URLhaus Database

You are currently viewing the URLhaus database entry for http://tier-2.desevens.com.ng/wp-content/YIKscDWO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290993
URL: http://tier-2.desevens.com.ng/wp-content/YIKscDWO/
URL Status:Offline
Host: tier-2.desevens.com.ng
Date added:2020-01-17 14:34:14 UTC
Last online:2020-01-21 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-17 14:36:04 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:3 days, 13 hours, 22 minutes Bad (down since 2020-01-21 03:59:01 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18invoice-FJM6_9175514.docdoc 2f90590da13be020cab94f6054224224af5d674bb07964796cbb051cef5dde3aVirustotal results 27.87% Heodo
2020-01-18invoice-Z4889_510390165.docdoc c0ddf7ec4f4905aaafd9371d7d00d8bd21bf9f5d9d49403591e1cfbde36925ebVirustotal results 24.59% Heodo
2020-01-18INVOICE BJRO113_9433557.docdoc e4def16e9897c04029e960d9ba6d20e17757ac6084e0e9ecc6cab31c90669e8dVirustotal results 22.95% Heodo
2020-01-17invoice-FI0_02554971.docdoc f67b61ea433330be6144fce1f21cba4c59d0389ad995cba85b7b5034bad72279n/a Heodo
2020-01-17Invoice-MLM66_982168703.docdoc 040930dcb6516ec19aa7e830246bd05a7df2479b23c3b9e23add649f38469c1dn/a Heodo
2020-01-17invoice-LZFY505_670051255.docdoc 612232f5fbbd7e962ff9a576f1a32be4fe4dc541a1bf7dad094becace6e2443dn/a Heodo
2020-01-17invoice W4373_304464564.docdoc 44a7800af970884939e0d1e420aa3f140610c62a0a1e7d207cc020b9971c6c2aVirustotal results 21.31% 
2020-01-17Inv-GLO94_930979627.docdoc 75da7c2a84d8e27223752a60ebe7fafcc97c8f989ab0a73e6563907e6acce897Virustotal results 21.31% Heodo
2020-01-17invoice DET79_81915368.docdoc 4bccfd69e2d0f9968b1a8471e9d094226f9ca6cad0fb4681943bfe1cf459a706Virustotal results 20.00% Heodo
2020-01-17invoice-HOA53_4099323.docdoc 50682122531706e8b035ce5b24ace8f3b0e7e50526937b524c4523e7da0adcdeVirustotal results 19.67% Heodo
2020-01-17Invoice 729_57465447.docdoc b4b6809e8ad49a3c2b726e5ba3c33fbf94b11f51beea1f5208ce000ac005cf58Virustotal results 21.67% Heodo