URLhaus Database

You are currently viewing the URLhaus database entry for https://lorimakafrica.com/wp-includes/Fox-C404/root/tmp/HW_12/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1969479
URL: https://lorimakafrica.com/wp-includes/Fox-C404/root/tmp/HW_12/?i=1
URL Status:Offline
Host: lorimakafrica.com
Date added:2022-01-12 03:13:04 UTC
Last online:2022-01-12 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-12 03:14:13 UTC to abuse{at}cloudflare[dot]com)
Takedown time:7 hours, 45 minutes Good (down since 2022-01-12 10:59:57 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12FHZ_77857.xlsmxlsm 0ce7f819733d08362b743df1f8a94ed0d3abd4469a31fc411ea7e26d3119b02en/a Heodo
2022-01-1280396489_725.xlsmxlsm 6828ea8aa944ba958a4863701d41c46fbac044a3916242dc9495151fbd977612n/aHeodo
2022-01-12703259_20956.xlsmxlsm e8444d7c8ad337d68d8f8125303ee8727cef369798e6855603dba9c41ce05f62Virustotal results 14.52% Heodo
2022-01-12368792_33914.xlsmxlsm f9692b1b14f84c19013c44d18cbce9002b36fae19825c152563aa55cd4507402n/a Heodo
2022-01-122440JPDC_953475.xlsmxlsm d4864682c7ec6c7464511d321df944a7133cf2b0b3fc435d5a88d19cbec3df3dVirustotal results 15.00% Heodo
2022-01-12JHRF345234603.xlsmxlsm 6913af2de9271a92bd9c7c9afe4923a08f237459d7e1e03d171e96fa291e39eeVirustotal results 9.68% Heodo
2022-01-122636SJDFT_136.xlsmxlsm 1432dfaf66fc92262751cc8a85c31df66552687538effa62d8df537136495e1cVirustotal results 14.29% Heodo
2022-01-12230724815_594.xlsmxlsm 625687935238f3440d23e0e665260938c35db15afa88359c423fccbbadd6d4dfn/a Heodo
2022-01-1247063084_86181.xlsmxlsm 43b1fd1045c3f14e9e12685a2fd7074bd2a0d7cf9e47d23af2e2ff8dca2a2f5cVirustotal results 14.29%Heodo
2022-01-12QZXrL-119.xlsmxlsm 4b2ced5ad04b4256bef5bee0fb95867913b271eabac843923fc16220f924b332n/a Heodo
2022-01-12OV_1158.xlsmxlsm db88756a23fe6c0998ddbf1864efe7e4a28073dca342fa7712775388ac757529n/a Heodo
2022-01-126698_499.xlsmxlsm 7bd438038cf3ae20c965eda9ebaa1805f9347adef486223ff8d6815a0ec40cddn/a Heodo
2022-01-12R_05857410.xlsmxlsm 4bdfc4d2f6481a25fe90516f5ec9235465fb26cb61e9099697c9c99002c9fd3cn/a Heodo
2022-01-12J-670723.xlsmxlsm 1703b3ed61314b55df26556fb39593560397c5da3dd952dba8f721744e14e1afn/a Heodo
2022-01-12I_034324.xlsmxlsm 95761ae4efbb60ee498b7d56d6c84e48753a21ab59a655f5439b47167baf6ea2Virustotal results 10.17%Heodo
2022-01-12P_78062296.xlsmxlsm 8232bffcdf155d94e02d6bf3de90b25764ddf81e8d0071b283d866debed7e5a3n/a Heodo
2022-01-12ocYuF952.xlsmxlsm 1c873e22b4b174756cf0b84c5fd5af1b12515761507c3723ff77a95572ef0823n/a Heodo
2022-01-12TINVB_755865.xlsmxlsm 6fc6f7cbaed594e40371a289a3a56eeb8915a7893409b8b85b07800b543dc3bcVirustotal results 12.70% Heodo