URLhaus Database

You are currently viewing the URLhaus database entry for http://cheapwebvn.net/wp-admin/zfan-u5m-47/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290039
URL: http://cheapwebvn.net/wp-admin/zfan-u5m-47/
URL Status:Offline
Host: cheapwebvn.net
Date added:2020-01-16 13:44:08 UTC
Last online:2020-04-23 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-16 13:46:05 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:3 months, 7 days, 12 hours, 40 minutes Bad (down since 2020-04-23 02:26:06 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17INVOICE-DLEK9235_400287.docdoc c7019134762489379265c21822035aa7f361e4e4bfa8cde104ef4d1ab39ecebfVirustotal results 35.48% Heodo
2020-01-16Inv-2489_322659815.docdoc 2e1f347233bf11c5e1231fd08171ba3cd797101180810eb5984a728f282af86bVirustotal results 36.07% 
2020-01-16INVOICE-HRNS116_6586227.docdoc a9c149a3e340636d38664f3cfdd5fd4fb95a2fd330c0c1623096b9fff0629a44Virustotal results 28.33% Heodo
2020-01-16Inv_G2456_1307394.docdoc 10a9ecd17e41685a7887e61d9f954dda1fb10b88f63108e0fa658862eb6350ebn/a Heodo
2020-01-16Inv-IFW3_4186491.docdoc a40a39e50828aebfe097dc6367407cd7a46a10cca1743c4b49849c6d4d7f8034Virustotal results 27.42% Heodo
2020-01-16invoice-DE7_511948660.docdoc 44265368bc8d60086d77c23474d91755e5c0dd6c214337554d4865aefb751813Virustotal results 25.81% Heodo