URLhaus Database

You are currently viewing the URLhaus database entry for http://kenweb.co.nz/doc/En_us/ACH-form which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:50197
URL: http://kenweb.co.nz/doc/En_us/ACH-form
URL Status:Offline
Host: kenweb.co.nz
Date added:2018-08-31 08:05:05 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?):No
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-31Invoice Query.docdoc f21e796035e8fc8916cb80a3ca4361d5e4d01cde2301ac0540bca3c92db7d3c1Virustotal results 31.15% Heodo
2018-08-31Latest invoice - 223019.docdoc b134ac283063896b64c18aabb90961561dca0480e9c7fccdbbdb7316f231d369n/a Heodo
2018-08-31Final notice.docdoc 4986ba3fb0b7756341ebeddf0af16792fb61dad7cc47f6c1e44e5e2fb629d171Virustotal results 33.33% Heodo
2018-08-31Latest invoice - 225050.docdoc 87d1341c26511e57d07e8df5c6d6cd64d4d6f95e7403e171c1fc38415d134177Virustotal results 33.33% Heodo
2018-08-31Accounts - Invoice.docdoc 79765635b755992b9035560d4e00b550c3690c4a75d4e022b5998f11db4db738Virustotal results 42.62% Heodo
2018-08-31Billing Invoice - Job # 175573.docdoc 9c089c555d580ac18b55b2874e92232c5dc86517904ae107ad79cbaf945170d7Virustotal results 42.62% Heodo