URLhaus Database

You are currently viewing the URLhaus database entry for https://waksurgical.com.pk/wak_admin/rUcb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303656
URL: https://waksurgical.com.pk/wak_admin/rUcb/
URL Status:Offline
Host: waksurgical.com.pk
Date added:2020-01-31 05:04:03 UTC
Last online:2020-02-06 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-31 05:06:13 UTC to abuse{at}ripe[dot]net)
Takedown time:6 days, 17 hours, 23 minutes Bad (down since 2020-02-06 22:30:08 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-03Inv_VWN4670_333282.docdoc 44a34f2eeda9ec1ef09ec3ca96938381479b3fafa65ba020357fb3b65106c5ecVirustotal results 58.06% 
2020-01-31INVOICE-UL508_5305412.docdoc 1c1ee91ce47a73525fb005c941777860af76c0ce946b7e56c26d920e9cfd2c25n/a Heodo
2020-01-31Invoice-TY257_44289471.docdoc 3e43537c29e5174e6e982ff2cfa6b7752413a26de10839b58420ceb8a425c316Virustotal results 28.57% Heodo
2020-01-31Invoice_0_35229489.docdoc b777b2c1bf49b5a05bd8241ae61fbcfa3c3c96cd899ef9ff4215bc6121945da2Virustotal results 22.22% Heodo
2020-01-31Inv LLFO9_858888.docdoc 39749a5fa62f593521a2251acfa4e36b1fbd1e36cb9dc73834157fa917c51698Virustotal results 27.12% 
2020-01-31INVOICE_VE1099_884617.docdoc 8e0afd2fa4abbe847f9ff21eb7ac55c920eb69a98ebf7d214cd28aa32d5a5eccVirustotal results 20.31% Heodo
2020-01-31Inv-YON53_655542923.docdoc b7240479fd2d092d581c72b25531ea78df9956fb2ea6457b82a34c9c45986bb6Virustotal results 20.31% Heodo
2020-01-31INVOICE_ESZ7_059373.docdoc 9d887063a7f3798027fe7987b0bc2141ddefde963883c48e1d3ad602fda96e0dn/a Heodo
2020-01-31invoice CQ21_273055.docdoc 1588ef587024ad7de73a0791fa28080025d2b56083263d8c9a597c2a4526ef1eVirustotal results 20.31% Heodo
2020-01-31INVOICE-SQZ21_82509767.docdoc 64fed04221b3089f9ca965d7265619bad9d87b2d65ce2f55c04e3f3f95c5db4dn/a Heodo
2020-01-31INVOICE-XJ0658_873984656.docdoc 1fdae9fc6aa69ff362c050d3b72b7ea035f4347be47b332d1cf733a6a60ebf62Virustotal results 20.63% Heodo
2020-01-31Inv_XSDE98_638630.docdoc 605d7a3139166d8f5ef7e7c7acea745d2c208df433a07e161d991fd71275e763Virustotal results 34.92% 
2020-01-31Inv-PZEH95_644680427.docdoc 84d46bf763331a37dbbb8ad419567136746910d9f1f9de72be0ddb3590786396Virustotal results 36.51% Heodo