URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ngcdfkibra.go.ke/mail/sRxXqv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421473
URL: http://www.ngcdfkibra.go.ke/mail/sRxXqv/
URL Status:Offline
Host: www.ngcdfkibra.go.ke
Date added:2020-07-29 14:53:15 UTC
Last online:2020-07-30 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-29 14:54:02 UTC to abuse{at}ns1[dot]bg)
Takedown time:11 hours, 35 minutes Good (down since 2020-07-30 02:29:38 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30Inv-YV867-138826834.docdoc 28ad746a87c186873fd8d644a8ca704b9768959c1d8cc780bbd1e4fcec07256cVirustotal results 45.00%Heodo
2020-07-30InvoiceTZXA2_5950552.docdoc e039f53c75e931e700cbcafe41ac39dfd4673929f7f2cf333a2f722272fd240fn/a Heodo
2020-07-30INVOICE-M370-239772.docdoc cf7363d569abe51412e602a505dbb2d3604aaf97ee7c71db42e66b09224dce54Virustotal results 44.26%Heodo
2020-07-30InvoiceWBCJ553-0914326.docdoc db24098d6bd41dec460588297f00255c409f745bbe32faaf2cb6476fd44ee504Virustotal results 44.26% Heodo
2020-07-30INVOICE4257-8871338.docdoc 72244c8748d1f0b37e10ef8b0f5be0624ea7ac975aa1214281b4f326e6b2f4b2n/a Heodo
2020-07-29INVOICE-P34-4481379.docdoc 9682cb3fed20b168899452201908168de9b2c2d82530d7227a4474b8b2587eb8Virustotal results 43.55%Heodo
2020-07-29Invoice_2_3987536.docdoc 40a19219a853bbc60201d4cd4fc226bcdda0966f87f05dda562d113d65c8ce67Virustotal results 43.55% Heodo
2020-07-29Inv_XPIJ56 698591.docdoc 1a509a842e1a24c4ffe665706fc677197002dad72cf5ba4a2711e9aace8dcd70Virustotal results 44.26% Heodo
2020-07-29INVOICE_BO32-294852.docdoc b6eb1c7760e06c0bf914bc6f8d26d4aa98a1d859d71fed9d6712db95af81f5f0Virustotal results 43.55% Heodo
2020-07-29INVOICE FA5357-37601010.docdoc bab24985fa20dca7f015976c0212909f59429d181ee874074692fa835b0f604cn/a Heodo
2020-07-29Invoice L474{:REGEX:.docdoc dca65af614b79dad6628ee637674667f9dee8b395388283c22e3fca41e8afe31Virustotal results 35.48% Heodo
2020-07-29Inv_N933{:REGEX:.docdoc 42d013d9cce79a7e86da79f6dd3d25b04f8460636e45c85ec23d1a962173f389Virustotal results 35.48% Heodo
2020-07-29Inv_XNP320 012894495.docdoc 4ece79e02379040355a4ff12f9b622c675a9910c6f10d98c393b790dc0c9536bVirustotal results 36.67% Heodo
2020-07-29invoice-7-852811.docdoc dcce5b7a5bcb690a1e944e5dfe8577fe2bf2d913de0e0828825c8a3daf0d76acn/a Heodo
2020-07-29invoice-E415-448729.docdoc c9908873e05408d13895e8545fd5b9e3eb95032f5e363086b19e6a14a8ed7075Virustotal results 35.48% Heodo
2020-07-29INVOICE_L880-744764377.docdoc eedf761aed061fa63744aa541d5ddef3b7d53978fd00882cbf9fb0f88bd82550Virustotal results 36.07% Heodo
2020-07-29Inv-X3{:REGEX:.docdoc cbf7197df6cd966772e966e4e8a67f74d1b090ade41e58f80f706a071ac64286Virustotal results 36.07% Heodo
2020-07-29Invoice BLW3603{:REGEX:.docdoc a19deec65bef4fe1030b463be94b414c4b4b1bad207acfc2fd8df6bb5bbbefdbVirustotal results 35.48%Heodo
2020-07-29invoice-ZPIF7{:REGEX:.docdoc c65c81e1a76fdf4122271da9b47b9b45e0a45519719f468e7539eba8ab8f9d5fVirustotal results 35.00% Heodo
2020-07-29INVOICE-3842-55659090.docdoc ed92633dcb1b2dad6206cee946593ef3d93a891dab991b164595043fe12d82f1Virustotal results 36.07% Heodo
2020-07-29Invoice RGQ9_01129484.docdoc 934f5d399e3b3914f2c3410ad251ab6817ddf37637d4cd01aa0faabb3f39ab2eVirustotal results 35.00% Heodo
2020-07-29Inv-FUJ8{:REGEX:.docdoc 2f455cc6268ecdade0ca6fffc1663cc0afd5ba64feef4dcad85b6d26f5a6de40Virustotal results 33.90% Heodo
2020-07-29Inv-VLGO9877 825273996.docdoc d38a56d36ace7f2adafd305ed44cdd1667c68209148e46187c616be8a00c379aVirustotal results 35.00% Heodo
2020-07-29invoice-DAG4_1525974.docdoc 6ecb72b433b635a49ee2f82737cec4103d08d18e988b42d36bd1b35d175ef612Virustotal results 33.87%Heodo
2020-07-29Invoice_BP250-052844.docdoc 6c3d8011d58d421f0db32a2fbd7ff2dfc39c7fe557dedcd503aca7d97d7a1e80Virustotal results 33.87%Heodo
2020-07-29INVOICE-DD9286-4878805.docdoc 4dbfbd8a057e49274bd92c01fa9680f9b478eaf207fa1c55aeb36d7879a35b27Virustotal results 33.87% Heodo
2020-07-29InvoiceYFJC924-332851624.docdoc 4800ef4ce359d4cfcba1becb6f8f276e0e968f7184af96279a1c448b897cccben/a Heodo
2020-07-29Inv-CY46{:REGEX:.docdoc 50445a74463d73e829f22308488c8ff5b166f83d4d17025cccf6f9c634146f8eVirustotal results 35.00% Heodo
2020-07-29invoice-YHPH2-42779712.docdoc 4fcf5c5d7a3296eae7876be45da5f2043bb300507716ac8927c882b5faeb1c2bVirustotal results 33.87% Heodo
2020-07-29INVOICE_3815-0201104.docdoc 1ddd4cbe0cce870cff910c166130add090f1e48f6f6c146f30cc368b32df026eVirustotal results 32.79% Heodo