URLhaus Database

You are currently viewing the URLhaus database entry for http://www.kev.si/wp-content/brisi/NdgSzNk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:293017
URL: http://www.kev.si/wp-content/brisi/NdgSzNk/
URL Status:Offline
Host: www.kev.si
Date added:2020-01-20 22:43:06 UTC
Last online:2020-01-22 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-20 22:44:03 UTC to abuse{at}siol[dot]net)
Takedown time:1 day, 7 hours, 39 minutes Poor (down since 2020-01-22 06:23:27 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-22Inv-BMB1_3989608.docdoc e3c19433848a0b0023963e05496e09744003119af344985daad6a614cebfb1b4Virustotal results 21.31% 
2020-01-21Invoice-CTXM26_593238.docdoc 5fc5b0f1165fd1d3c8d8143b5ba08e4ab2b38f7a7d2d4e68bb454d0f14272414Virustotal results 21.67% Heodo
2020-01-21INVOICE_OJYX9_140465158.docdoc 6e45a9ae91897bec6b4aaf8f30420016e4f6875e176f032b00102a67f94ed9a1Virustotal results 22.95% Heodo
2020-01-21Inv-PL0_442230.docdoc 515e0e1a9e7994eab3ad00067f1549639c284e0225db703ce58dae8d605f075cVirustotal results 21.31% 
2020-01-21Invoice-XVF407_763651.docdoc 7501ac37ca9adce1a6c87e4cc6db66d985a25c0a47eab1ebb098d308f8b1a96fVirustotal results 22.95% Heodo
2020-01-21Inv_TN439_12217532.docdoc 0169a03187023faa9f8036938797b135cd4b0f17a7d25563f3774917831350baVirustotal results 24.44% Heodo
2020-01-21invoice GV01_0276137.docdoc 91e0d42ba8778c7ad4683f16d759d11e62f7725cce00cca40536e24ce07a4c32n/a Heodo
2020-01-21Invoice FBBC316_669717.docdoc 7c138128d8dcfcef1f383d815bb70b4c4e33f6a88ca5996fff2f67bde4f4b26fVirustotal results 22.58% Heodo
2020-01-21invoice KWJC62_459360315.docdoc 12d1c9a5a6319d649686cf8a271a5f5987092a9716476a009a8084f28c0961ecVirustotal results 21.31% Heodo
2020-01-21Inv WSQX7_892629.docdoc b2bcec6fdfedf345d48f9ebbd3662ecf2e63e9a6f6d3fd1ca81e7c45655cac90Virustotal results 21.31% Heodo
2020-01-21invoice_U7_98867847.docdoc 3d54a3649da061513fa3169fbc132afe22f3c0534d8eb483c38a9abf1f4bae66Virustotal results 23.73% Heodo
2020-01-21INVOICE-LWXN0972_22637344.docdoc b771bd8355401ea565dec0a76276f979eaca401e72db5ed2c3e8abcf8edf2d20Virustotal results 24.59% 
2020-01-21INVOICE_D8_443397228.docdoc 5e4d7fe7b015da8212c2430900e6a4cd61d246c9785f6e85f5acc72d04432cc4Virustotal results 25.00% Heodo
2020-01-21Inv-OKX9590_361215167.docdoc e09637eddfc2bfc14bc5b1c30b82abf32499e5dc406882a5a825ecb223492e86Virustotal results 28.33% 
2020-01-21invoice_3_892275.docdoc 8b65f77f5f67b7866d9a75e082d5f78a46eb64b702afb8baf95299bb476172c7Virustotal results 25.42% Heodo
2020-01-21invoice IQU5_680777.docdoc c4006de4be2a4e83778973add496e8901ef1b90ad3540b3351008a162591dbb0Virustotal results 24.59% 
2020-01-21INVOICE TWH87_31418279.docdoc c9b288f025cd8dd448fc3b9a7315b5f54fd97d274d7c3716334e92b10c22bad9Virustotal results 33.33% 
2020-01-21invoice-HK2078_178404.docdoc d89b5faa54e9999869983e93fe08744d8a65678bfd072bbbc6d5a90ea3ec64e6Virustotal results 34.43% Heodo
2020-01-20INVOICE_SE5_63523687.docdoc b95b56910014068f64d86ee139f0c66209a1ee735ca07f47be55be41b7440ca1Virustotal results 27.12% Heodo
2020-01-20invoice-TOK68_6962407.docdoc 24d9d09777124f7ca0551515a3923075a9f8cfc47db2d697e82cac08531b2379Virustotal results 32.79% Heodo