🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for https://asianwok.co.nz/wp-content/tna8l-ke3-236/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:266565
URL: https://asianwok.co.nz/wp-content/tna8l-ke3-236/
URL Status:Offline
Host: asianwok.co.nz
Date added:2019-12-10 21:58:06 UTC
Last online:2020-01-24 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-10 22:00:04 UTC to abuse{at}a2hosting[dot]com)
Takedown time:1 month, 14 days, 22 hours, 36 minutes Bad (down since 2020-01-24 20:36:50 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-11Invoice_HV19_60.docdoc b90f01ffc41d2a6bfb636c583f51b0431cc8586905e93cd1763f2ba42836604bVirustotal results 40.68% 
2019-12-11Inv X093_22.docdoc 83f7ce484abc3af048f630f0895d6389cca58b37dc011aba6adeb24492a09064Virustotal results 36.07% 
2019-12-11invoice-WE370_1763.docdoc ef38bfb8cd3a1bb99df164b2613694fbdfab9419ef2b491dbf75e38b840a8d0aVirustotal results 36.07% Heodo
2019-12-11INVOICE-UEV25_56908.docdoc 382425cdebb2e8dc116b493ef9fd458861de6ff82c9cc87b1300806258050193Virustotal results 41.67% Heodo
2019-12-11Invoice_B762_3801.docdoc fd19a4fca8e4b745cd9ff1d4d71151792218569c027632793dc9bab396294b09Virustotal results 40.98% 
2019-12-11Inv_LM82_60701.docdoc acaca87404d323e919e910f2ad0c6ca398a0cd789ffc327973d8fef90b238ca3Virustotal results 36.07% 
2019-12-11invoice-V446_630.docdoc e1f315e16cea5360492223af2d3b47da3f3b3d250882552371d5578b0f319ba0Virustotal results 29.03% Heodo
2019-12-11Inv_PMQ431_91.docdoc 5b768f2eb1cff9eefcf29280f46237f0bc583be0b55327e1be41b0192c21fcf1n/a Heodo
2019-12-11Inv_BX533_52.docdoc 04be7eba40d5714971a07b09474dc59ce7492539bd1d0ddcfa4a40023980340cVirustotal results 27.87% Heodo
2019-12-11Inv_W93_3168.docdoc 9483705e55d6da05244fdc7d18120f246c8021f0c62ca7a9a83285ed7a7adebdVirustotal results 29.31% 
2019-12-11Inv RSB392_41.docdoc 4ee0bf78e3b0a06c35fed0f912db6fabbb5fae13f838cd4132634359ad0d24daVirustotal results 39.34% 
2019-12-11Invoice-YVB871_812.docdoc 60dc37d24be40eb6877afb78510b380c3951e419311b10c45c1e296d520ee7c6Virustotal results 36.07% 
2019-12-11Inv-ID07_4829.docdoc a60c7102286fc773ec8ada02318ac04bc6b9e5c4d835d4465fee783df6afe81bn/a Heodo
2019-12-11Inv VP484_298.docdoc e418066e29b56b817f639c08108a7e87860ba30e896203a7cf96a68a512c64c0n/a Heodo
2019-12-10Inv DC450_45.docdoc 950da37e5fbc9901ae5c4fb56a0486b6968893313eecc0a01ed002debeec5b8fn/a Heodo
2019-12-10invoice-XOD20_2393.docdoc 678910fc7e2f8301dc3f2494cf9cc0c6182af7861bea2238b8c7ab23b9648b2fVirustotal results 29.03% 
2019-12-10invoice-JI750_21.docdoc 1839b80fbdd99cacda376650c356f64a1bde0d2f38e5457f1752099ab401816cn/a Heodo