URLhaus Database

You are currently viewing the URLhaus database entry for http://fashionfootprint.nmco.co.za/wp-admin/i4d-uieze-679/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300832
URL: http://fashionfootprint.nmco.co.za/wp-admin/i4d-uieze-679/
URL Status:Offline
Host: fashionfootprint.nmco.co.za
Date added:2020-01-29 05:21:07 UTC
Last online:2020-01-31 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-29 05:22:02 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 day, 19 hours, 23 minutes Poor (down since 2020-01-31 00:45:26 UTC)
Tags:doc emotet link epoch3 GandCrab link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-30Invoice_KBG08_591427.docdoc b93c176b25e95c8538cc6e80bf1dca7b57ab9a7fe306415caed9989f1c306dd3Virustotal results 33.87% Ransomware.GandCrab
2020-01-30Invoice-J5870_03546999.docdoc ea0054ea77bae531dfe21c9c57ed960e3fdea5d9d5472e752c8cb6e12589e6f1Virustotal results 35.94% 
2020-01-30invoice AD5_588838.docdoc 70029b2efe245977665727cabe746a92f951297bf034a85f96c12a828c18a682Virustotal results 38.10% Heodo
2020-01-30Inv-2_45940937.docdoc 9440498706f2d925d78ed85c677ee615fe3fdf05c7188cf59cadf543e59e0c32Virustotal results 32.81% Heodo
2020-01-30Invoice-461_380062806.docdoc d204a8808c41d9dbf3ad604139c838f916986ce563143b7e41b33c85d22d5973Virustotal results 31.25% 
2020-01-30Invoice P8_781883.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 26.56% Heodo
2020-01-29Inv HR711_02529313.docdoc 3025dd0f7c5bcce361eb76f350f7313e70bb8d2b908d2edf67b9494b934c8f7fVirustotal results 26.98% Heodo
2020-01-29Invoice QV903_6731235.docdoc 3be00db967f63065494037f5de7659deb23f83c948d103057222421fc50cc775Virustotal results 28.57% Heodo
2020-01-29invoice_WW9_231329.docdoc b14d70827d5d668aeb31e94be512fea9fb38ead8ec12cdf7617616801c76b6e9Virustotal results 32.26% Heodo
2020-01-29Invoice 36_311989391.docdoc b9b47debd4d9fb932401d580847e8c3f82b770c5163dbc7d405aefb5cc704a1bVirustotal results 31.75% 
2020-01-29invoice-359_200069494.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29Invoice_FS44_921529758.docdoc 1ba609c2095cdbef36a0e219af3617879554508243a6dfd58adaf935ed238105Virustotal results 48.39%