URLhaus Database

You are currently viewing the URLhaus database entry for https://koddata.com/wp-content/Document/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:295046
URL: https://koddata.com/wp-content/Document/
URL Status:Offline
Host: koddata.com
Date added:2020-01-22 17:34:16 UTC
Last online:2020-01-27 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-22 17:36:02 UTC to abuse{at}ihs[dot]com[dot]tr)
Takedown time:4 days, 16 hours, 27 minutes Bad (down since 2020-01-27 10:03:54 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24H_85747301.docdoc 17d0af0278265e68fc7bd551aea53ca47aea8455884650d045407cbddf0d0b96Virustotal results 26.98% Heodo
2020-01-24E_PO_01242020EX.docdoc e8ef32345c2e61a78f1eea641048793d7ed37ec7c09ec86f7452bbb6c7b3463cVirustotal results 29.69% Heodo
2020-01-24BAL_A7NDJJP30.docdoc 3c1909a7c6468844b58967307b5f06237d78fb69b9296e407cf9ea0079701bc1Virustotal results 26.98%Heodo
2020-01-23DOC_892830565382478703.docdoc 8167096ba1038c26ae9d1be89037b443bab5bce82cd036d5e1208a2fa48534bbVirustotal results 38.10% Heodo
2020-01-23ST_0XO2GWFC3U89L6.docdoc 65aaeeb0a72ec80b56b9de3b67fd6fe12ce700f89f08e80a9c281ba49ba1c846Virustotal results 29.69% Heodo
2020-01-23BAL_GT8089426188JE.docdoc f351e1457d7673a650544a0130b943fc10aba1ee461e398687a2d85fabb79129Virustotal results 25.81%Heodo
2020-01-23DOC_5743501953653175926678390.docdoc 5c5abae014b0b9a7ce03a1ae3d2c46c81ff18764fcd3f8e62ade1ab7c570deb3Virustotal results 25.81% Heodo
2020-01-23PAY_ZHI_010120_SEM_012320.docdoc 3d01b5634985350eb0753da8324f05a468b2e27cfb4e7d5911f3005520bfd2f2Virustotal results 22.22% Heodo
2020-01-23C_ST8822606648HU.docdoc 79950a40bf62dac08fd1adbb9c8aba2b8db0e05de9829d485ac3a51302d546a8Virustotal results 20.97% Heodo
2020-01-23DOC_43612856.docdoc 87375ae81a73bb3dc7f704b3e7e62e3e496b286fa24c145831637953f4bcd132Virustotal results 20.97% Heodo
2020-01-23PAY_PQ6820207491RI.docdoc 627970068806ee557b861c46c5f66f04f0985ad9caddd21dc3c8e4682108042dVirustotal results 22.22% Heodo
2020-01-23INV_WP1443760910AS.docdoc e50ca42cece8459c5ed1bf0713f580775a5bea5fd9384b1e5f284e52f2db08b1Virustotal results 20.97% Heodo
2020-01-22JYV_010120_SWE_012220.docdoc 69c30ae1f274f4f7aa2273b592797c11b0441a1509a548ee212c4b86bbce9780Virustotal results 30.00% Heodo
2020-01-22OW5805872385IQ.docdoc 09ba2c714fe341925320bc402db84ab428a6d8eac27a70d68cd6cf9a0ca714cbVirustotal results 26.56% Heodo
2020-01-2289636699.docdoc 1acea02225c6650692c85051717ea09e03791a57fe39ab10730263373f7fbde5Virustotal results 28.57% Heodo