URLhaus Database

You are currently viewing the URLhaus database entry for http://modasafrica.com/bwk5/INC/zwJnbSkwv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:203258
URL: http://modasafrica.com/bwk5/INC/zwJnbSkwv/
URL Status:Offline
Host: modasafrica.com
Date added:2019-05-29 00:44:07 UTC
Last online:2019-05-29 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-29 00:46:01 UTC to abuse{at}ovh[dot]net)
Takedown time:9 hours, 34 minutes Good (down since 2019-05-29 10:20:09 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-29FILE_33156790688US_May_29_2019.docdoc 0ec17a8edb1ec98daf5790820bf85ff91c11a851924f3698c1dd44c2cf748c21Virustotal results 28.33% Heodo
2019-05-29LLC_73959768811US_May_29_2019.docdoc 94f338b63bd496a96cf9a3416dc4daf1700f2d8f41b94cccd9e7ad598e2d4b9cn/a Heodo
2019-05-29Document_23622614334US_May_29_2019.docdoc 8e8d942ee2283a2529b4d273cc6c8db779a74130a585b2536cd214e7d8ae9789Virustotal results 41.38% 
2019-05-29Document_5407729223US_May_29_2019.docdoc 5562dcb788a2c33d19f327cef9ca79bf51c08ecbea0ba637ffa8af54bac3d463Virustotal results 40.68% 
2019-05-29DOC_084658401433US_May_29_2019.docdoc 913d5a77b54de2bf16bb2e0e8b39af0b83750ade322a5e38b98aea925b491570Virustotal results 39.34% 
2019-05-29LLC_275121200761US_May_29_2019.docdoc c0285a05f35e5c7ac9b7436dcc0fdefb62400b8d869e55141a7ea84268ae970an/a 
2019-05-29LLC_5480884970US_May_29_2019.docdoc a239776607f11c9a2b4480e23336e5281244cef6f673ca16f1d0466db9de3465Virustotal results 39.34% 
2019-05-29INC_52688272228US_May_29_2019.docdoc f4698dc0c5630110e51ddfed69b2364659b103308034c69c1d7a02c70e978f46n/a 
2019-05-29DOC_015910111455US_May_29_2019.docdoc 71ffc0572d33719508587b6fb096c1fcf4f95eed91a4859d8f0e37911bcd7531n/a 
2019-05-29INC_62044207678US_May_29_2019.docdoc a75fa23ea816abe4a2ada31182aea5bb12748317be14ef2808607070d92cbefcn/a 
2019-05-29FILE_247351157552US_May_29_2019.docdoc e151c10ca1bd2c8ec3dfa403595402778c44287819362151ae647c11febaa91en/a 
2019-05-29FILE_7805129064US_May_29_2019.docdoc 15dafe76124cb0239e7593932864fe5defc12cfe2243f3ca51c968c597bb62c5Virustotal results 29.51% 
2019-05-29LLC_31033480531US_May_29_2019.docdoc b8ffa044c1aa76470b3ad334f834da777ef71e8532497610d00b128d37fc6a54Virustotal results 30.00% 
2019-05-29Document_8659212110US_May_29_2019.docdoc 63f8450d3c9f65a624fa65d8e760fb3baf430de9e6dff4efc096e7f3e2ac756bVirustotal results 30.00% 
2019-05-29Document_05621716482US_May_29_2019.docdoc 791995d3e1cfd697b9ad833e1712357a476f1538c38a001925ce94d3ae39edb8n/a