URLhaus Database

You are currently viewing the URLhaus database entry for http://kanhafuncity.com/Fox-C404/iKiX9w2MLkrGpgzORQMw42NyOKkg/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1993903
URL: http://kanhafuncity.com/Fox-C404/iKiX9w2MLkrGpgzORQMw42NyOKkg/?i=1
URL Status:Offline
Host: kanhafuncity.com
Date added:2022-01-20 21:33:05 UTC
Last online:2022-01-29 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 21:36:10 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:8 days, 7 hours, 55 minutes Bad (down since 2022-01-29 05:31:10 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-21823314721742601.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 36.67%Heodo
2022-01-2146887900204212.xlsxls 3ca3bcd5771a06938cc8e8c44cd2c85b794376401b469fad7e5d4b513449fa27n/a Heodo
2022-01-218473941928873075.xlsxls e59173f043483afd41faf0edf28ff91047d48ddbcabe29efe43bbc7d238c9861n/a Heodo
2022-01-217864151156433.xlsxls 5a6ae409ad46c453172d047a1b1d7685cbdcc317653d90c6a968509d1c2229b6n/a Heodo
2022-01-214397831128.xlsxls f35abc3dbc3faa333da128234f2b7778969e1ea5f8ef088498cc8ecf325f8a9cVirustotal results 35.59% SilentBuilder
2022-01-2138491612529671555302.xlsxls fc79dd33ef2208cbe871b54938ff2ad295a34cb9a720e4995853dfed5761db18n/a SilentBuilder
2022-01-21491062511107763708.xlsxls 29111d8e5e8306e76660db292e7232ab39e901955014eede21e912c931a09b5fn/aHeodo
2022-01-214754888897510071333.xlsxls fd83649a426e706a363449d7dcb503e4bf5b59cc3ab5d5a346e4ed308ec2e2f3n/aHeodo
2022-01-21558576208292.xlsxls 531278b90b12ac32bc7671c1f2a52ccc15afe992249b5dda28ae98885b954c99n/a Heodo
2022-01-20376097308739172315.xlsxls 39123bd1932920eca6749593bee628c405f8bb88114d8647a5d9db8b5914f46cn/a Heodo
2022-01-205906387336285624.xlsxls 79ab6a611483efd4c9e4394ac5c6a91c458857820c4c4b9bdecf0cab92acf8f2n/a Heodo
2022-01-206488598325.xlsxls 1aa1e797bd106f28bc73e4a09bd4d3eb7a13943ef42f06bda76c41fbca54d0ben/aHeodo
2022-01-20764597065299512.xlsxls a72795a18fa2b90928f307e227b1f1a57590672870b3acc9e8cb0eb4d38bdbffn/a Heodo
2022-01-2068431084110.xlsxls b069423ac3753a4878bd652c9c55362c541db7529bd0b294ddc47bb7c6475946n/a Heodo
2022-01-206965279209.xlsxls 8a39d34f5c3133db2f6137b02545e312f05bbdabceda4bd830948380fa4c98c7n/a Heodo
2022-01-2084339465322944227272.xlsxls 3b63534dcaf71bdf8293d2a3ce3310a02d2eda37deac68d5ccbdc89cfbc8f408n/aHeodo
2022-01-2065100514783746.xlsxls 245057c2c16d698dc5399ecd43ca39f9e0b35885a19cc42cd2650eb8e17d0c00n/a Heodo
2022-01-20628149232859.xlsxls 817f4c96e056390228a3d9ce57239ad521627a3617b13e4043dc99c91569ffccn/a Heodo