URLhaus Database

You are currently viewing the URLhaus database entry for https://govn.com.tw/wp-admin/css/colors/k52bgt-zl-52515/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:416046
URL: https://govn.com.tw/wp-admin/css/colors/k52bgt-zl-52515/
URL Status:Offline
Host: govn.com.tw
Date added:2020-07-21 14:29:04 UTC
Last online:2020-07-21 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-07-21 14:30:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:4 hours, 10 minutes Good (down since 2020-07-21 18:40:08 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21Invoice_EC53_804116.docdoc fbe574d0ec900ab75186ccf3c428c88e23c8fbcab1f479239fc690e327a127c5Virustotal results 29.03% Heodo
2020-07-21INVOICE_BOWF5319_3613923.docdoc bdf6b8a3ab43c2e8091f591a913040c789e38a80e2f57d9dde2c5f0cdd9d7fe6n/a Heodo
2020-07-21INVOICE_O37_452354.docdoc a15083f68d55c92228c997e26d8596bb25b5cf8129f45e98d3c78ded130081f9Virustotal results 27.87% Heodo
2020-07-21Invoice-FD384_10276628.docdoc be14def968a7a7ba9caaac07b0784bf90fcc93c6917657fa2aae18ebc3813563Virustotal results 28.33%Heodo
2020-07-21Inv-8_66268120.docdoc 1e574fc4ba69742cc714c4f704166cb427d2bb27aa53005da2f65b9bdc73769an/aHeodo
2020-07-21Invoice 3771_059499.docdoc 029bef505d5de699740a1814cba0b6abb685f46d053dea79fd95ba6769e40a6fVirustotal results 27.87% Heodo
2020-07-21Invoice_RU8_9579908.docdoc 37b40dfa5b0802e246f8fc7b2454db8cb46ad31ed36c4f7fb154a71aa200279eVirustotal results 28.81% Heodo
2020-07-21invoice-W8650_78039551.docdoc 2a76ed46e142b56dacc929cf3fabf2287c2023d0e06e9f5842b23102f584c373Virustotal results 25.81%Heodo
2020-07-21invoice_XM8294_8296594.docdoc 59dd7c2d9c2fad7c4cbc87c1818ab2684f7e977d40f4898d2c9e93a443fc39cfVirustotal results 26.67% Heodo
2020-07-21Invoice-033_58039796.docdoc c83c07e01cf52fa87275f561514ca3379a168698dfda6b53d5a0854c4ef01d21Virustotal results 27.87% Heodo
2020-07-21Inv IMH922_218461.docdoc a6676abd7576b5182d997fc919b7a7d2d42d6ae8c7e7ae41b804df93d6b49e48n/a 
2020-07-21Inv_QH0_2756390.docdoc 4504a75a3b9c58a27fae7939e1fa1ddff84f70af61cdcbd3614a693d236eb599Virustotal results 25.86%