URLhaus Database

You are currently viewing the URLhaus database entry for http://148.70.74.230/wp-includes/kk4kmb-5fs5-11/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:301111
URL: http://148.70.74.230/wp-includes/kk4kmb-5fs5-11/
URL Status:Offline
Host: 148.70.74.230
Date added:2020-01-29 10:18:05 UTC
Last online:2020-03-02 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-29 10:20:03 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:1 month, 2 days, 19 hours, 41 minutes Bad (down since 2020-03-02 06:01:26 UTC)
Tags:doc emotet link epoch3 GandCrab link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31Inv_UQR1727_9701557.docdoc 44b0100daa5d7db6900911e8ae9c923d3c3d3490dbc7be73dab2f3206a97b74aVirustotal results 20.97% Heodo
2020-01-31INVOICE-78_588492810.docdoc 5fc58dd1b38642a2abbc2ace5bf733f212797bc0272a7f98e48e334c75ee37fbVirustotal results 20.31% Heodo
2020-01-31Invoice Y5_616818487.docdoc 1fdae9fc6aa69ff362c050d3b72b7ea035f4347be47b332d1cf733a6a60ebf62Virustotal results 20.63% Heodo
2020-01-31invoice-MHO2_591139.docdoc 943444f98f1bb22118cddf2198722733aa216ad0aa313ece459ae6e268a9e2c0Virustotal results 35.48% Heodo
2020-01-31Invoice_IX9807_9789757.docdoc 813226187f75c12909c10d00dfafe96c916ad768979a68def760048753fdea9eVirustotal results 34.38% 
2020-01-31INVOICE G15_5046030.docdoc ee1131887f27be7f3d89f2b3a3079353cf3e72f8ef304b948dec44e635310cecVirustotal results 34.38% Heodo
2020-01-31Invoice-48_0144444.docdoc 5f956252e9f433a4b7675b2422ef016eac5627672a114bfafbc0c667a22db5ddVirustotal results 34.38% Heodo
2020-01-31Inv-FC866_858053790.docdoc e663621ff749e2033b4a4cda21d7cb98e6a4efbb1c21080b5238c718e9000b4fVirustotal results 34.92% 
2020-01-31Inv-ZJQ7_2623730.docdoc 2a154df78f570ed8acf939ecc71aa078e047b4a0b7cadbcc449df5c0d3f0f665Virustotal results 34.92% 
2020-01-30Invoice-QOWE42_95091971.docdoc b93c176b25e95c8538cc6e80bf1dca7b57ab9a7fe306415caed9989f1c306dd3Virustotal results 33.87% Ransomware.GandCrab
2020-01-30Invoice-859_701436825.docdoc 9755ef1672fe2fea84ded8999cf71bd62d9a3873bd4fa6ddafab57f59f0527f4Virustotal results 33.33% Heodo
2020-01-30INVOICE_FTY9720_2495204.docdoc 55e09691a61d983f8bb5cb7d81ca1c07171d3248c62cfcd4f3b1a89f5e9a66f1Virustotal results 33.33% Heodo
2020-01-30Inv_H9332_641429660.docdoc 68ddd33bfa87185496120195d7e4007b09c04f658553fb64e558b89269d70492n/a 
2020-01-30Inv_JGJ85_34131677.docdoc 9d23b6da889229ad96e4d4ac90dd6c382fca9006273b8de6254bd3fe1415f403n/a Heodo
2020-01-30Invoice_ABYQ3240_783607436.docdoc ea0054ea77bae531dfe21c9c57ed960e3fdea5d9d5472e752c8cb6e12589e6f1Virustotal results 35.94% 
2020-01-30INVOICE LQG3463_15572132.docdoc d56e776237f0e2f1be46e032a21e425c59b7e0269fdb96d3cf6ec91326785b19Virustotal results 38.10% 
2020-01-30Invoice-OQ5_01580470.docdoc 35b7d39e8f33f3118f3d205355b739038483d471119ac6d7712d92ad982c756fn/a Heodo
2020-01-30Inv_N140_6971499.docdoc 4a3077b819873dbaed2f26fd4cddd843ea14f4c339f797b60eae4543fe33971fVirustotal results 31.75% Heodo
2020-01-30Inv-WM76_907463.docdoc d204a8808c41d9dbf3ad604139c838f916986ce563143b7e41b33c85d22d5973n/a 
2020-01-29Invoice-JED4684_701276.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 22.58% Heodo
2020-01-29invoice CV8121_73624139.docdoc e14bd51bea91be160aefdfd75c853ce85ef348e87400f0d1e14b64c7d46eb748Virustotal results 33.87% Heodo
2020-01-29Invoice_RR7_472850760.docdoc 8f114fa9732298d525aa216d90905f24142f129d79e62500f139a3c09db00fd2Virustotal results 29.03% Heodo
2020-01-29Invoice-O275_112541.docdoc 4491676350c083084299affa5206946e8a9d6b63632f236d119e24cbd1239a38Virustotal results 31.75% Heodo
2020-01-29INVOICE WW958_856742.docdoc d965b7c533614e4ad1f1a9090edd5e83a4f4aae50a67b1ab1158ceaa31cfe7c0Virustotal results 29.03% Heodo
2020-01-29invoice-GGX00_0944996.docdoc 7522a47f398818f54f95582e8d122a7bbd81f69c9807cc61fa12d0fc15a2e39bVirustotal results 27.42% Heodo
2020-01-29invoice-NF681_16033569.docdoc ae350e475f5f34203313d523d6a5b8eec86357ef06ca6c9cc222d2c353506387Virustotal results 26.23% 
2020-01-29INVOICE-4783_553152.docdoc 19f29957bde797c4505244aec4c78ca3ff7e264967215abd6444d9f7c31da7edVirustotal results 25.40% Heodo
2020-01-29invoice_4_07321292.docdoc b14d70827d5d668aeb31e94be512fea9fb38ead8ec12cdf7617616801c76b6e9Virustotal results 32.26% Heodo
2020-01-29invoice-XN6715_803071983.docdoc b9b47debd4d9fb932401d580847e8c3f82b770c5163dbc7d405aefb5cc704a1bVirustotal results 31.75% 
2020-01-29INVOICE-R0007_121959.docdoc b49c9eba58537f8d856daded80bc9493a83c508d73423b98686d4e8b232d61c3Virustotal results 32.81% Heodo