URLhaus Database

You are currently viewing the URLhaus database entry for http://ks.od.ua/wp-includes/KXdkADm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:246322
URL: http://ks.od.ua/wp-includes/KXdkADm/
URL Status:Offline
Host: ks.od.ua
Date added:2019-10-18 12:57:19 UTC
Last online:2019-11-02 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-11-01 18:22:13 UTC to hostmaster{at}ukrainianhosting[dot]com)
Takedown time:14 days, 20 hours, 57 minutes Bad (down since 2019-11-02 09:51:25 UTC)
Tags:emotet link epoch3 exe heodo link Trickbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-10-1881dd_75251.exeexe 9201b966c3774597ff7b2682c55a7fe048a1b36b0b7fd393e7e5d2ffb4ac09ecVirustotal results 18.57% Heodo
2019-10-1809q_8708.exeexe 5dd5760cbae451b409c211de42c63cc428a0989c2c485605a331f51d1118d361n/a Heodo
2019-10-18ouy2c2as_9235393385.exeexe f97a22eee4af3537661856c847cf4770d50050af3af61d25d8448e35df0cdf6dn/a Heodo
2019-10-18w4q2uh_5086246.exeexe 5cf4e4685ad7ca9ab329c28b554936ed72cf7501e2c1f66fe1c0e234f97c1b40n/a Heodo
2019-10-189y6fip7h_015.exeexe 8784e9d5e6ec26293a5cf0cb4533459cb94934c1560635336ed7bdca667ab381Virustotal results 17.39% Heodo
2019-10-18ssp9_004.exeexe 581a994bec377fb99e86a238fb2129617dfba0c15e4335b5b1759f5f25becec6Virustotal results 14.08% Heodo
2019-10-18bybgsnp_68.exeexe 9fc0fec6e1613ca223e6e1f44775c7a650950bbaf37645d685d2eb169f97c0f9n/a 
2019-10-18ucw29frnl_6006.exeexe 8fda26d340732ed51fefdfb1d0d114efc6414d9eb64db9eda83d3e6ad17799cfn/a 
2019-10-18i0t_140503892.exeexe 42512da89412fab0eaf46dc2b9e664d0d428a6a21e003207bdf481ce5e1774e8Virustotal results 14.08% 
2019-10-18vjdlo67p8_53.exeexe f6e775667e1f065186796a252092dc725f5850d1261266f77f0f42366a7e4d47Virustotal results 17.14% Heodo
2019-10-18ib_54.exeexe 9c0524237e961eac875d1e6141396a9866354661861eb12f642789da55af7f3fVirustotal results 7.25% TrickBot
2019-10-18q0g92vgok_3987760.exeexe ebf4f8fe26acf3ab1c970b75c05ec84a62fa59b9442ee1696acb3f1544dbfc9fVirustotal results 8.57% Heodo
2019-10-18dmu1yc_7.exeexe da0d6099dbd7ec520cbe3702eabfa6943ca2421435a20c66dee25196e6ec5a03n/a Heodo
2019-10-18on5_978.exeexe 62318dfd70e6650c48b00766fc140cd96647cedb2acd36959db4f9781d5f905bVirustotal results 7.14% Heodo
2019-10-18x97np8dp_4112658.exeexe d5e515c572d20e44a136312a3f700c5a69bb8fa9f62d90f12cef225c6ededecfn/a Heodo