URLhaus Database

You are currently viewing the URLhaus database entry for http://editorial.wijeya.lk/oldadmin/wp-content/verif.myaccount.resourses.biz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:167287
URL: http://editorial.wijeya.lk/oldadmin/wp-content/verif.myaccount.resourses.biz/
URL Status:Offline
Host: editorial.wijeya.lk
Date added:2019-03-27 18:26:22 UTC
Last online:2019-03-28 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-03-27 19:06:02 UTC to abuse{at}amazonaws[dot]com)
Takedown time:8 hours, 9 minutes Good (down since 2019-03-28 03:15:04 UTC)
Tags:emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-2703_2019_G3_36-03_J721.docdoc 87750caffc8fbe4109d678333a28134bc58096cd9c56e6d3131ac0d39234b9a9Virustotal results 25.42% Heodo
2019-03-27eINVOICE_FILEN3_14-19_C8858.docdoc a5b83356c5af3eb2a1501283ee2b6528d1a66bcf3250db4c9ce135d2c1dbb046Virustotal results 27.12% Heodo
2019-03-27INVOICE_DOC_03_2019_G3_9-25_N112.docdoc 64877c2ca66f4be260d79e854cb9c6c53a3e7ec4fbc5a3d11686a2bbe6801b2aVirustotal results 24.56% Heodo
2019-03-27inv_num-201903_S8_10-68_18935.docdoc 16a1211eaea306077774dfa0429f826433dcc8720e1bf64ead6e95f44c9e436eVirustotal results 24.56% Heodo
2019-03-27eINVOICE_FILE032019_O8_27-96_V8673.docdoc a196ccb4650badd3b67d60f1377e0612d9dd0c4171a758fb96294ab66a4b0349Virustotal results 31.67% Heodo
2019-03-27U2_31-97_Q5547.docdoc 12aefb9788dcb7742691cb65f47fe77eb529d1af66629aa23540923d8bf8a3cfVirustotal results 24.56% Heodo
2019-03-27NEW_INVOICE_K4_26-71_E5726.docdoc 16bb2cc98db47919aad31b64f89faf26fb9eb4e831a334e1132b843659533147Virustotal results 26.67% Heodo
2019-03-27last_invoice-201903_S4_2-42_19194.docdoc d894bd04d5dcfa46856bb122d3c8c4934302a513eb6326733608271b102ed414Virustotal results 24.56% Heodo
2019-03-27OPEN_INVOICE_03_2019_J3_16-07_0304.docdoc 390e1912a2e15d28182d1119e691a015c19badfbac587d9a0ffe2b6ac65e09d5Virustotal results 24.56% Heodo
2019-03-27NEWFILE_Q8_46-90_W256.docdoc ba4a393249fe369eac65cee06624824db2ef81079d4625e251ffbd620299796aVirustotal results 24.56% Heodo
2019-03-27OPEN_INVOICE_N4_7-81_1570.docdoc 885402297b94bde75190d29262083790e59f00e61e30d17b49caced0c16c9e94Virustotal results 25.86% 
2019-03-27INVOICE_DOC_F4_50-97_V677.docdoc bbed2e1a2d1cc935ce62cb37f46d2d875b39c388a5d988265214f8d7af0db999Virustotal results 23.33% Heodo
2019-03-27NEWFILE_Y1_14-70_C6532.docdoc 7282f6fbb637af7bac0005621dd72c6b3e10d673a04a8942d9598e3ed6d02976Virustotal results 25.00% 
2019-03-27invoice_number-201903_T5_9-37_D4659.docdoc 062e43db2b3fe0234038bc344f9c373bcd3b9bbad6aaa9a79063ae6a34678a2an/a Heodo