URLhaus Database

You are currently viewing the URLhaus database entry for http://technoswift.net/wp-admin/kkhk7-uj-690454/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:433136
URL: http://technoswift.net/wp-admin/kkhk7-uj-690454/
URL Status:Offline
Host: technoswift.net
Date added:2020-08-14 11:36:43 UTC
Last online:2020-09-16 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-14 12:10:02 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 month, 2 days, 22 hours, 26 minutes Bad (down since 2020-09-16 10:36:32 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15INVOICE Z71 602165.docdoc b9d2bc9624f1e81b007fd1d89170294eb6eb29c779f83f4e75576a0fa3fa421aVirustotal results 41.38%Heodo
2020-08-15Inv-T2536-936115592.docdoc 8166f9d5647da264c416fb5151e8f329302965d5717c6d4210d146fc41acd16aVirustotal results 40.68%Heodo
2020-08-15Invoice QP349 296053.docdoc 8f88dd80520ccf01a78eb649cc1a7918ff8a0c36019a7b5ecf59ae9c79afae7dVirustotal results 40.68%Heodo
2020-08-15invoice_7_904424.docdoc dae18dd9a3dbbfc06b5e5c10fc7dc93c670a0c191d7cb7065e9d478503274567n/aHeodo
2020-08-15InvoiceQQ5870644263.docdoc eab20959bc5079c5ec1b36810cc4511087f90d989ca29d297bb6b000c7bcdcc0Virustotal results 40.68%Heodo
2020-08-15Inv_EL20_9023307.docdoc 1fa982bca8d93cd9a5ed44c8adf3099360cb86476a38bcaa476ad2e23b32d854n/aHeodo
2020-08-15INVOICE-SCHQ9-3175851.docdoc b50b82d54433037c2321938527d4485ff439d6f6d5871ca14b88b0c887a51116Virustotal results 40.68%Heodo
2020-08-15invoice BS30 158743497.docdoc 4ac2ea7a4562ab7ea7c23ad733c0e4d0767936120e16b62e0248ce2af1beec1fVirustotal results 41.38%Heodo
2020-08-15invoice D42 408968801.docdoc a586ca4e85501c0a9314f75805246a91c9de018ebd8b6441982d39e8d13f8a64Virustotal results 42.11%Heodo
2020-08-15InvoiceCZED730175090458.docdoc 0626485a74e0892c83b55a0cf767cdf3603df9603dfe205ff02ab869d24ec13dVirustotal results 38.60%Heodo
2020-08-15invoice-030-51024728.docdoc b2d036dd47e8eed612cd5fe5dae22412f857756ad9f6a4a293cf7990bc73c8b3Virustotal results 41.38%Heodo
2020-08-15Invoice-FLB298-5260656.docdoc 7685045c26c2b57ea45d561d8f6b9d4746939825e90633a6e3d72480686c1858n/aHeodo
2020-08-15InvoiceS271251990.docdoc bae86b6997572490c22ffc81ad1e24ecce68f3d2124066b202be498fbd9b7d72Virustotal results 42.37%Heodo
2020-08-14Inv-QX340-3593720.docdoc 95cc5ce9259454f349e823d4c1e4c546a303dacfd17dd01c60af5f9dfb171cb6Virustotal results 36.21%Heodo
2020-08-14INVOICE-YAJS1114-072029.docdoc 9b4854075266029833675d652902a1baea75b0755d7ebcd141125072d0967b65Virustotal results 38.98%Heodo
2020-08-14Inv-Q0-538640.docdoc 30a1ebc7ccadab73a1c6463cf44298031c3f083c146a97526e66aeb4f851e881Virustotal results 31.67%Heodo
2020-08-14INVOICE19385206995.docdoc 8668a5aae3e7db513fdb925e16313049037536bc67a86ed756b682c98b7f6f09Virustotal results 25.86%Heodo
2020-08-14INVOICE-PA04-9418238.docdoc 4935ab1182453885ea821cc714b1679ae7eeb54bb744fe13f52ad6e954a7f785Virustotal results 25.00%Heodo
2020-08-14Invoice_45_977592.docdoc 21c03f89445c00697538e5c37bbb08c294916530de14212a348e7fabbe09a554Virustotal results 25.00%Heodo