URLhaus Database

You are currently viewing the URLhaus database entry for https://www.netkafem.org/wp-admin/maint/swift/icakxgqw/kg615o3-587-77-smr5-t0jdoi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:293149
URL: https://www.netkafem.org/wp-admin/maint/swift/icakxgqw/kg615o3-587-77-smr5-t0jdoi/
URL Status:Offline
Host: www.netkafem.org
Date added:2020-01-21 02:24:06 UTC
Last online:2020-02-04 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-21 02:26:02 UTC to abuse{at}ovh[dot]net)
Takedown time:14 days, 12 hours, 34 minutes Bad (down since 2020-02-04 15:00:04 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-23PAY_PSIXY979EGC.docdoc 5b5c673977368413117352d249d99d185bbc339181ec3953a208adaa6b0214f4Virustotal results 31.25% Heodo
2020-01-23PAY_PO_01232020EX.docdoc e63aa1c3401d847d86e7d7a0183b1b09932060991feb79d6e2b775a27f30c36bVirustotal results 30.65% 
2020-01-23AU4019563902VH.docdoc c902819826aded735fa4ea8025d726e7b868dbee374343fde8e6b5a3fe6733e0Virustotal results 28.57% Heodo
2020-01-23IXBZ_QQ1259330563DT.docdoc 1fc298251ecbc967c1a852ae8549568c2d11d20ff8c2fe5795d71c0701dc0d1bVirustotal results 27.42% Heodo
2020-01-22REP_3571002673080507729343852.docdoc 29487cc347b96694240c5003b2fde7f8e509ac63ea9365249aa1a23c122502ceVirustotal results 27.42% 
2020-01-22XIXE_AS8801324867FT.docdoc 160af171ed50cc482af73eb1c1e975595087813849ae0bf122ad3b24abcf8696Virustotal results 26.98% 
2020-01-22BAL_07821426.docdoc c551f97351c13e0f158f87d3c11bbdb5b9f2b2b10576509755d225e3f3bf46c7n/a Heodo
2020-01-22BAL_50738444250.docdoc 97ebcfa4df6f809a741a2027ed56f4ca2f814097ecbb08eb5c4e6788a3a1305aVirustotal results 26.98% Heodo
2020-01-22Y_ME7726024201MF.docdoc 1edd209142cc223e891e8dd444c153f50de141b3239f20dfad8f44bf278752a9Virustotal results 28.57% Heodo
2020-01-22RP_HY4127323551GI.docdoc 6ae88a641c3cf227c2db6bdc728158b97d4b9f912b642fc6c41e453eda9c27b4n/a Heodo
2020-01-22BAL_PD6869077300HM.docdoc 76945e1b8c864c6a733fd32287175ef1d964299180918949c4bfcfb1566e53e1Virustotal results 27.69% Heodo
2020-01-22DOC_PO_01222020EX.docdoc f953335933b0bfdd1a511f17473513146e45bd32b38f8279a759eae1d2dd42a1Virustotal results 33.33% 
2020-01-22BAL_TRL_010120_YMT_012220.docdoc 4c80edcbb0062e3b1f50fd07de05afa15805203131f6a34ae1dd4f4591dfcf20Virustotal results 30.65% 
2020-01-22FILE_PO_01222020EX.docdoc a8e86ce1edef7bad9f725d8f9b127d50d0a80a4e3477a2294f61bd2be001bfc7Virustotal results 31.75% Heodo
2020-01-22POA_010120_LQM_012220.docdoc cd1d589c80332498c1497b75ec3532ce643fa739a27ce32fc53e53551562361eVirustotal results 30.16% Heodo
2020-01-22ST_F4KXRSF.docdoc 8866f17525978f2cec2f21518499d6d84bd654adcc1bfc22f90d7fc47eddd406Virustotal results 29.03% Heodo
2020-01-22FILE_6IQOFCUI80EPOAYM.docdoc ae732e2481c442c721b9c70bbbafde35384fc2d9c8e8426e67eabd9863b3e009Virustotal results 26.23% 
2020-01-22PAY_81914938.docdoc 65a1628ef9bc3362fb43fdae7776948360a3fe80ae3fb6f8f03a5d2a68e8694dVirustotal results 27.87% Heodo
2020-01-22ST_BCZ_010120_QKJ_012220.docdoc 134850341519ad670ef48fcddc9e953e257c461ddb9e870b15510d02269a5e5dn/a Heodo
2020-01-22RP_PO_01222020EX.docdoc a85351653bf9a0c8c76db9f4c1076418ba4fface5c3a7f373d29186bf46732e0Virustotal results 25.42% Heodo
2020-01-22DOC_OXAZ0O8.docdoc 6386c6fdd8a1eb4f6fc7bf14c51236c53a6d7dc8419ff7add51d3a75c46d3610Virustotal results 20.97% Heodo
2020-01-22SW_336964860192547386556568.docdoc 8205eac5713b6e780f44ca0ead54f7b14258c7553e717184eee2ab927d901095Virustotal results 21.67% Heodo
2020-01-22PAY_OWC_010120_UYY_012220.docdoc a0855eab3940a455dc8d9abb41fe9a44d09eb1153e79da6e813565d5dac82f24Virustotal results 19.67% Heodo
2020-01-22BAL_NN2308497074VO.docdoc 8bb40f94230c4779d38d4849765d3c668b37c66d257ecbf89fe76f042c850958Virustotal results 19.35% Heodo
2020-01-22RP_79511615.docdoc f1c1ff6da408d3db36973e88b9e655de09333c432f5360ddf9ba275f6b330d46n/a 
2020-01-22SW_PO_01222020EX.docdoc 368d63a431bc9d979e6ad0775f7327956d973a19119aae25175bae3b42ce1c5dn/a Heodo
2020-01-21RP_LBH_010120_NKV_012220.docdoc 97e30189b2d55dda8919c75177d0ef9f6a7922a82a9d14b90f334d3a04a281abVirustotal results 19.35% Heodo
2020-01-21FILE_397775412477.docdoc 5fd6ec312654d263689e335748f1296c2e1cc8b5d84f2f28e4f0af1686d55715Virustotal results 19.35% Heodo
2020-01-21REP_UW7893401603TF.docdoc 2b0dc7a3f1517e44bdc07ad1f4e244e973879e977697384256d409300c3d8396Virustotal results 19.35% 
2020-01-21PO_01212020EX.docdoc 87f198aab109437e66b753398ed36d61115bcd349c900750ed31b89952b9f3bcVirustotal results 20.34% Heodo
2020-01-21R_11581539764496002727898.docdoc 0ac7a98f0bbf451a51cb75aa5b065d00e46c0860c7cd1c90a194e8a40a56aa93Virustotal results 19.67% Heodo
2020-01-21ET73QXPOS3TFHZC.docdoc 2590c9b4152ec806778205a6eef85900e2117e4d70c59de1f5f7546fdc255070Virustotal results 20.34% Heodo
2020-01-21PAY_92235544131067905208904.docdoc ce7997a982cda9e7c2591ab8566bbdc583595e079b68bb121820bd81bc0f5c7cVirustotal results 20.97% Heodo
2020-01-21INV_87X0N3Z0EGX6RTTW.docdoc 61507dd50818260d95aaadcd23ed886f445d5c1afe613e53e1633c08ee5bdab8n/a Heodo
2020-01-21REP_MK9909891006CM.docdoc dfe2815ab27e806aa38d3a86f0c43e7aa9fca4b580604411f1d339c734d038e3Virustotal results 24.59% Heodo
2020-01-21HE_903986681.docdoc ac0a043ddb5cd2ef939889a7dface6d1464766b504e1cf491e8d05d6983e0d12Virustotal results 22.95% Heodo
2020-01-2162940877.docdoc e4932995a94e0c841f96d023503d1a1bb8e8278fe5478a736b9a4cbc83283ab7Virustotal results 25.00% Heodo
2020-01-21REP_HW1194191739PL.docdoc 0e9e43c0429b560afae123776797b95528cfb7b3564487c82a25a57c81570144Virustotal results 22.95% Heodo
2020-01-21BAL_PPS_010120_MEP_012120.docdoc c5a685afc7986b2e868818c0a531726711bd19cb5e60ed99da8ccefce4cc95d3Virustotal results 22.58% Heodo
2020-01-21DOC_72637105.docdoc b8083992ca8cf08ef3353bdea04c93eaeb2c2d9a0840119f89868e27b2261a32n/a Heodo
2020-01-21REP_40462933236608.docdoc 1a54c57512dbcac388648552cf8ec7536827af1c60f032cf6b3b6fc3197033c4Virustotal results 38.71% Heodo
2020-01-21LFZ_FF1028662887BJ.docdoc a02cad1bc2e1e070005d123abd1ed33ef20a502d65d597145a77c7f1983a8888Virustotal results 37.10% 
2020-01-21INV_040990140398648.docdoc bab6c6989935ad3265af5fe641a9070d85fafb84e2148f1eb356282fd2a51aecVirustotal results 32.26% Heodo
2020-01-21Z_DHQX43COQ1CU9.docdoc 97f55cd9a4169904bb304d25dec8f7e772082dc8c1aa3468206307bb6e95df26Virustotal results 28.33% Heodo
2020-01-21Y_Q1HGB6PY.docdoc f05c2025b90ce115551639e825f3a570b61147aeba158c50735a16f8622541abn/a Heodo