074cef1c597e9766918fc0d394d11b8762d20395a86ad5b5883an/aHeodo
2020-10-28File_PO_10282020EX.docdoc de6aea23d0d0c49a68ce1e1762c71c2976fefcbf72b8b2676fec3c065edf9b47n/aHeodo
2020-10-28XDH_100120_ZKT_102820.docdoc 463241e6a0960fd095261611fd7c0192520ec5ef493dac9c695b7c0ab74f43fbn/a Heodo
2020-10-28PM3767121969XU.docdoc 302684a1df1b3b6bcf6995798581972d23b71888983b326ff3eed9bbcaf1c56bVirustotal results 23.81%Heodo
2020-10-28DAT_PO_10282020EX.docdoc 0285b11153063e88e38a1f507f0bc7da9d0cd443a93a28f5d029fb201910f212n/aHeodo
2020-10-28Mes_PO_10282020EX.docdoc 9423019c9d0c788f9b0f3542a6df53db5b54620754419ca1c69895b15b6c73c2Virustotal results 19.05%Heodo
2020-10-28inf_PO_10282020EX.docdoc 53fa42ca6eee828e13b26f79efca50367e1863311520bc82ec6d97b0c7268845Virustotal results 19.35%Heodo
2020-10-28List_UE1320790248BA.docdoc 558c61e9709e06aa045d7ba7933b35b9fb9c125734e3c4e8955a573a31cba52en/aHeodo
2020-10-28FILE_9573677400444053088.docdoc dcbe02f1aa0077b9eb58a4e8a30c9c220fc240162ffcb1bb73376e967d6e7b62n/aHeodo
2020-10-28DOC_PO_10282020EX.docdoc a2a1fb0e34755eda063fd82d7fe452eb979f87b8cf484cd8fa59a45df5adb29dn/aHeodo
2020-10-28LIST_6550951952881409184175.docdoc 3a80f65b200ea7247726fab9a6a422ee11db27f16b629823f536e69e6b534f76n/aHeodo
2020-10-28PO_10282020EX.docdoc d424fcc461427fd257e6bd50b98d81df0efc3254426388661e5ec4d9a4815fe4n/aHeodo
2020-10-28Doc_54132985.docdoc 7c5cba3f361edbd305005728464aa36e44d98db05cc52860a979780b6036fac6n/aHeodo
2020-10-28File_2769944048731163728424.docdoc e225005a6da2c501109a5d73599e7697179f449c42e91f675b4fcb81e49bda29n/aHeodo
2020-10-28arc_610661826444.docdoc c52d8de4c0df2d3039b4e550b081b8386bf713ff22749065c331fd9c03bfa88dn/aHeodo
2020-10-28648062FCONQO8T.docdoc 6a3681628d5e90051c68dd3bf6855abcdff9d8b6e25447bad58745cc5406d4e2Virustotal results 17.46%Heodo
2020-10-28Doc_H2HSADLDJ.docdoc 2871ff5b986f5c582a3468cf2a6210dad8216a164b0affd7c6b11e8ef69761ecVirustotal results 29.51%Heodo
2020-10-28OVG_100120_MKJ_102820.docdoc f8ce9f330d0b10e66d01f784d66c98d45fb6dc902c622d65ab15dbe965cf36bdn/aHeodo
2020-10-28rep_6KE6GWMWBT46N37E.docdoc e84f10ffcf5fd10005895d655f0d56f42e4a2ca26671d6da455d742fd10a76e7n/aHeodo
2020-10-28INF_PI0510990506SG.docdoc b749fa9443216bb372f3a786fe6f921aaf83800f69c46eec065ad8b2bfb0ad89n/aHeodo
2020-10-28628497334203739327017256.docdoc 971349194e2895c67d792f09a40990e6754e2ce4fa00b738c17c34cbb88cc6e2n/aHeodo
2020-10-28file_PO_10282020EX.docdoc 430cbffbdc5d6ef1494df4bf0b8ca22a4e95fcc129261a53ee799778b2ef644dVirustotal results 28.57%Heodo
2020-10-28Untitled_R4ZQPQTMYR7NZ0C.docdoc 2964b5d28a8d65a8477f44ee1cc2b6859302f4e76e07a48217e9d948772ecb36Virustotal results 28.33%Heodo
2020-10-28Mes_AN1247836092BF.docdoc 520ca27ad3a13618d306b397f83a91daf238997358520459895991c6285328e5Virustotal results 29.03%Heodo
2020-10-28Arc_654128210274416.docdoc f10a2b9719d2cd6b88deefff1b2c61c214527041c7097ccd16d96c80c577f58cVirustotal results 28.57%Heodo
2020-10-28FILE_4WWC3LCVO.docdoc 43f4b38dc2240818e174dc1351b7e7237a95f782d2f39578ed29bae1a18cf373Virustotal results 31.48%Heodo
2020-10-28Rep_PO_10282020EX.docdoc b1de6df6c2b5ac15a030ee3b606165a808dd7fb78a4d22a267e304c2edad0fc1Virustotal results 28.57%Heodo
2020-10-28List_FU5699626815TZ.docdoc 089982175b8c27323227a0cbe60942992e1cd89852436e481f6947e75cb25d67n/aHeodo