URLhaus Database

You are currently viewing the URLhaus database entry for http://kejpa.com/roundcube/plugins/codemirror_ui/lib/CodeMirror-2.3/Overview/ij87emc2r/drae-6923333-844804-9uu6n23ef-7a7c9q0t/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:266340
URL: http://kejpa.com/roundcube/plugins/codemirror_ui/lib/CodeMirror-2.3/Overview/ij87emc2r/drae-6923333-844804-9uu6n23ef-7a7c9q0t/
URL Status:Offline
Host: kejpa.com
Date added:2019-12-10 18:51:31 UTC
Last online:2020-08-12 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):No
Takedown time:8 months, 6 days, 16 hours, 38 minutes Bad (down since 2020-08-12 16:04:39 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-1188011527.docdoc abffd9f417afcbcd4ebf00f102fbfe6f45ebfc4ce14815326ccb910dfd782cd1Virustotal results 41.94% Heodo
2019-12-11DOC_AA4426232136HU.docdoc 139b05a61272b421d4e9e0f4f9890837810349b07207f762cab5c4897a33c002Virustotal results 41.67% Heodo
2019-12-11KSB_EK8272523093IC.docdoc cedec09a05fcc90ba1bf5b84f0a2b0ea2f384029fb3d280a67442d359d3885efVirustotal results 38.71% Heodo
2019-12-11FILE_86756354.docdoc 90e23974d581520e1b57be4e012a78aa866183d2c77fb67d3c2458746ca41481Virustotal results 38.71% Heodo
2019-12-11O_477317863021221983.docdoc 786eabb4f96ccf74790c24189c6f33dfb54bf75d78055fb4d8c39e979a97fd7eVirustotal results 39.34% Heodo
2019-12-11E_74212243.docdoc a13264f95b1eb3d0145e1a2c7406e2c176bd66071d5121075992b1d712e753a3Virustotal results 39.34% 
2019-12-11REP_PS5339403600XS.docdoc 2fc9cb2f58be7de71d8abff77a2d9f65f61bfc1a003dd3324f062396b4feaffaVirustotal results 37.29% Heodo
2019-12-11R_PO_ 12112019EX.docdoc 339eda06c52e6d7b48107857f065a87c47c5a5dfe37d11ab8bc156d5e81cd2d3Virustotal results 34.43% 
2019-12-11PO_ 12112019EX.docdoc b4eaf914ccc446ead4b90498e82aede354a3f4235774baab829ac5cde833771bVirustotal results 29.51% 
2019-12-11YS5965573667WM.docdoc d5c9c16d38cf7070fb8014414a6633ed14e7f0e1c4569615dc416a01e259724eVirustotal results 25.00% Heodo
2019-12-11FILE_44799348.docdoc 90348b4d3ac94dbc837178f28d608e0d5f841267ac43e98cfa355e8973c34896Virustotal results 49.18% Heodo
2019-12-11NI7ECJRR2R44PZ.docdoc f5611c378395ec709c8d53b044b5e5c7eb33eb9ee2c49363330618c368666532Virustotal results 46.77% 
2019-12-11B_70793052.docdoc 1a15dbb9573d4715318740a3d2a70ae5fd0d3ed5d3f349dd68ff15fc8f65d3f2Virustotal results 44.26% Heodo
2019-12-11FILE_T1XUT9OIBJAKH9.docdoc 8832de54848c35df3e32e0b7c4ed84d791e62699015b5298d78759ecd543a4e2Virustotal results 40.98% Heodo
2019-12-11DOC_NNH_120119_GOR_121119.docdoc ececa128a027e4dcbd41d97bc3378c242a9701e8c583b0587b867621efb1503dVirustotal results 35.48% Heodo
2019-12-1154671975.docdoc 80e2530d3d5ca8a19d530fea03a6571390a32baeb4caa764ffca13154112df8dVirustotal results 34.43% Heodo
2019-12-11V92PT4DG6L9893.docdoc 1b4dc64e86c2a8d112ea18c3528bf6a9d51d273c5ae78456abfdd2368cea5485Virustotal results 31.67% Heodo
2019-12-11DOC_54499265.docdoc 4face44e712880190ed46611d9e2c94b7fddc704e8580accb2f4fec0e02692ddVirustotal results 31.15% 
2019-12-10YO_HCX89H6X0T1R.docdoc a4ae6d12de46e63e0cd39c07e9a2d18a416348796063aa31f847409495f074d9Virustotal results 31.67% 
2019-12-10PO_ 12112019EX.docdoc a26dc8a554ee1fb2a297968a6dd0c3908bbc7149ec9df10b6ce145ee4fb73318Virustotal results 26.23% Heodo
2019-12-10FILE_47222412.docdoc 44fbf4ea9f5e37e0eb42081211baf00263af7403ebb3691ba77e977bc488da4cVirustotal results 26.23% Heodo
2019-12-10BIJ_120119_GBW_121019.docdoc 78c50ea898da14b8a184493ba20f1a17c200aa20cb59e4e31b89f52c4c887799Virustotal results 29.51% Heodo
2019-12-1013066506.docdoc f59f73d7fbdf5f55bdbfb25723195c405ff709e47d9142b62e1c913f849118dfVirustotal results 30.00% 
2019-12-10WCP_H2FH14EZ6.docdoc 0dc277af2e541486a5da636b5ea00cce26b49a8f2ccef30fb0fa7a74f607c66fn/a Heodo
2019-12-10PO_ 12102019EX.docdoc 5a0b309976b939df56f64d6e406cd85c619641b452b69bc6e74582f6eb263a97Virustotal results 26.67% Heodo
2019-12-10FILE_39RMCBI687VP6J.docdoc e957d0caf7e733a850d49f34c1966ee538a06b090606efe7d132201d72c2d4e2n/a 
2019-12-10REP_290710683.docdoc f2afee4962b529df9ef6ac0e75eb79d75de99c2fba61bf60410116510a4e910fVirustotal results 33.87% 
2019-12-10FILE_PO_ 12102019EX.docdoc 79718b362785a78decbc3002ec938601d948de6eb2d20a024d034df58efd65a0n/a 
2019-12-10HI8528163261XL.docdoc 08ef301df4dd764b31c2ba72b9ffecaaa9ecd0e3847d007b6f7075eeefab3bf8Virustotal results 27.87% Heodo
2019-12-10AEQ_120119_XVM_121019.docdoc d819077d2af92f3fa0cd3c935a6e0e595cd90665dac5b5ec8ae6e66aacc8d303n/a Heodo
2019-12-09DOX_4016948388612942463925.docdoc 79287e4f096f96eaa72cc42b541f8c5a2dcea19bd5c90da3543d79b25447ad26Virustotal results 25.81% Heodo