URLhaus Database

You are currently viewing the URLhaus database entry for http://revol.vn/wp-includes/Reporting/HGdutdVHBWVIMJPdRG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:753578
URL: http://revol.vn/wp-includes/Reporting/HGdutdVHBWVIMJPdRG/
URL Status:Offline
Host: revol.vn
Date added:2020-10-26 22:20:06 UTC
Last online:2020-10-27 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 22:20:10 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 59 minutes Good (down since 2020-10-27 02:19:54 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27MES-2020_10_27-161842.docdoc 6562c1ec0d60cdfb002adb4ed15dbbf2f2f3f717002fbe8151e35d3755eb4358n/aHeodo
2020-10-27mes_20201027_F34836.docdoc d5fc142bfa2e0ab5cc22067cb316b2f73dbf3cceed7fe452a46028fe26c38610n/aHeodo
2020-10-27INF 2020_10_27 HE598.docdoc 39bc04da6b9d4faad7b5cae654c8f59ad7ac01b3fb70e293d8fbf1b5b6e15c61Virustotal results 51.61%Heodo
2020-10-27LIST_LK201.docdoc 98ce88c9f247c75c579d1893aa0e20cd63f5a61f4b7ab7a70b4e138e34fed993n/aHeodo
2020-10-27Rep 2020_10_27 AHA868.docdoc 52d4dcd449517b101bb99988f9b270b9785a8987cc4edf558f18fa0bbd5bb438n/aHeodo
2020-10-27REP-ZG1996.docdoc 34552d4adde7395abb5b114284e79a47c0aab68c0ab1fc62affe993b7373852en/a Heodo
2020-10-27Inf 2020_10_27 460.docdoc 7f3ad8f66409867f25e71e87520c6c5bef13981bf27cab43e285638a3681292bVirustotal results 50.91%Heodo
2020-10-263270709_20201027.docdoc 5af94d5b1e905c40d01805e011b493589549f37de4d6eb3e1b68044d47d8988cVirustotal results 41.27%Heodo
2020-10-26file_20201027_5629200.docdoc d51e0046c1cfccdbbee59aa82fdc5780aace64ee8225348e067170db0a442ba6Virustotal results 41.94%Heodo
2020-10-26Attachment_20201027_3185266.docdoc f620c363a605c7c11abe0ed6c9f919168781361df2901e24752c0ebd428c4854Virustotal results 40.74%Heodo
2020-10-26Attachment 20201027 457.docdoc 73d1b4c3fb5a035d592fd68fb3393cbfbd659c6fb165d4aebb3c1abd953aa593Virustotal results 40.74%Heodo
2020-10-26Untitled_20201027_OYS552.docdoc 4e166862bb4b0cd09fb6d5fde9004ac49c14d9ac11f8e9d37f551c815721128aVirustotal results 38.71%Heodo
2020-10-26Y2916-20201027-6426.docdoc 300fe8a8206fc96bf8007311c265ecd86c75124818fc9b9f3424286f106da398n/a Heodo