URLhaus Database

You are currently viewing the URLhaus database entry for http://elokshinproperty.co.za/jtau/paclm/8ouar200imvhee4iy_f85p9l0e-62227938/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:189707
URL: http://elokshinproperty.co.za/jtau/paclm/8ouar200imvhee4iy_f85p9l0e-62227938/
URL Status:Offline
Host: elokshinproperty.co.za
Date added:2019-05-02 19:14:06 UTC
Last online:2020-11-17 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-02 19:16:05 UTC to helpdesk{at}apnic[dot]net)
Takedown time:1 year, 6 month, 24 days, 11 hours, 58 minutes Bad (down since 2020-11-17 07:14:23 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-03-26FILE_6413972249US_May_03_2019.docdoc b3c13cb2986a038249adde69d86b8ea1bfb54271def19fc3c2ecfccdcba00f5bn/a 
2019-06-21FILE_6413972249US_May_03_2019.docdoc b9f18fa8392dd9be62fa5e88a7ce0d5e94998280d5e5021f073f6ba5bd3aa43fVirustotal results 66.67% 
2019-05-03FILE_492161672543US_May_03_2019.docdoc ca8b291d0dc68db57dcde7e61fa81d3da86f9c65c5006a6228e7fb80cd8ee651Virustotal results 35.09% Heodo
2019-05-02LLC_10072156374US_May_03_2019.docdoc 15d6cb9824fffd568458004f7229d69b27e35d5832a06314821f924491c61f3bVirustotal results 35.00% 
2019-05-02SCAN_8340784159US_May_03_2019.docdoc e94720b4121c2f2d41e0ee3d754100229d76b7f7085c5700cc059ac806f0a59eVirustotal results 39.34%Heodo
2019-05-02LLC_403168451693US_May_03_2019.docdoc 354a0c17e9b347d1d27a3b8d605f7f1bf162d5ed17453430d9bd70ad026da3a2Virustotal results 38.33% 
2019-05-02FILE_95528513391US_May_03_2019.docdoc 279da8586939650e58af66d116101b17bc938c19bb18661aa9f44475bf1a5478Virustotal results 37.29% Heodo
2019-05-02INC_8091183134US_May_02_2019.docdoc 6c1d9bbd9dcad8b950dcada8139a8b21e31036ae9d319050f7513d240ef31995Virustotal results 36.07% Heodo
2019-05-02INC_201182480930US_May_02_2019.docdoc 7b492a6aa0b683eb1c70b5363eb6649a63b0cf81cf23c8534546d71a762be37cVirustotal results 36.07% Heodo
2019-05-02DOC_890583825361US_May_02_2019.docdoc 9412268f1f2c0eb9a06cc682d774e05495a3b4e468749c77e157a5a354c2c8d8Virustotal results 38.33% Heodo