URLhaus Database

You are currently viewing the URLhaus database entry for http://koogaya.com/wp-includes/sites/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415377
URL: http://koogaya.com/wp-includes/sites/
URL Status:Offline
Host: koogaya.com
Date added:2020-07-20 16:49:07 UTC
Last online:2020-07-21 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-20 16:50:03 UTC to abuse{at}linode[dot]com)
Takedown time:1 day, 4 hours, 13 minutes Poor (down since 2020-07-21 21:03:26 UTC)
Tags:doc emotet link epoch2 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21CORT_PO_07212020EX.docdoc dbda4797cc002eeb66a87ca2dc004b353d72aff451eb3ba1010bd900cac133ddVirustotal results 33.90% 
2020-07-21KE_PO_07212020EX.docdoc 25d8674a9a9f8dc39e05c8625561abfa731d499fa4fcf8ef72bb9dadb1d4c156Virustotal results 32.79% Heodo
2020-07-21INV_QP3053703225RZ.docdoc 3272cc94248da1f2887200825c05ff98d655ad34c77c5f92e87ffca784324a54Virustotal results 32.79% Heodo
2020-07-21DOC_PO_07212020EX.docdoc adc75d7a700b766503c50f538a24148656ae2c500683944ad15c8a2c8e42b567Virustotal results 31.15% Heodo
2020-07-21806674202578.docdoc b2dcd1d5ee235a978ccd72a68fa2448f80577a051cf78c994fb62d41e7932e39Virustotal results 31.67% Heodo
2020-07-21BG1Y5E3XLQU9HL.docdoc 6acb37f46741819ca10ee4ccb7f88dc94b5dc36a3a1c5c366450d76db4b42a6cVirustotal results 30.65% 
2020-07-21REP_80949148.docdoc ffc575665829ae7905ee6e5f2194883080c4ec8d2fa69ac1770319767a1b5456Virustotal results 31.67% 
2020-07-2109196536.docdoc c3db961b04941123b6924d69f2c5b149df9b54835cffe9dc0f693fd0dfca31bcVirustotal results 31.67% 
2020-07-21INV_PO_07212020EX.docdoc 15416a6fc11e7393653dbfbadaf3a03a0948ecfa7aef70fa367412c3b68d5eden/a Heodo
2020-07-21W_SIB_070120_VTJ_072120.docdoc a543b622ebcc58314854fa85473ce89753b8c30877e2562d607aa9483023d16fVirustotal results 31.15% Heodo
2020-07-21REP_PO_07212020EX.docdoc cead2b444fb70319f7ad607f10b254f3888d97ee61adb8a5be9492f259718ec9Virustotal results 31.67% Heodo
2020-07-21BAL_NW2269290912QQ.docdoc 2deeb69125cd75fba93b9bc64b1defe43dc4e1ea009f2f44bc8fed64c5f2a003Virustotal results 30.00% Heodo
2020-07-21BAL_833577709584317474.docdoc 04aa8ab2ee7412b2c59325c52dbb46f1ce941b3d602ac44d01afcc1efb9c08aeVirustotal results 27.87% Heodo
2020-07-21FILE_PO_07212020EX.docdoc e59ab4e1a047866cf6ad7eea19330ef2c3ace4086662158f0e46d07333ea11ebVirustotal results 29.51% Heodo
2020-07-21FILE_57299958.docdoc eea895f78d31fab11d485cdedb1938309a53c01bcbad7657c9695879ab1f0979Virustotal results 30.51% 
2020-07-21DOC_WYI_070120_UUG_072120.docdoc e8eff9852fefe1a01b140600735f3b9abecfd2f1bb93929c8955778bb11d0681n/a 
2020-07-21INV_45463352.docdoc ace3f1e921953c5ef33479a1772138bf5c88c39e1677a8e5a78905066d4818feVirustotal results 27.87% 
2020-07-21BAL_58244692.docdoc 5f3da5a1b6d61a46a16169eaf72e463f3f5483f15213d0799b577d4684e38a70Virustotal results 28.33% 
2020-07-21ZBJYIOB.docdoc ced32d6bf400cc3bb59aa1929efa4c17228064153ca0615288fc1fefde35f11bVirustotal results 27.87% 
2020-07-21REP_SIG_070120_JHX_072120.docdoc 28d652dc57d7025b36ae37336947faf6ebf313cdcbdecbd236dedef9323f2b16Virustotal results 26.23% 
2020-07-21CCL_070120_MKV_072120.docdoc 9d29290a0e2c6f3801444df8141e4099b9d87d0d3d3ba984bbc9d9684fcb5511Virustotal results 24.59% Heodo
2020-07-21FN_BOL_070120_FYE_072120.docdoc ab0c125341cfc43f2b78b409b59b4defac478f57c6989d3197f29790d5cba907Virustotal results 25.42% Heodo
2020-07-21BAL_UQO0C39X.docdoc 281280ed257511ed8f8f2b291a83ce2978bc6e6f14c52ca9ce10540c70cf0605Virustotal results 24.19% Heodo
2020-07-21B_GZ5588894121SR.docdoc a77f0d09a07d8f85b737d25216501b343e22c4e04a6f88b16dc1ab9ea1b2a222Virustotal results 25.00% 
2020-07-21HJA_070120_PSL_072120.docdoc 78ee28005bbef4cfe7fb058b986393b6a9210ad3420ed6941bb999e6b8a25e8fVirustotal results 24.59% Heodo
2020-07-21BAL_03109406525079250582613.docdoc d40a13f38676eec40c7fc38f03d55507495374f948219045d50e6ae6af725275Virustotal results 23.64% Heodo
2020-07-21S_HXB_070120_ZGZ_072120.docdoc 2cccb5979a562d00936dba58168f63f56806a4013284bab9f2a8e84be5eee72eVirustotal results 24.56% 
2020-07-21NW7376068470OD.docdoc 8969bcaa62533ea3d1c200c02009112d2d21e5b51ec3500698935d4689d46265Virustotal results 22.58% 
2020-07-21JLM_070120_RKW_072120.docdoc 24008d212916e04542b1f308917ce152914fc98dea21a3ac690999db725ea0bcVirustotal results 22.95% 
2020-07-21INV_GPN_070120_UXM_072120.docdoc 283288b5bb193523ad2659b4cf322feea153048b6f27a8fa9673ca683bca177fVirustotal results 22.95%Heodo
2020-07-21NS_PO_07212020EX.docdoc 09828f45a3ecb9732b256236d772b4af278b4d4855c7ed217c1a7d7ea21ef296Virustotal results 23.33% 
2020-07-21DOC_TRJ_070120_QTX_072120.docdoc 49e7f3d18db1b3402794fa15a11d36c41d2857d4a668834b6178d0c739e2f821Virustotal results 22.58% 
2020-07-2179782959.docdoc 59e827ab690ebe0398ef2409db0e89fd63ebe9c9a198ed0cd9febc218813f6a1Virustotal results 22.03% Heodo
2020-07-21870186288989183878.docdoc 2786a95d643bf9b6c90e2940c4387436c45e5bcd4f88746449713a6abdfb5c51n/a 
2020-07-2130935424.docdoc 597286f6b0f26fcb3c8507833ab54e1ecd981baf7b290a4f741c6e92064d5feeVirustotal results 21.67% Heodo
2020-07-21DOC_4308516872.docdoc 660ff4d3124a99db58894556a3461eda17393ca94c27e075185e72536eb6735en/a Heodo
2020-07-2147HTQPRIO9O0B.docdoc fc2bb7719f33ff249113e3c05c4b2b6fdbc99190e250b3073295e271c553f0d0Virustotal results 32.26%Heodo
2020-07-21INV_JED_070120_OLP_072120.docdoc d604f20c04d25e448176ddfdf3e01865091590cdf5f2cd2c42eb9af7cf41c718Virustotal results 33.90% Heodo
2020-07-215002381584995.docdoc 99e6f4568c137fa746b98dfe1e68f86435c581cdbcd14c1ccc5ea04b9ff74c60Virustotal results 33.33% 
2020-07-21BAL_GAH_070120_CZG_072120.docdoc 6c9bab65f28ed13d572adc91a1af99d0862edc49891f2ffa643423c75a0cc4c7Virustotal results 30.00% 
2020-07-21INV_88989444.docdoc 9312e2d0d00f48b53f5ce88ad3c874968ebb3c219e93cf1c5848021de545956aVirustotal results 31.67% 
2020-07-21BAL_TJ9031685060VM.docdoc b5956950d2004aceecfee887e4d5435b6d7cdc6d13a6655cb5d81a7f7425555dn/a Heodo
2020-07-21INV_9LX0EEC.docdoc 4889dc2e25eb4a39c1afed23f47c68f25441da2a8a16860479a9af42e6588696Virustotal results 31.67% 
2020-07-21INV_9916126743048618915047372.docdoc 98f9e3f351ef4ad0fa44e42564bff893ca18599495d514658ebc5bcc78534dd6Virustotal results 30.65% Heodo
2020-07-21REP_232203200812566936898134.docdoc 31753fd36a9782bc8df01e639556c0f7a72a7eecc326382a981a6c69edc8d318Virustotal results 31.67% 
2020-07-21FILE_MI4AG7LM.docdoc 9953004cdba2aa71a7552b41ec9b4718f1fcf03abe1589629ce524746cece259Virustotal results 30.65% 
2020-07-21DOC_HAY_070120_QOF_072120.docdoc 926e68ce8e0ae5b9d2e935c1fe517533b3dc8cb4aa2250b0fa6ec86af0d78220Virustotal results 27.42% 
2020-07-21LL_XV9460686588SA.docdoc 7e1aeb2be52594be4df58400922f10eb753ee56699771180bd21fed441171c2fVirustotal results 27.87% 
2020-07-21LU1676041162VW.docdoc e341cca78e446c93ee00c387cee3517341c104ac0587512879a602ff58871c64Virustotal results 27.87% Heodo
2020-07-21RA4401687269YJ.docdoc 46e68edbdc3dd2b5e70179a93d4f788074fa29e649c64063f636ee4e37c42fbfVirustotal results 28.33% 
2020-07-21BAL_TCX_070120_BMN_072120.docdoc 229710df49bb17b78fae2414fe4ff138609fdbbe410dc297f49d8b7bf10ad109n/a 
2020-07-21BAL_WM5366395979KP.docdoc cff09d732ea9fe1f128dc29bff9f5d5d8ff78ea22eadb52fa4b5b8d7c056928bVirustotal results 27.42% 
2020-07-20INV_PO_07212020EX.docdoc 1d9333d44f7442890d84cbc3972b9d00c93bf1556042f7b58c1386365eae3c76n/a 
2020-07-20PO_07212020EX.docdoc 49f90436f418a86b0f4e55e14bcf74793954cc90596ad08dfb6355a1e50a8f27Virustotal results 27.42% Heodo
2020-07-20FILE_1058490753159026.docdoc 2a7edcd4009ca88459bd2ec64af866f700abb7acb68cc5b13a40315c51976df7Virustotal results 28.33% 
2020-07-20A8JZJ0XRQ.docdoc 80b27b3a7242ea8cdfbcc0d266c4fe489cc0b035fb614b755e2546c80cdfbed5n/a Heodo
2020-07-20R_ND6451669207BD.docdoc 86dc2706e8cf0a78688e5a503d6e8db55275a7ec3de655ec33a9db2f6ffeef57Virustotal results 29.51% Heodo
2020-07-20DOC_5854921829641.docdoc f073a991092d0dc2ca2d7308e64b58992ce0cb00fe5da928b65b58530c10e7a9n/a Heodo
2020-07-20INV_26427771.docdoc 4ec7f2a0359b740dbbc849705f2856818bccc8fafa5a2237fd79640e61423255Virustotal results 27.42% 
2020-07-20DOC_4B2LGXIUUKM.docdoc 53dfc48b5b049b05895bc4e2e5fca037946e69d083cdac2e6c222b76c86f4763Virustotal results 29.51%Heodo
2020-07-20FILE_71399381.docdoc 148aa06dceabdc99c7588bd48277867f3d0528fcf04463562707fd66f953045dn/a ZLoader
2020-07-20PO_07212020EX.docdoc 3886724a53ad93931a6339f285e19c703a1bb1dadd7e348ca8dfca75ad42aef3n/a Heodo
2020-07-20KCJ_070120_EJP_072120.docdoc cfb6588d9181a97aa1f93b2b9f8af82134836e916938a80a217cd03fe4294811n/a Heodo
2020-07-20P_PO_07212020EX.docdoc 401dadd7c1211dae181b8767949d274790aa4fb72e78a3d57ae92ac2cf925da8Virustotal results 27.87% 
2020-07-20MGLM_CRR5MVG.docdoc 8163146178e6d55057843fa5f0da1b851d049bf802aea69b44aaec7352be33d4n/a Heodo
2020-07-20BAL_HZMCQ2BFSHY3L52.docdoc 33c897cc3c1d11687231644af13032e24358c594f4b484a7040a3eeecfae7145Virustotal results 27.87% 
2020-07-20FILE_PO_07212020EX.docdoc 4fdba539896383e37ec2383fb569df4f17395dd40115ba8caba62127b7ebe949Virustotal results 28.33% Heodo
2020-07-20500PB4D6B.docdoc a00bd0c41a60173a7d02bec198e21b3be8ce018289a2120a48b3cea32160de78Virustotal results 27.42% Heodo
2020-07-20BAL_ALX_070120_KEJ_072020.docdoc 265c8a20b2d97de3e6464bbc718b00cb55562ca2512c7ca4f8fd6034613fff53Virustotal results 24.19% 
2020-07-20AGI_070120_VSS_072020.docdoc 021aa9ae780b058779de8a93eb224c78e1d856ebd0bf6a3de8810e1b20e88f7fVirustotal results 26.23% Heodo
2020-07-20FX_APR9QO69SN4ZHAL.docdoc f479686dfc59c7e2cf8607ef958b067288d47d2de6a92db1b0c1268b9862f42bn/a 
2020-07-2018332953.docdoc 69167697c3c077b3ca6449ae55750d1712c20bc33196537fdbbe05e463aab195Virustotal results 27.42% 
2020-07-20XVH_070120_WQV_072020.docdoc 1e146c18d65265b27e23f9ee84a8f1d20c046aa76c30ed386710a10cb0da2960Virustotal results 27.42% 
2020-07-20REP_14166432337993492.docdoc 4cf16b8ae2f4acfe07cf097092f011d77005a1289ed6b609851c04fb52dd78f8Virustotal results 26.23% 
2020-07-20BAL_PO_07202020EX.docdoc 4a12475b07d363c78dedd7070df1730851f1871bd0951f703375692801ad2f97Virustotal results 25.81% 
2020-07-20REP_PHV_070120_RCR_072020.docdoc 16a986a19d026da35781703a1baa7901b7c796b6a56c4cb47d21b741c9b47291Virustotal results 25.81% Heodo
2020-07-20ZYWN_8DEQRD4PC.docdoc dfd60a37d9d7dc24e9302548219fc2547abf5a5cf7a6f4df5812bd4c737c7f69Virustotal results 25.81% Heodo
2020-07-20HPB_070120_OLB_072020.docdoc 6184126e3453b754392ed6f6123957890870d807b6f67d16cac4116de881e3bcVirustotal results 25.81% Heodo
2020-07-20QL8HP7N9N.docdoc 0fee9dff045cb53ab19cad51113a8af4f6b38c19b46c50150f606626fd1a42c9Virustotal results 25.81% Heodo
2020-07-20BAL_52155394436040.docdoc f49f50e867c62fbba39a590c6fd467d0a6ae957409da5832c798cf31558296c3Virustotal results 24.19% Heodo
2020-07-20FILE_56823911.docdoc cab46a148c83d32a55562969c697d8f33682fca7d91c3b3980f49b2e964a5f88Virustotal results 25.42% Heodo