URLhaus Database

You are currently viewing the URLhaus database entry for https://www.netkafem.org/wp-admin/maint/jcz94-atqbdjw2cg-13/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:260790
URL: https://www.netkafem.org/wp-admin/maint/jcz94-atqbdjw2cg-13/
URL Status:Offline
Host: www.netkafem.org
Date added:2019-11-28 00:29:16 UTC
Last online:2019-11-28 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-11-28 00:30:02 UTC to abuse{at}ovh[dot]net)
Takedown time:7 hours, 57 minutes Good (down since 2019-11-28 08:27:05 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-28b0prtt1eo4_9217.exeexe 27d4b08ae7bc58be3114b19f898f01cb9925dd3b13427c030cbebd258c2bf006Virustotal results 8.70% Heodo
2019-11-28g7mk7pppx_563.exeexe 51aedefe29f75921a16172c68f8e910953d19dd4e940c4daa1009a6911130e04Virustotal results 18.84% 
2019-11-28lob_3.exeexe 124c7a79d9faf9ca3cab58dfcce2ede3a58ff628afe0afe56c481ab69deb6132n/a 
2019-11-28rv_980.exeexe 3fdcba84749946fa4e2b2d43b85ee3bd18db34bc0a4425b9fc33ac2c2816e1ccn/a 
2019-11-28ip78dd_918.exeexe 03ca9107003abad1615501e4b9aadb76007a293fce246ec6f14abd23978ac9a0n/a 
2019-11-28903t49_3026033977.exeexe c0ea2dd573afed78d40a4df96fec2882aebbf77ad9887d3c1dcb1131562f4ff2n/a 
2019-11-28lpgdz_1304113.exeexe c3f0038e29991d8584963ff5b5acd4f1c4f9466fa0ff45d57bde268efc2c8ba5n/a 
2019-11-28g1r4t91ttn_6.exeexe 4793d4d9634803c2596646c6467b72301e07fe9dee357a53b2026e95bff31eb6Virustotal results 16.18%