URLhaus Database

You are currently viewing the URLhaus database entry for https://deveshdas.com/fgniwbw/browse/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:491817
URL: https://deveshdas.com/fgniwbw/browse/
URL Status:Offline
Host: deveshdas.com
Date added:2020-09-14 07:56:36 UTC
Last online:2020-09-14 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 07:58:02 UTC to abuse{at}e2enetworks[dot]com)
Takedown time:6 hours, 26 minutes Good (down since 2020-09-14 14:24:49 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14INV_PO_09142020EX.docdoc 8479daca0fc8e5a71c4658b54796c49513f4c6b45d048438213ec781db114c6bVirustotal results 22.95%Heodo
2020-09-14REP_IU9965804965XF.docdoc 42c4b1eb39af3f83f49c39994431eb0a042d94a008313cdaf1831db93c45cf5dVirustotal results 22.03%Heodo
2020-09-14PO_09142020EX.docdoc 1696e01404af8e515a6ed2d5b48c04a659ac1ac279a678816278240d1ce7b9e7Virustotal results 22.03%Heodo
2020-09-14INV_89120797.docdoc 21bdbf6ef88670da6f32d97e4d4d1ddaad79bbee1a8d10d476ef78b5a63e14b3Virustotal results 23.33%Heodo
2020-09-14BAL_82874818.docdoc 506bd0bf18d33b2e92b6638ec09ed0af6dcedffe870c41063f7845695e19fbc4Virustotal results 22.03%Heodo
2020-09-14EYK_090120_OBC_091420.docdoc eceae0ba2886d41470b5aacd0de4ac004bc97d88e4bfd489d7e8c420c5f00b79Virustotal results 23.33%Heodo
2020-09-14J_05072098.docdoc f14c6bc62e459f57fcbf3044108e087966c7f90e706b655248f9707410094bccVirustotal results 23.33%Heodo
2020-09-14D_EEX_090120_VGC_091420.docdoc 11cc4036d50f7e705e15ad8d6b14813b0f328d9e14d31aa6ca51ba7e13fd4f4en/aHeodo
2020-09-14INV_RB7432499556JB.docdoc bed57dded8f474e1685273acb47e279b76b699d0e2c44ac0f299ee924329f3a1Virustotal results 23.21%Heodo
2020-09-14BIW_090120_VXU_091420.docdoc 098897d4d3c482f9c893a2e5e57a45d28eae55a43d34b828145c427ec86d8145Virustotal results 23.73%Heodo
2020-09-14PO_09142020EX.docdoc 024ff9ff62ba78ea622ddcaaa68aacf0cb62fc53c52caa27db4e4cbe4e413a89Virustotal results 23.33%Heodo
2020-09-14DOC_JLZ5J7EY8ZQUK.docdoc 80d8e37e856ada6bc31bdd15d3ef46e47cf2163c6394c78aba7ee026b55a6b2bVirustotal results 22.95%Heodo
2020-09-14BAL_912105711975612967356.docdoc b55cdf490435476aca6b1d71b6b9e509cf20125e5c8135c53de653035fa5a76aVirustotal results 23.73%Heodo
2020-09-14DOC_65713414.docdoc a4382cf56e05d13630c7a129db107238817296f692f1eecf1822c8570b7cb51bVirustotal results 25.42%Heodo
2020-09-14DK2217137235VP.docdoc 2e215528092b344b0a24685e8a198c966686cc291bb40928657a8418d60e6dc2Virustotal results 22.41%Heodo
2020-09-14REP_46994786845325514.docdoc d22e0f5cf4f0cd9ab2121bc4d93499f817db516480f38b3d0c231c96b6325fd4Virustotal results 25.00%Heodo
2020-09-1444196106.docdoc 545c9d3db8ab6b89f55b30fdc4e712ffed6df46456b43712f1c817c0d51eeff7Virustotal results 20.34%Heodo
2020-09-14I_BIL_090120_UNP_091420.docdoc 2d20ebdc70f23d11e13468b4de38fe69555e3669ce8cf1baae4eb1d420bb85e6Virustotal results 20.34%Heodo
2020-09-14BAL_98668140.docdoc 785e1a7b7818be6954ac21f9d27f2d52615235cd8915f6580b94a3ccf806c8eeVirustotal results 20.34%Heodo
2020-09-1457199297.docdoc 5007f4224186818c079d433d9e2f64a83f4fa9858c1b0ce3ea1eb9a63ce16f17Virustotal results 20.00%Heodo
2020-09-14B_BQ9215113749OZ.docdoc be0e619baef81261208fc1b0df1626bbcb28a3bb029a537c635a5e4649210291Virustotal results 20.34%Heodo
2020-09-1439561374252685.docdoc 99b56f40d2606b054f2ebb2682d4578b3e8813434d42cacd763e8e278712ff0fVirustotal results 20.00% Heodo