URLhaus Database

You are currently viewing the URLhaus database entry for http://evexiahk.com/wp-content/balance/d4k6f73i2v-0020283/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:722839
URL: http://evexiahk.com/wp-content/balance/d4k6f73i2v-0020283/
URL Status:Offline
Host: evexiahk.com
Date added:2020-10-20 09:56:04 UTC
Last online:2020-10-20 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 09:58:02 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:12 hours, 8 minutes Good (down since 2020-10-20 22:06:16 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20INV #0736213 FOR PO #0075405261342.docdoc bd285e352fbd21f0dc81df11d362338b6d68c0feade3946cfb351cd09759a9a6Virustotal results 51.61% Heodo
2020-10-20form.docdoc 6e81190ea76657504baff9bef3ee1e2b652f05d439d5d47cd39fe510ac240b26Virustotal results 50.00% Heodo
2020-10-20L-100120 TCFP-102020.docdoc 354fea5033e720e774f141b26f7606a4d844f9e990565c0c9ef51558c3581836Virustotal results 51.61% Heodo
2020-10-20S7037874205VH.docdoc 3efdffb2e5d608726b26fade900a88aeca31495f56871fe6723d4959fd1d6c56Virustotal results 55.36% Heodo
2020-10-20Payment.docdoc c31795e9d2a3b7bf6e19d054a2574f0ea3eef997e49bd9318316efd609cada94Virustotal results 50.00% Heodo
2020-10-20invoice #34674.docdoc 5cfa1457e7ddb2e7c49419cabef1c969debc4d677e7ca6f72d6edd8e2ac88a32n/a Heodo
2020-10-203093754.docdoc 03ed194d560f6e7b976f45dd5678707c7132079b5d6d1bf0366c7163e939cb1bn/a Heodo
2020-10-20QLX-100120 DSVE-102020.docdoc 60ac2df8c0a56c198ce34633dc5af133c4fda800a85383a2ea9e6da298e77904Virustotal results 48.21% Heodo
2020-10-20L00446 invoicing.docdoc aea562896196459f11e274751fcc92aad6234db3e78088c86bda7f2b31be9b4aVirustotal results 53.33% Heodo
2020-10-20IH9803343573EI.docdoc a67d3d825a05eae828eb68703949b29ce211f2873a8c91c7875b89ea9577a817Virustotal results 49.06% Heodo
2020-10-20invoice #16289.docdoc 63079c50ac6b966778ae92e6a4d39927b58a475be4b8d095192b40ad5a877756n/a Heodo
2020-10-20October Invoice.docdoc 31f0b205c09b9d99e10c2626936588bd3b473116e313045031cfa6f9a8bf23c8Virustotal results 57.89% Heodo