URLhaus Database

You are currently viewing the URLhaus database entry for https://www.netkafem.org/wp-admin/maint/tku7ax/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:291003
URL: https://www.netkafem.org/wp-admin/maint/tku7ax/
URL Status:Offline
Host: www.netkafem.org
Date added:2020-01-17 14:56:08 UTC
Last online:2020-02-04 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-17 14:58:04 UTC to abuse{at}ovh[dot]net)
Takedown time:18 days, 0 hours, 1 minutes Bad (down since 2020-02-04 14:59:48 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18UExrLjsB.exeexe be403ce2d14f38b66528d438457927218f1aa44a68530bf46b2703da75dcc8bdVirustotal results 26.76% Heodo
2020-01-18e8i.exeexe 0eb1a5bf7abf9512627c97dc285081b71038c5d821bdaa1bc7f92fe7158761c7n/a Heodo
2020-01-18cryKBwwPTzk.exeexe b1e1931567195640c4e361cefb4e3ebc2b3588f2ff209e4e441db4284cb9111bVirustotal results 13.89% Heodo
2020-01-18G45iKjYL.exeexe e9a40a3dffdf4520b286d3a3ba1c9a2ceb395459ce561b65121595086683eddcVirustotal results 13.89% Heodo
2020-01-18R.exeexe 68e699b962af409b5e0cec19f0670991fa5b2dc59672c91cdc4f7a59c037dbf6Virustotal results 9.72% Heodo
2020-01-18DTCh3niILsAY5at.exeexe fca4b4ca521eb7bb649c5a2729c56d682cdde4b05fdffaca4cb1c2fed9850681Virustotal results 8.33% Heodo
2020-01-18n8Ch.exeexe cbf4d162acf55c6e5bdf5f80b313487426ecc6066306236cf8a95f7995b40d6bVirustotal results 8.33% Heodo
2020-01-18zJZgyWm.exeexe 34b5c666e95d914089e1b988c35bb69a2a9d3685a5460d4cf632881f8621c3beVirustotal results 9.59% Heodo
2020-01-17xx9m.exeexe 024c315b15a1a1876ffea2adc9de974bf1c67dfc265fd823290b7aa3e6694ee4Virustotal results 8.45% Heodo
2020-01-17oRLOqbqGVB.exeexe 999662e3a8158d3cb895d6ebec42d15872ce9b3fac2aba0ee2aa28ae5d233b57n/a Heodo
2020-01-17WahoDh7Gqb.exeexe 65fe970bbdbbd368cb55743016bd9590ff42c9b2152052d33316912c9c80c87aVirustotal results 12.33% Heodo
2020-01-17T4aVeAD3kQtbvfgD8Qpr.exeexe 7b8672b4397bb9300e2b48400945727108f27aad2a32042f1b30494b8c2b3eacVirustotal results 12.68% Heodo
2020-01-17JARJ7.exeexe a81da16101b9696765cac5839a458492a87d07e8e0fffc336b96fb256de0f66aVirustotal results 13.89% Heodo
2020-01-17p2f.exeexe 6a80efcf19fe0a6c61519b4f5147dfe0b62627abb84d29e7e0cbf1f243248064Virustotal results 13.89% Heodo
2020-01-17AaWFiKp8xqYLLxm.exeexe 896ab23df38df795c3f5fe4cf3adcb617334b38115d506cd4c0519648afefc76Virustotal results 15.28% Heodo
2020-01-17hDF5CHH.exeexe c352a5d56fd27225116d5f2d09003be016a2e09bb864a19e8cb0f37ba7946c11n/a Heodo