URLhaus Database

You are currently viewing the URLhaus database entry for http://wdl.usc.edu/wp-includes/zvlp-s69lox-wrkbb.view/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:156155
URL: http://wdl.usc.edu/wp-includes/zvlp-s69lox-wrkbb.view/
URL Status:Offline
Host: wdl.usc.edu
Date added:2019-03-11 17:06:05 UTC
Last online:2019-03-11 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-03-11 17:08:03 UTC to abuse{at}usc[dot]edu)
Takedown time:6 hours, 1 minutes Good (down since 2019-03-11 23:09:36 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-11D920598739564.docdoc 8b1f35703b1fbe2540d9b142114cdbfb9b71de667393c0597e6edc250686f415n/a Heodo
2019-03-11PAY57242045600623089375.docdoc e69742e157bd0b2dc16aec06611d17972f1b733e8caff3f4234057580ac5edden/aHeodo
2019-03-11AUFZ355040338327.docdoc 2be6bcb4d51274424ac7297e1492f5d7f0f2482963e32f32e7cfd3a928e9758cVirustotal results 23.64% Heodo
2019-03-11PAY65094296134391033.docdoc 68636519a36663c39db87c75f080e53c3ea740e96c8f9732ad7df923b23dfe6dVirustotal results 23.21% Heodo
2019-03-11ACC7136717499.docdoc f5e9c63713c7ff968f4958a9b5161e78af05f21493e56555734b89f55b2be24cVirustotal results 24.14% Heodo
2019-03-11US6028766993097717875.docdoc 4d4fa8cf813b85581ac7da303eee226dd0eee86351e0807094e30a9e56d7c517n/a Heodo
2019-03-11INSTR573066604958500.docdoc b700fe84b3a4b2f7309261b7220d5975fc3b820c95ec0eaa3fe28b8697cd5d50n/a Heodo
2019-03-11US03607161981000156.docdoc b907acd6a02543366867e9f8a849178c26c9f4e98d5f76f63bb039e057c4c267Virustotal results 24.14% Heodo
2019-03-11US36590136764068.docdoc 9777f20e030ebb2e211eed375b5ac6360d16896f8b091e23c0556d9eb089c4e9n/a Heodo
2019-03-11INSTR85555227235632372.docdoc 888e712b99d5a19ed417790734d50f7f33ad39ef19207005c9bef1b79e40fec8Virustotal results 22.81% Heodo
2019-03-11PAY96659410025.docdoc 0fa9bed6b20bb49ad59d9ed007c13e46b2bd8341428d97c37607214332e93a6dVirustotal results 23.33% Heodo
2019-03-11WX7040628848990.docdoc df047be4957aebcbbacb29fef0a1498956264be5987608db823053e1c440d6c4Virustotal results 23.64% Heodo
2019-03-11INSTR96122078686222055.docdoc 3ecbe3a35d674894b21a70e091735c8936d9b51468ade48a4e697b2867ee12aeVirustotal results 23.21% Heodo
2019-03-11US41112597147529130638.docdoc 0c01a0c8fe422da038934fe5206c6d9f372828b44ad4d765446fe21c7eb337c5Virustotal results 23.64% Heodo