URLhaus Database

You are currently viewing the URLhaus database entry for http://library.udom.ac.tz/wp-content/ipR/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:289838
URL: http://library.udom.ac.tz/wp-content/ipR/
URL Status:Offline
Host: library.udom.ac.tz
Date added:2020-01-16 08:03:07 UTC
Last online:2020-02-10 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-16 08:04:03 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:25 days, 2 hours, 25 minutes Bad (down since 2020-02-10 10:29:13 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-20invoice-821_917905623.docdoc 31ad3169f11c87da6ccbc71737617e56190dff422121b45ebf0a41525a87273aVirustotal results 24.59% Heodo
2020-01-18INVOICE_3_83348863.docdoc 2f90590da13be020cab94f6054224224af5d674bb07964796cbb051cef5dde3aVirustotal results 27.87% Heodo
2020-01-18INVOICE EYLR075_100243646.docdoc c0ddf7ec4f4905aaafd9371d7d00d8bd21bf9f5d9d49403591e1cfbde36925ebVirustotal results 24.59% Heodo
2020-01-18Invoice-OA7296_1851177.docdoc 83f1652682079f39835315667ec159797f69ba97e5032d110999fc7f0b6a3b43Virustotal results 22.95% Heodo
2020-01-18Invoice_ZZ1216_00667182.docdoc e70d619f1ca2594c00e8973e7268a2d2d3bb0917c2663977b998e567542fcd45Virustotal results 21.31% 
2020-01-17Invoice_UK2_47703530.docdoc d8bf43be0fa83fd0c670bf59a500ec1de69bcbffe0a2fc4a318b4e2eebe849c9Virustotal results 22.58% Heodo
2020-01-17Invoice 0689_955657.docdoc 92c85540c7e919439415aa82c133d50f19540ccf3d76526199af09ed1b2a69beVirustotal results 17.24% Heodo
2020-01-17Invoice-T57_5258640.docdoc 562abea095cfa78a34b3896d0d1c23bb11525f5c7691852026b0aaa3d97151c8Virustotal results 19.67% Heodo
2020-01-17invoice-ON46_181490801.docdoc cf8f7f9ebc40351bf67d9c14743199a531bb1c4ab1155316debc244c85a29cacVirustotal results 20.97% Heodo
2020-01-17INVOICE 56_8154779.docdoc 864035dc0e85ab49fb76ae8a004075c03e1eaa8c2694f427a2999cc5f9e6bca6Virustotal results 22.95% Heodo
2020-01-17INVOICE_PGQG7_8775809.docdoc 5b5d276c15b051d7bd90d0a94065b9989ff8678436c073df253abb3dc9d5f2c1Virustotal results 22.58% Heodo
2020-01-17Invoice-EJF2503_768909813.docdoc 87896962c7df598510381a91ee545e0d564d8fc19ca59620eb520eaa96173602Virustotal results 24.19% Heodo
2020-01-17invoice-SCLL9804_228108651.docdoc 02b101f1e0c6d3901cafc61ecc03bb67ffc336f5239ac8f0d0195de3d54873a3Virustotal results 22.95% Heodo
2020-01-17INVOICE_NU10_401424225.docdoc 2372e21dc0f0b168488ca6f3ba9820fe6daa998778f8ad2b9e9d0812601004e5Virustotal results 19.67% Heodo
2020-01-16Invoice_CC158_336.docdoc 8db35f574e2b6012d8df6ef0b47e6aea0b538086aa6b0ac9a41c0a0eea1fd828n/a Heodo
2020-01-16Invoice O901_2582.docdoc 1243b8bff831969783b47e614391d4b2fd0fb2ee634743a000848c76e8dd6b1bn/a Heodo