URLhaus Database

You are currently viewing the URLhaus database entry for http://vnitservice.com/wp-content/themes/it-solutions/ka-wqmc-8148/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417627
URL: http://vnitservice.com/wp-content/themes/it-solutions/ka-wqmc-8148/
URL Status:Offline
Host: vnitservice.com
Date added:2020-07-22 02:07:08 UTC
Last online:2020-09-20 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-22 02:08:08 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 months, 0 days, 6 hours, 2 minutes Bad (down since 2020-09-20 08:10:25 UTC)
Tags:doc emotet link epoch3 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-23invoice TV9451_286335618.docdoc 7b25bdeb4bdd1095c4328d3726aaffb2b6b32fb4c28539786017e3d4f1016f52Virustotal results 40.98%Heodo
2020-07-23Invoice_PBU7_062070921.docdoc 063f625ee5274a7caa1637adec2235e98aeaab2f5f8b14877835b82136892654n/a 
2020-07-22Invoice R4827_0047433.docdoc 7e10a0e92fcdcd90d995ee6b0b0059e7a879145f512a34f8f80deb336c83fbcdVirustotal results 39.66% 
2020-07-22invoice-3331_518632883.docdoc 2dd5a90bf7f556f0c8a9a024f6ac592b4c6654f59b7d663c5b313e77757702efVirustotal results 39.34% Heodo
2020-07-22INVOICE-HCA8649_466172.docdoc 9906a5bee4b9e562812454fe546581f17dcea82db95ce7b846c50d1537cb8316Virustotal results 37.70%Heodo
2020-07-22invoice BKR475_614485012.docdoc bfd7374a797a6c3e77d704c3ec20c246e532ab967cb7cec9f3f77f386bdd7455Virustotal results 38.71% 
2020-07-22invoice-1107_637087423.docdoc 1038e244b3cda47068c4265401d36e8f73b0302a098dfebb6ddf4316a1e88f95Virustotal results 37.70% 
2020-07-22Invoice-SEDK4131_5046093.docdoc 16c6a9dd4a72829040a232b03b8dec183f1b62ba3a8fa829760e83ce534755aaVirustotal results 39.34%Heodo
2020-07-22Inv-F0078_71435451.docdoc a673367d1b59b0dc8e2baadcc7b82bab3cd5366208e024034a3f982be198b3a3Virustotal results 46.67% Heodo
2020-07-22Invoice-M4_52720828.docdoc ac88ce74a14a0b5a78e6bdf86ffa9bd0f2770cd7255210ffed47affc2f220dc7Virustotal results 30.00% 
2020-07-22Inv-YVFB7_744882.docdoc fde7e7c9bff062ca0cc9f328703f09d01dba0100af30e9f1d738bf276614a758Virustotal results 31.15% 
2020-07-22Invoice KG6858_104663.docdoc 02c7fd8ed2ff395eb8c7eb3caca1e0cec299f4db7480e6d19829069ce541bc7dVirustotal results 27.42%ZLoader
2020-07-22INVOICE_DNZI3_34056425.docdoc 6c9f7eb3f83892e735f0beedd952428a90922073dcb4f87543facad68fade4dbVirustotal results 26.67% ZLoader