URLhaus Database

You are currently viewing the URLhaus database entry for http://sehahealth.com/wp-content/awto7y-hn-1775/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421561
URL: http://sehahealth.com/wp-content/awto7y-hn-1775/
URL Status:Offline
Host: sehahealth.com
Date added:2020-07-29 17:45:17 UTC
Last online:2020-07-30 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-29 17:46:02 UTC to abuse{at}hetzner[dot]de)
Takedown time:16 hours, 49 minutes Good (down since 2020-07-30 10:35:16 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30INVOICE-SLAM500-350462185.docdoc 8e78935c6ae4c5164c54350ae754eee471aee652bbc37521c1fe2706c62303e3Virustotal results 40.98% Heodo
2020-07-30INVOICE-NMZ305 43207075.docdoc 5217ac4d4844f46408d93f03a543551534ccfe73887beacbaea3ee0c0c2eeecbn/a Heodo
2020-07-30Inv ZYBX93{:REGEX:.docdoc 4fc258e1d97be191b9316641ade4df2be7dc40501cbdb9e2d495abfdad6f8426Virustotal results 40.32% Heodo
2020-07-30invoice VL9-8522357.docdoc c171e3eb929b57d92d6a1a2e4e81a36dc1233be6abf5dce5e51dac677ec50017Virustotal results 40.68% Heodo
2020-07-30Invoice2{:REGEX:.docdoc eff2527b0d1491dcfc46be3cf12fb6a749988c8c869f06e9adadc236474b60adVirustotal results 40.00% Heodo
2020-07-30Inv-MU988_996909911.docdoc 917e50fdd6263927050a585d76924748310f1cb1fb4e7612e7c5a385f0c373d0Virustotal results 41.67% Heodo
2020-07-30Invoice-BFYS1478{:REGEX:.docdoc 84f1793acc6d7c229aed03c0334fcb223eb89415c1d96b08822e988c1a5652afVirustotal results 45.90%Heodo
2020-07-30InvPALM38_6296082.docdoc e66e3c05c9813a7da90cb5090c3b35bd492b557b83580d7f5f7592f0dee64d90n/a Heodo
2020-07-30Inv DN0405{:REGEX:.docdoc fd4e7761b18405677fc5c8737a34ace11283a0c1503a19a20120c9f36af7c004n/a Heodo
2020-07-30INVOICE_RS589-285082.docdoc aa6bbf739a15097060f35839f8bedf662f371e5d1f27dfacd0bd8863b46ab1dbVirustotal results 46.67% Heodo
2020-07-30invoice_KB0209{:REGEX:.docdoc d7f5fca8f5de440dff815ea87b1b67a6d1a22028f8b39363240ebdb3cc43479eVirustotal results 45.90%Heodo
2020-07-30invoice-Y256-376149.docdoc 7579d4a1d6d4da73019950ba9cd7de417560465889ccbc12fffbebff6b87ca3cVirustotal results 45.16% Heodo
2020-07-30INVOICE ISF50_48392748.docdoc fcc525f6dd0c743849afb4e000a0829d47f24999eea8c8689721e2afd70df51bVirustotal results 44.07% Heodo
2020-07-30Invoice-WFTO2{:REGEX:.docdoc 35dfa0b9a11dcd3a2920e7da86c66da6b2b94ab67c9aac6e3743e53bd3346f80Virustotal results 46.67% Heodo
2020-07-30Inv_YAST986-273915.docdoc 1a36bd245a9053a5742fb8aca3169f91382921c429bc62eaef3471cb4bfc743eVirustotal results 46.67% Heodo
2020-07-30Invoice0 26081976.docdoc df1063c155004f08777c7bf91d18f44c2529b0736a80bee492c957f99efb23bdVirustotal results 46.67% Heodo
2020-07-30invoice_OPQ2{:REGEX:.docdoc c444016d70224a2cb4808352f39232719d705243dbaf2321c3aed6cee511890fn/a Heodo
2020-07-30invoice_K764{:REGEX:.docdoc f1761ccaa75c38c0b7a7816b613688bcc01590af8717fef82dc50d9620ff7838Virustotal results 45.16% Heodo
2020-07-30Inv_QV01-15079958.docdoc 981ce108681f9a7d192ab87f86b3442976f338e3118d533037a965c0cf00e601n/a Heodo
2020-07-30INVOICE MFIF7-948858.docdoc b56bf0f5aef789b7a05528c971f8f709495c67e7b3025fb13dba152446d9c197Virustotal results 46.67% Heodo
2020-07-30invoice FV9997-568403.docdoc 2ebfcb3a012fefed6779dc9a99fefd03e27f24621cac89362926b5e589af06f6Virustotal results 45.90%Heodo
2020-07-30INVOICE-PYGB3{:REGEX:.docdoc 299b8c34cfaa47a3f884d83e3b6ef10c75f0552bf3b16350d44d8ca86f89c8baVirustotal results 44.26% Heodo
2020-07-30InvUIPQ88-868643.docdoc 4e0a207adc8d98c528137c91938100b8095dccb87c1ce94b293ba27824b6835cVirustotal results 43.33% Heodo
2020-07-30INVOICE9038{:REGEX:.docdoc 9073425e395c1b7a8d42cabd461cad86cd0646bd77f042e13bcd2f98979fe12dVirustotal results 45.00% Heodo
2020-07-29Invoice-DE689-5155670.docdoc 9682cb3fed20b168899452201908168de9b2c2d82530d7227a4474b8b2587eb8Virustotal results 43.55%Heodo
2020-07-29Inv_EGYF9-718682.docdoc 51077cb5f430fd81fc483c397d7619718e338949394dabaa9ca2f95283c1e1ban/a Heodo
2020-07-29invoice-ZBD10-1364762.docdoc 4c620acfa4d837bab69227d52e1e1c2ad812ee779e76d3c8ae271956d8320550Virustotal results 43.55% Heodo
2020-07-29INVOICE O54{:REGEX:.docdoc 504c84d3083058366a68b164b12c19ae0a928586ff465b3f5199ee572d5ff953Virustotal results 44.26% Heodo
2020-07-29Inv-13-88114542.docdoc 0154bb8b4ba5c8ae6953ccef01b7c2520377c676c34d08564a7fb556b5dd5dc3Virustotal results 38.71% Heodo
2020-07-29Invoice-DEGB2 639721.docdoc 26c166a9ac0dbe51032e4bfcbd085f892aff04ef46a649d4e51a11d2a1ae5848Virustotal results 36.07% Heodo
2020-07-29Invoice_G015-88866384.docdoc bf57e995ed5164cb8ce9480d1fbda2caf6151a35967a50f14c191d96881f227en/a Heodo
2020-07-29Inv_SOJ147-636086596.docdoc 9a2096146b8ace7eb4e64e5a25cf48da7bfe891b37e48e83edd349cce12d5628Virustotal results 37.29% Heodo
2020-07-29INVOICE T24{:REGEX:.docdoc 0644fc32d19fccfcc17f4c76d1f463049498e6005f7228f63aa9b88a1d17c95eVirustotal results 36.07% Heodo
2020-07-29Inv KT00 3431810.docdoc f993b6aad57f95ab2b4d2dadf658a9accec7c914478dadf58e5d136f42b5f0b7Virustotal results 36.07% Heodo
2020-07-29invoice-CLJ4644_254567276.docdoc 46019bce6a3fc37ac4ba303099277dbaf8bb4e7fb09196ab0317ee1f5fae9da4Virustotal results 34.43% Heodo
2020-07-29Invoice OJ699_9069144.docdoc eedf761aed061fa63744aa541d5ddef3b7d53978fd00882cbf9fb0f88bd82550Virustotal results 36.07% Heodo
2020-07-29Inv_RG25_91099980.docdoc e71897829455d67c03b3f1a81795720974786866c4cbcdc3b93be5cd01c9071fVirustotal results 34.43% Heodo
2020-07-29invoice-A6-959533.docdoc 237c43a5291d6a1fcc464727bbfdd174bb1225e9c12283348c788b1b884b1dcaVirustotal results 35.48% Heodo
2020-07-29Invoice_JM4427{:REGEX:.docdoc 6bd95c503150dd15cb18ddacc365a182f9dc405d69fc8cb0c081ff4e8064e9d4Virustotal results 37.29% Heodo
2020-07-29INVOICE-VH9-472843187.docdoc e73f2075610d9b2cdef2e9a0cd4cfb82d1be854382f0fd03f5f1f9b28707e914Virustotal results 36.07% Heodo
2020-07-29INVOICEO5 59661469.docdoc 18b4fa83a6ab9f4a394a9642e954cf6b8184bd9b0597de0ff9fe3376db4a6c86n/a Heodo
2020-07-29invoice_RD675-303838740.docdoc 016b416def5205972b6d2651f449b02216a8063c2d205249bc8e1d58ae914a99Virustotal results 35.48% Heodo
2020-07-29INVOICE_DGD133_05393103.docdoc 836f741608d5aee28ac46b0fa047807f7ae6a35279131bda901f56e31f4d9561n/a Heodo
2020-07-29invoice-WTV67_60092216.docdoc 66101af9345cb4f58a1380f463086cc56c8b653f617e9b6f264bdafff2889bf3n/a Heodo
2020-07-29INVOICE-DYT8-749918567.docdoc ce84a183d89aa2b9c0fa25465a6a34e63fdc6b0bb9a8f403301851f964fa2e53Virustotal results 33.87% Heodo
2020-07-29Inv_I46-204818.docdoc 8456274a688414232817a75773a07e793e349e504a9b92f536826a89911a07cfVirustotal results 35.00% Heodo