URLhaus Database

You are currently viewing the URLhaus database entry for https://www.dalice.edu.zm/content/NKKT454/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1984017
URL: https://www.dalice.edu.zm/content/NKKT454/?i=1
URL Status:Offline
Host: www.dalice.edu.zm
Date added:2022-01-17 16:27:06 UTC
Last online:2022-02-01 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-17 16:28:06 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:15 days, 3 hours, 8 minutes Bad (down since 2022-02-01 19:36:24 UTC)
Tags:emotet link epoch5 heodo link xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-18WKF_3186472.xlsmxlsm 4768c2ac693c9073317c292a37bcf481c9f41cfe760f77e4b2eb91a3dc6e3ffcVirustotal results 22.22% Heodo
2022-01-1708362_11.xlsmxlsm 6bee685b8b324236eb8b115a9e45415d17156584fd6a5766b216655909a50f02n/a Heodo
2022-01-172595TCUYQMT_690954.xlsmxlsm 8dd820845baaf3c5c1c3fbb2ce94c52fd4d4efa16364469c20a3146cb22f44acn/a Heodo
2022-01-17MFN927647.xlsmxlsm 7c3c2188b9cc8f4f771664509a37bb3c4cf568743a9e887095bc598b96d72c33n/a Heodo
2022-01-17XE594282.xlsmxlsm 136486d9857b5cc401cdd33c2ba110d61f9a6842f8edc9065352d4f8fb153234n/a Heodo
2022-01-1765157_5312381.xlsmxlsm 55fc4b8c2e3f9db7f0c8f3fcfc0297b17c57c680c4c9df5006ed94196ff783den/a Heodo
2022-01-17U_62.xlsmxlsm 34a1b0b5d38a036c45fa73926dedfaff07606db3a238014cc94e799c8ec6bbfen/a Heodo
2022-01-17G82650532.xlsmxlsm eaa45fb291dc0a9f4aedbc4240bb250a5d8d76d6e09b3bbc071cb7aa32493600n/a Heodo
2022-01-17YHEW-3276872.xlsmxlsm 292fdc91610f3758448cd20465cda055cca6df8b9fd19c579b79178b90ae0ccfn/a Heodo