URLhaus Database

You are currently viewing the URLhaus database entry for http://desevens.desevens.com.ng/wp-content/kWv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:293107
URL: http://desevens.desevens.com.ng/wp-content/kWv/
URL Status:Offline
Host: desevens.desevens.com.ng
Date added:2020-01-21 01:08:33 UTC
Last online:2020-01-26 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-21 01:32:04 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:4 days, 23 hours, 8 minutes Bad (down since 2020-01-26 00:40:26 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24invoice_1_92341099.docdoc d4a5dec72600091f43cc79f5efc5b76ed09571f1a906a6fe4400b3ff08341638Virustotal results 25.40%Heodo
2020-01-24invoice_269_153318.docdoc d830dd74d73625f82a36da760445920cea41b3321cba4769dd421d38e5c8b366Virustotal results 26.98% Heodo
2020-01-24Inv-MF767_28321186.docdoc 21ed646e9c73d65b5355a50adb7b3a7b2f6d76b45d4248e2ad2480fd784ee8b5Virustotal results 25.40% Heodo
2020-01-24INVOICE-H682_6778433.docdoc e6227f508ea8149469cf318e6939e1fd1d8b32b728997677e8220d7c4b827ac3Virustotal results 25.40% Heodo
2020-01-24invoice-PJ2_439295.docdoc 829533600afafde7716701f0ea4bc0cb998fbd85124cda950547315d1c512adeVirustotal results 25.40% Heodo
2020-01-24invoice PUT8893_96717591.docdoc 7c181b5800d9b531de9f431cbd6947e93f55ac0e5f6fcad200acf2466f411a8cVirustotal results 49.18% Heodo
2020-01-24Invoice-IM23_481405408.docdoc 3019c5713b1eae96e9080ac03f4c948abb9012ec8937fd082bf6f26c9aabbd98Virustotal results 46.77% Heodo
2020-01-24Inv_V5072_1088303.docdoc 8e96c8617604fd15ab39a4e48e257ad769bfc12440f857da0cb0b21ddcaa86ddVirustotal results 47.46% Heodo
2020-01-24INVOICE-QJ840_150830.docdoc 614057ec99d029b526fc3313b3385293cbb2a480d15596dd0a975d679fd753d9Virustotal results 46.03% Heodo
2020-01-24Invoice-KRW725_70365602.docdoc 5c566546a1462e17becc0023ddfae0f8e4d8b495e4feda5bcc5f7fa52e0ddd0aVirustotal results 45.00% Heodo
2020-01-23INVOICE-VUXF658_329968667.docdoc 4d65aa1d4d4356e59a68839a7e437a4e3d207e6bf481c90baf4ba6de5b9d0ed4Virustotal results 34.92% Heodo
2020-01-23invoice-BO559_53737989.docdoc b404c8cd754884f9552a1c29dd478a57accbdc3f7b2b0ad038db189d6c635040Virustotal results 28.57% Heodo
2020-01-23Invoice_1_78065803.docdoc 76f2ab5b7640f30ff423838998fc1337e13e6ad4d420753f7becf1e06c29768dVirustotal results 34.48% Heodo
2020-01-23Invoice-8188_655091.docdoc 02cfb7e59acad043e26b2a2effef7cef941860dfbb632d603c4a8cacf15c739fVirustotal results 33.33% Heodo
2020-01-23Invoice-UDI231_664961.docdoc 12958a0020162751f99e336844423a03e94d65328cc2bb55a570293e54d2a0c3Virustotal results 32.26% 
2020-01-23Inv-785_107714.docdoc 68e17ea7659b443ae8e50bee4d874db5b873b772ffa3eeb61b5324f2b4c637cfVirustotal results 30.65% Heodo
2020-01-23Inv MFG95_733260.docdoc e41c558156d999fcb01df97b67cc0df4652e2799d05f12f7bf987d9d54e668acVirustotal results 29.69% Heodo
2020-01-23INVOICE-3_809055.docdoc f8a99bfbf6c324f6f76f07ae81630edabaf926a75bc2bc290abeb01d910b9a67Virustotal results 27.42% Heodo
2020-01-23INVOICE_UQMS8_324083389.docdoc 4efe99e760c862d17d3128bc8c9bfe85a4512b981ac9944bd6f3c38d0d02651bVirustotal results 28.57% Heodo
2020-01-23INVOICE_UVFO449_696343320.docdoc d91ee6af9a42e6c4c90bcc0602f6ca687bf444b88a183867d943b365bf8a7db2Virustotal results 33.33% Heodo
2020-01-23Invoice_FXLQ78_1282194.docdoc aa561ec45a890d783fcb412768c706f829bf7648de033cdd190fab9584ed7a40Virustotal results 26.98% Heodo
2020-01-23Invoice-038_017252770.docdoc bcd78fb2ae376c31ea21a7d1b7d110e4dd0a49c9a8261bc5f68816e4d1091bbbVirustotal results 22.22% Heodo
2020-01-23Inv_M7808_7524288.docdoc bdb5f000963cc046a5794deb863fd7698b3420f5ae8d41d6b09a2f13df7b3f47Virustotal results 22.22% Heodo
2020-01-23Inv LWAX1566_922511.docdoc ede0274ada2624e552749f7852dc316f0d689fa6669b78853a60f65e99d1aa93Virustotal results 20.97% Heodo
2020-01-23INVOICE_NQI8437_593510355.docdoc 0f8e10bbdc8728918591e85cccb046c2773c40bac92da35c9474905528e4f22eVirustotal results 20.97% Heodo
2020-01-23Invoice 313_720539.docdoc b4f3c614764ab55febfefc958d4fb70920c4c17380c6d2adf4f77d68878598daVirustotal results 33.33% Heodo
2020-01-23Inv-HU004_31435915.docdoc 38a532b0fe2efb6f1c0e860c4b4590be3fef1f28fb355f0de343fedcea84dc00Virustotal results 34.92% Heodo
2020-01-22Invoice KF7_3074020.docdoc 975aaa0512dbb84a3bab02f13d499e897d4594c9c465f978431021ef836b7dcfVirustotal results 33.33% 
2020-01-22Invoice-LJAA359_528411.docdoc 8011476e9a36ab9f8defcd9fab9979d4a19203eec24376520d244caea880f353Virustotal results 28.12% Heodo
2020-01-22Inv_VOE95_781493210.docdoc 3c1cc64c9babf45acdb186c3dc9689517fefa31918bdd47faf8e17878f2e43e4Virustotal results 28.57% Heodo
2020-01-22INVOICE-371_691075.docdoc 029859049d0e521193d86baf0d209080d9d885e31b9ecab91b2c2484acd58af8Virustotal results 30.16% Heodo
2020-01-22Inv_NVSC836_210149.docdoc 58fe40e165c8619daa7dca1d76a7dc59f79bdccbf16ec14d2ea0ccc20d8d55a3Virustotal results 32.31% Heodo
2020-01-22INVOICE-TUQJ427_60410514.docdoc 3c883920142d8e22088985f3f3594665bd83571bfb755aa1aa5b7354fa7912bfVirustotal results 29.23% Heodo
2020-01-22Inv_MXGM3_828711.docdoc 424176c5eb3fe9eb958ac0e0b9ed8a3fc23ae3b56334f12d4e47f5cedadd49e1Virustotal results 26.98% Heodo
2020-01-22Inv 2_895512.docdoc a92d0f72b0064095dfb9f3c33107f9d2968dacb8267450d79a0e0d265fe23941Virustotal results 30.65% Heodo
2020-01-21Invoice FKBK6651_168075121.docdoc cecb334192ab8a14791e3dc5b826c95f4d92e232b9a4458f5457dadb109b81f0Virustotal results 22.95% Heodo
2020-01-21invoice 621_235722.docdoc 0c9c3b35c2644f8b16e462cde0d72f7d2cd0e33fad833335fd0b76c4882caa57Virustotal results 21.31% 
2020-01-21INVOICE-KRH54_976474285.docdoc b46efc95b770045478b6b58baa2c3131dde93763e8a177d0a4e96cc8ff86571eVirustotal results 26.67% 
2020-01-21Inv WKGG46_43582333.docdoc 82bf92f8f30ec4f7813dce2e62d60dbcfbd53b5e53e5ded8307d4898e41ab0a6Virustotal results 25.42% Heodo
2020-01-21Inv VC5_851925138.docdoc 5e4d7fe7b015da8212c2430900e6a4cd61d246c9785f6e85f5acc72d04432cc4Virustotal results 25.00% Heodo
2020-01-21Inv-DC2_189775.docdoc e09637eddfc2bfc14bc5b1c30b82abf32499e5dc406882a5a825ecb223492e86Virustotal results 28.33% 
2020-01-21Inv-GIQG68_46344705.docdoc c9b288f025cd8dd448fc3b9a7315b5f54fd97d274d7c3716334e92b10c22bad9Virustotal results 33.33%