URLhaus Database

You are currently viewing the URLhaus database entry for http://kowil.com.vn/wp-admin/Intuit_US_CA/info/Redebit_Transactions/Notice/lDiGI-OB41P_d-n3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:157343
URL: http://kowil.com.vn/wp-admin/Intuit_US_CA/info/Redebit_Transactions/Notice/lDiGI-OB41P_d-n3/
URL Status:Offline
Host: kowil.com.vn
Date added:2019-03-12 14:25:09 UTC
Last online:2019-03-12 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-03-12 14:26:02 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:3 hours, 2 minutes Good (down since 2019-03-12 17:28:43 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-12RDBFORM.docdoc b6c0a75b1280dd885a3c20db39f80ca390e6fd9937e648216f5050528b50a2a4Virustotal results 22.22% Heodo
2019-03-12TRANS_REDEBIT.docdoc c96e3523ba164f2d9b869ee7162739a8e622e07cd9455f12204626fb9dee3200n/a Heodo
2019-03-12RDBFORM#######26628.docdoc e3af5d9186e98f7e7fcfceb13d38a4f37fe799a0203dee369e1c08ccc66be979Virustotal results 28.81% Heodo
2019-03-12RDB_TRANS####9373.docdoc 1984d5b6c602cdd9f38ebbad7ad96441073a343de12adc8460effe6ccdf2a553n/a Heodo
2019-03-12REDEBIT####91904.docdoc bd15e559ccec4276d36e746c8a05b64318c5736853ea3c58da1618da7ab82d18Virustotal results 27.12% Heodo
2019-03-12INSTR****6881.docdoc d1e304110d0dfdd0ede2d7c88591b86aa2606b3d12a57bc1bd44874d7747b459Virustotal results 27.12% Heodo
2019-03-12TRANS_REDEBIT########7002.docdoc 55d1f4109d124397b061da807dca77739d0006eabd6dfad3093ff73cbff617afn/a Heodo