URLhaus Database

You are currently viewing the URLhaus database entry for http://lutgerink.com/hhfl-RFkQQOMIaP1BeoV_iboQrfFT-tZw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:97307
URL:http://lutgerink.com/hhfl-RFkQQOMIaP1BeoV_iboQrfFT-tZw/
URL Status:Offline
Host:lutgerink.com
Date added:2018-12-18 19:45:04 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-19 05:47:26 UTC to gerwin{at}office[dot]digitalus[dot]nl)
Takedown time:2 days, 15 hours, 28 minutes Poor
Tags:emotet epoch1 heodo

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2018-12-20BIZ_5ZOAEIJX_12_20_18.docdoc7081e6d6803dfacfa22aa60a2c520f2c2ba11a8d58645e80272dbbf7b2b0a347Virustotal results 16 / 60 (26.67)Heodo
2018-12-20BIZ_1557702JKTUPFH.docdocc829a5adea730a03784788f481d177e25a1a2d4d91cfa3f975a5caa0e1ac4e8eVirustotal results 16 / 60 (26.67)Heodo
2018-12-20ACH_719FBDDENXK.docdoc4d6ce9ce52e4319ff789f540706047cf3653c4279a463def957edd882aaefcbcVirustotal results 16 / 59 (27.12)Heodo
2018-12-20BIZ_1415506NLDCQG.docdoc85e19a6e2b1ab96f920634e5f99ba0a6c6e905ef6b0b655d7e6fd6084ae71fc4Virustotal results 17 / 58 (29.31)Heodo
2018-12-20PAY_209BOHOMEH_12_20_18.docdoc117f73ac9cb118ea3cb15e12828cd1230ed32ca9f5dff32d37329cf3be0e2639Virustotal results 17 / 59 (28.81)Heodo
2018-12-20BIZ_593TDBPWHXE.docdoc7ecdf9b93d2ac88d1eff2c859f7a1051b09d88bdf2e0057c099fba72e962c88fVirustotal results 17 / 58 (29.31)Heodo
2018-12-20SWIFT_670YKBQCG_12_20_18.docdocb7a376c01f14765a00a27fdede2c809e22f754acbebd5e914633cc81ca8b8345n/aHeodo
2018-12-20ACH_388BTDQBXL_12_20_18.docdoce0a32c200e279334cd4303c0ba0a793c949228c9f8258743b552cbbc5d3952ffn/aHeodo
2018-12-20ACH_7347OQSKFW_12_20_18.docdoc539b86e6bbfe0eeea3198709f97c5d82d2a407e52e7a6ab4babd34f32826de42Virustotal results 17 / 58 (29.31)Heodo
2018-12-20SWIFT_7841810XIJYMXH_12_20_18.docdoc697153bc9d678f8be35c9408f215693e0063eb03095c613519ed5fd0aa7c05ddVirustotal results 17 / 59 (28.81)Heodo
2018-12-20ACH_289HIEYXVDW_12_20_18.docdoc6a682417951d814c957bea0e701222a05dd77331dcd4b6481cfd40ac6600075fn/aHeodo
2018-12-20ACH_4761JZNNOUAF_12_20_18.docdocb76e20536a3e5990bb0712a4ad0f113b7443d8025f53f6ad7c4eef42210562feVirustotal results 17 / 58 (29.31)Heodo
2018-12-20PAY_3185078FDVZKYI.docdoc8424d5945b0c3307861490cb14a0410c615b4c2e69c0a388017425611b9f5f10Virustotal results 16 / 59 (27.12)Heodo
2018-12-20ACH_7014038FHLRWNUX.docdoca5a7179b804377829b6bd377ae3752020dd98586c26a71386b11cbf43d3cabb3Virustotal results 16 / 59 (27.12)Heodo
2018-12-20BIZ_2612019ZZXGPQWC.docdoc301c836640b0bd278f52a6ee214f6a982e85d66df3cd424f98b39c6794ab9908Virustotal results 17 / 58 (29.31)Heodo
2018-12-20PAY_4YBIHKXTB.docdoc20efc84a7e968fb0490cb811c202426acd0c78c6481743c7621bd43a6ec277f6Virustotal results 17 / 58 (29.31)Heodo
2018-12-20SWIFT_9HTBMIZMF.docdoc296d7c632807f236935c7fc717fcaa4ed2b36e0417a5235b5b2213d4403dfc2bVirustotal results 16 / 60 (26.67)
2018-12-20PAY_8762GRFMYTMJ_12_20_18.docdocf45796612870147e0d8b7131cda3bced4dcb6f2c97026561778e438f57717d9dVirustotal results 16 / 59 (27.12)Heodo
2018-12-20ACH_96PMLLWMJA.docdoc358002adb1ceb8832cf6c42cbfd40cd309c2f8c32f3d346d44eca2c6076660d1Virustotal results 17 / 60 (28.33)Heodo
2018-12-20ACH_063445GLUMMA.docdocfe3f1c9e4d762e0181289f689dea23083b47575e1fdde2f72b1757180c87aa2dVirustotal results 17 / 59 (28.81)Heodo
2018-12-20SWIFT_28CAQEQEMV_12_20_18.docdoc23914ae7db6072f3cf5b8631b013c92f03405ef271686adbb0b6d27009a62c98Virustotal results 17 / 59 (28.81)Heodo
2018-12-20PAYMENT_9LDLPMOD.docdoc82905846bf2d58fb27723453132458047a90acd8a5dc54e61361dd08f323b62an/aHeodo
2018-12-20PAYMENT_9270383NSADGJIS.docdoc14b85ab78cf79fb43aed01381205b188a35c1ff38358c25ea61dc68ebecd0e13n/aHeodo
2018-12-20ACH_51739GBRAZW.docdocefbaf95e866de9191477e491d4092c3aaeeb66eeb8aace893e9ad7141ba633ccn/a
2018-12-20ACH_995577ZPVZUS_12_19_18.docdoc49a44cd152ae054e86482da2fe6223495a6f6af45455c6cae3e61ab58d7cb8d5n/aHeodo
2018-12-20BIZ_0724749PJSAZYY.docdoc41f19cb3e19d8ff1d5cf5a006ca95877667ef1a36b72cc9debeca54b37053bf0n/aHeodo
2018-12-20SWIFT_1HVRSKYHK_12_19_18.docdoc430ff4d90db9bad4fb0927d47b9de3f6bb08808eb55161e429bb00a27381b97en/aHeodo
2018-12-20SWIFT_946465DHSXFTU_12_19_18.docdocc6a82a19e8de3ec40378c8dcc17f2ba9ca788420cadf783c124893756d80d87cVirustotal results 16 / 59 (27.12)
2018-12-20PAYMENT_1BRPXDF_12_19_18.docdoce25dd88a0cc86f5665834d97385d8042005298cafe5e426ebc82f4fe30cb67e0n/aHeodo
2018-12-20PAYROLL_489869MQUCDRPV.docdoc6e438c6f191ae7692eae099e0f80f0282f258b0afbd606efc7e1c40c60d9f9e9n/aHeodo
2018-12-20PAYROLL_62IQSLGWEW_12_19_18.docdoc7213b10919b2455b67ed5759498e7f177db260994492d1b0157c4305957c42a2n/aHeodo
2018-12-20SWIFT_751UNGMSWSZ_12_19_18.docdoc110832be2faf57b513de8aef11421cdcd180efc1892752300dfa345848308defn/aHeodo
2018-12-20BIZ_159772JEZGLA.docdoc246d97c8562adcbea01d6a6942e361699ce5583297259194da8e03e5a8b73a2dn/a
2018-12-20ACH_82MNICZB_12_19_18.docdoc519cfa25fec32dea23510fb72f4265b8ccfb20a733ba038f3a8e422bdf27f5f6Virustotal results 15 / 57 (26.32)
2018-12-20ACH_78157EETKRVM_12_19_18.docdocd166a1b1581ef798c74414c6e0968d3569cfcb6d4589c3b7f5f053b7d6d0e9e9Virustotal results 15 / 58 (25.86)Heodo
2018-12-19BIZ_698IROOXHAP_12_19_18.docdoc43818efd1722e68ff8437840b1078786b9dc873a39d5f7d26c86f5596d9bc132n/a
2018-12-19BIZ_68OCCWZX.docdoc9e8225e586deb0f8aad14649cd5ffec0c304743df210a5acfb098726f9425a9eVirustotal results 14 / 59 (23.73)Heodo
2018-12-19ACH_028292FTPMTXWP.docdocaf7fbaa891bfbf0323709e49b9bce7b094b089208179f6320c7bc8d55685e3f0Virustotal results 14 / 58 (24.14)Heodo
2018-12-19PAYMENT_8SMCVMON_12_19_18.docdoca2a809f39e442f484a6ab6129a4c2b0c55f2e08bf581f86a361e84899705301dn/aHeodo
2018-12-19PAYMENT_1EQVXDH_12_19_18.docdoce18d59b2fc58b3f43864de07abcf6a72f4ab9c2e2901e79a01fa9f672af6e08bVirustotal results 15 / 60 (25.00)Heodo
2018-12-19PAYROLL_6KHPNLEOV.docdocf09bd77924f7558a2c70efdb4acd4ebd16b33a8636433778c01b6247c2e0d395n/aHeodo
2018-12-19PAY_5531034SIXXCW.docdoc59c5a6ad8827d90b094dc45f8d12a6b6bdad58597daa38c251622555ca851081Virustotal results 14 / 60 (23.33)Heodo
2018-12-19PAYROLL_1040YNGKZV_12_19_18.docdoc80f397c4057064edb5cd2e305c595a9a1d8144a68bc579c2d1438953e6c43210Virustotal results 13 / 57 (22.81)Heodo
2018-12-19SWIFT_642018YOGSRPD.docdocbd5df7e6cb61646a4b3bdadfb4b04427cdc578a3d6c01bcba6782d3a74579550n/aHeodo
2018-12-19PAYROLL_073IPWKMHC.docdoc9dade916742bc7c8a1270f4187e443a983bcc00af2ea0c4ea25cbe3d2b6a89d5n/aHeodo
2018-12-19BIZ_46RDBMWMW_12_19_18.docdoc6e6a2c47aafa8c967018831173e45b3e37d53b6bda1207825757d2e4b9737099n/a
2018-12-19PAYMENT_300TXTIIXP.docdoc7ae2e5a4d52b6d13dffd5de06d9efec26041791cc9c5e96a46a359b716ddda99n/aHeodo
2018-12-19BIZ_0ELKAQGR_12_19_18.docdocff1bf824a5f91dc121624a451101c172e8d7fa135fcef03a8a9a1cb6f23ba3e9Virustotal results 14 / 60 (23.33)Heodo
2018-12-19PAYROLL_2MRMLDU_12_19_18.docdocdc132aed4bddb62413af5b5ea9aeab5564666e384f42fcba0b5f52090a012e97Virustotal results 15 / 58 (25.86)
2018-12-19SWIFT_14TWWRTFZP.docdoc74f99474cbd773796849c10d3f71c7d5ffb3d6670445a086c7a59f368a7ecf7dVirustotal results 14 / 57 (24.56)Heodo
2018-12-19BIZ_89665QIJZDQ_12_19_18.docdoca9dcad525ec70b77afaaf959ce0ffe2b1ae9be291af209dc76f4ed8404642bccVirustotal results 13 / 59 (22.03)Heodo
2018-12-19ACH_9938DOCAXJNL_12_19_18.docdoc667e866ba6c82700e3a56226b862aad3c84892ba017b60226e775d42000f8549Virustotal results 12 / 58 (20.69)Heodo
2018-12-19BIZ_450809IXJSLM_12_19_18.docdocae106183d29ecc79bd1867d0e955bb0842d40ff17cbcd84ab634951cd7e59c41n/aHeodo
2018-12-19BIZ_35HNMGHQQU_12_19_18.docdoc773699408f9e8dccc446105dd63faf83e9264f6730b269852f8be1b10f82a5een/aHeodo
2018-12-19PAYMENT_9370664OPQWBYZZ_12_19_18.docdoc0d0eafb214b52e09ce7a141c7d25bb211fc788fc3b65073c83d77a94ad30dd8dVirustotal results 13 / 61 (21.31)
2018-12-19SWIFT_504975XJOHDSDI_12_19_18.docdoc26ac5141e1f25dc3125bbd126deabd383a72139b96fbb02795ef27ae6beabe84Virustotal results 14 / 59 (23.73)Heodo
2018-12-19ACH_7OCTPBZ_12_19_18.docdoc24b72b319b56976cc7712986af539f06fe63caeca539f181a486d0d1bd195795Virustotal results 14 / 57 (24.56)Heodo
2018-12-19PAYMENT_80NRKXFN_12_19_18.docdoca9d217e23d0a3fc01b857b3df99bcc2053750916ad5d8d819f01f7d361a86648Virustotal results 14 / 59 (23.73)Heodo
2018-12-19PAY_46MXBUNTHH.docdoc794cce0df1a506a886abf16c2776d90717c958ecaf359dd84e0fe8ebb5867979n/a
2018-12-19BIZ_7GLYFSNN_12_19_18.docdoc15b2d8b7c59bb1346961fc2398bb2cf18b5c074fa865952bfbf407b5e56055a5Virustotal results 14 / 59 (23.73)Heodo
2018-12-19PAYMENT_56QDEDOOLX_12_19_18.docdoca24c21b5b32feb6a6ac11275a21d0ab224ee8df7ac286b5aeb2fd53fe9255934Virustotal results 17 / 58 (29.31)Heodo
2018-12-19ACH_80108VBNXFGHV.docdoc32ce9e2aff3d741b6824223ab4df58e540d5358fcb16dba761c8202a02c33e60Virustotal results 16 / 59 (27.12)Heodo
2018-12-19BIZ_39499HPVNSOT.docdoc8d2ad53e74f3df6409c262041a431c7facd90e0a4c29fcae9ef35eea58fbe7c8Virustotal results 15 / 61 (24.59)Heodo
2018-12-19SWIFT_7807916LVNAMF.docdocdc70019c2daa7ade6086921bdda76a6f9fc38793c4685648068bb44b1b3d6d42n/aHeodo
2018-12-19ACH_1209PNAVMAFF_12_19_18.docdoc19396d75f839402f4329b6c3aa4641c6e1cba160f8720661ee9ea2f25e7a2ae3Virustotal results 16 / 59 (27.12)Heodo
2018-12-19BIZ_5TUVTYIO.docdoca3a0d88ed2ace5d01596a99bc20f8f5de1bf9b08681a47dcdca95c7198f20f70Virustotal results 15 / 60 (25.00)Heodo
2018-12-19SWIFT_98YPVTYHUA.docdocbbc301b501a05b85ecdbcfdbe6d199ff9c2754471a2cc8ccf2864866ca6a7fc5Virustotal results 15 / 59 (25.42)Heodo
2018-12-19ACH_42XZWYXUZ.docdoc80cf64323e7461a11e6352f79af8c9343c551ebb4aa081e71e3b58dc6abffbd3Virustotal results 15 / 59 (25.42)Heodo
2018-12-19BIZ_98386PTESZCBR.docdoce4aafbe990a5f1dd3595b1232512dc565af317b39bc607d73c4cadcba734d51fVirustotal results 15 / 59 (25.42)
2018-12-19BIZ_89420ZJYTVBGH.docdoc78628beb4a5bb96d49e21db8222c67456dcafa41ec30ee66b3097aae520313e9Virustotal results 15 / 60 (25.00)Heodo
2018-12-19SWIFT_401929YGHLFZF.docdoc0ddfec71e75e47c35aa4bc386628f8cde14541a059d384bf04a12c8b98713e0cVirustotal results 14 / 59 (23.73)Heodo
2018-12-19PAYMENT_9MYOTCBPF.docdoc2bd6d4277ddf9b1ea0ee8fb0288fbdc0d915a25a6017193b9644d0ffe15548feVirustotal results 13 / 59 (22.03)Heodo
2018-12-19PAYROLL_257ONJBOBV.docdoc7678783514f037f783823dfaa6b5f6d4f627283e955cc5fdbf74b90ec886ff9bVirustotal results 13 / 58 (22.41)Heodo
2018-12-19PAYROLL_39YEAJNOJH_12_19_18.docdoc51f2ca52d34d84c1219905690286bca9769bca5a78b5e9b5019edbf93866d23fVirustotal results 13 / 59 (22.03)Heodo
2018-12-19BIZ_7WDFJTN.docdoc3b061ec7809a80abfbea303c2721224a73a31f5a0823ca5eebc5a24b5fd61d71Virustotal results 16 / 59 (27.12)Heodo
2018-12-19SWIFT_22690VUZHOLMY.docdocc2163d51aa2e33ec573f7a77780064f99edd6622e2b130d29812945526e976b1n/aHeodo
2018-12-19SWIFT_7NRLYKA_12_19_18.docdoc05eb7f0bb617ce84e26192f529e4ceff87ad07f9bdd340f8439c2321bae6ee5aVirustotal results 16 / 59 (27.12)Heodo
2018-12-19PAYMENT_0747XCCVRZC_12_19_18.docdocb3befdd66b4c10721d277f4a6f77e779f85e49cd0d28a5507af96fab31459420Virustotal results 15 / 58 (25.86)Heodo
2018-12-19PAY_70KQUWTLO.docdoc8c0c8a18ed3d80ae5b69579e5c963df5480e3b7e5def991f9e36106fe3ee27bcVirustotal results 15 / 58 (25.86)Heodo
2018-12-19SWIFT_553242PRVTWKN.docdoc0011f100633bd595dd9a21849fb9e6b52fb1594c41c4eceebb8f33da4fb74150Virustotal results 14 / 58 (24.14)Heodo
2018-12-19ACH_80ZZJYBNW.docdoc66285eba00c10b3d32daee7c79c0f6305cf3699e1f48a72b3b692b642e661e15Virustotal results 13 / 58 (22.41)Heodo
2018-12-19BIZ_02136NYAPCZJ_12_19_18.docdocfd86839fce0dbda6ad4972202cad03d546e0920d8c1af13a6baf6ef48700b78eVirustotal results 14 / 58 (24.14)Heodo
2018-12-19SWIFT_768634TIOTDJP_12_19_18.docdoce0f8f0ae3022336f8a3eaeda88ef97297af862b86fef2c91310d55b631915169Virustotal results 13 / 57 (22.81)Heodo
2018-12-19SWIFT_9097318YRTYLIN_12_19_18.docdoc11149d8877f89d9d1bb6545dbbcb4d090b0428146e692d8374aa9780b964242fVirustotal results 14 / 58 (24.14)Heodo
2018-12-19ACH_1SMEXXA_12_19_18.docdoc99d7de1ae23a34061406dcee8be1730f2d93bdcf6aba027d2aa51ba5fef37d53Virustotal results 14 / 58 (24.14)Heodo
2018-12-19PAYMENT_2729782DVCTEZ_12_19_18.docdocdb2fc3ab7e15832a44fa886ff7abc6aea3670cb1f15500d0c111ed92fa6de586Virustotal results 12 / 60 (20.00)Heodo
2018-12-19PAYMENT_222CYDTEHGM.docdocfc311a823a1cfa0f63d289484ff01576fe22084403c6cd7a648cb51626abd10cVirustotal results 18 / 59 (30.51)Heodo