URLhaus Database

You are currently viewing the URLhaus database entry for http://www.wak.co.ke/cgi-bin/ygNzrF/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421695
URL: http://www.wak.co.ke/cgi-bin/ygNzrF/
URL Status:Offline
Host: www.wak.co.ke
Date added:2020-07-29 21:54:36 UTC
Last online:2020-08-04 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-29 21:56:02 UTC to abuse{at}choopa[dot]com)
Takedown time:5 days, 17 hours, 5 minutes Bad (down since 2020-08-04 15:01:29 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31invoice_QS2000{:REGEX:.docdoc 3d8ef147ca84e9943fdc850171e2de9c05b0db3472cd05901e4f109e7fbe07f1Virustotal results 50.85%Heodo
2020-07-31Inv-5970-775977652.docdoc c7ed06b6f4284ba3fd857f03875187654aad78683efa88d3ed984fe057d484abVirustotal results 50.85% Heodo
2020-07-31Invoice_F8-0275465.docdoc 0154af8049b8a7ec498151777f31d6e971c61bdfc439fe1a8150ad0f69c0e4f8Virustotal results 50.00% Heodo
2020-07-31InvoiceG52{:REGEX:.docdoc 5399417505ae67bdc2253943f273fe2b69fcdb71294530cbfe0cbe731a251b48Virustotal results 50.00% Heodo
2020-07-31Inv 8883-581958.docdoc 1d15a177160eef1bf592ab1b3f84d6153b13e07216de245a2ceb317635b7ada5n/a Heodo
2020-07-31invoiceM59-96698299.docdoc eae169c0ec808dcf097bfd419bae07e5c001b1157d781d90b037250ea07fd4bcVirustotal results 50.85% Heodo
2020-07-31invoice 607_16569496.docdoc cb27bed9b173d425693fe6c19d0d7502d62645a8fff074790841a362952e9936Virustotal results 50.82% Heodo
2020-07-31INVOICE MXBB848_659035.docdoc 1e253d59d5ef3aaf08431b406cd5c024476603459b847f6b40dd0f86827492c1n/a Heodo
2020-07-31INVOICE-UIS9221_192170.docdoc c8e498b47aef6cfa8fe5259b40faf397127d496992e126c2f4f6026f7945813bn/a Heodo
2020-07-31invoice-N667 914000.docdoc cee085d16cb1dec28ff7ef5bd5399111ba8a5e26623b17902866e886144c228fVirustotal results 50.85% Heodo
2020-07-31INVOICE-1{:REGEX:.docdoc ea4ec66d739ec6c93a0e5890743a01a5283b804889147308ba45d35ee1f2247dVirustotal results 50.00% Heodo
2020-07-31INVOICE-D2156 3148111.docdoc 2ab3a5f443403e9ed1928d27e4e551ab95a6532d540b98d5103f0ed8a45a75cbVirustotal results 50.00% Heodo
2020-07-31invoice-TIRF71-206153.docdoc 2789d1d3eea1e5dcb760faf9bbf395f267ec901bc7c52a67ae60133050897609Virustotal results 50.00% Heodo
2020-07-30InvoiceORVK7294_8967793.docdoc 2e24bcec136a5b896e730820974bfa9162575d275b2ee669ece097f7b195e4f7n/aHeodo
2020-07-30INVOICE-1{:REGEX:.docdoc 03ed835379b767b87a9892d1cf794cab0472025887c37ab437b2710e72f37e3fVirustotal results 50.00% Heodo
2020-07-30invoiceJMFE7255-11020271.docdoc 881c5ef2385626accbec7572c0b5c5b5cdff760f61e1bb044546983d6c3fbdc4Virustotal results 50.00% Heodo
2020-07-30InvoiceZ006_07047477.docdoc f2bef647cf5f376c3807d6693d2fcf28cd42e71629fb0cd64847604a0e189081Virustotal results 51.67% Heodo
2020-07-30Invoice-HUC4 52023643.docdoc 1c8026d6bd75a1ea091d6a6676d3a7e3bcba3b17717e21607488b9fdb762fba7Virustotal results 49.18%Heodo
2020-07-30invoiceVJKX268-6883992.docdoc f299a2c4f0ecc2e57db212cd815c6cdc02bbf1b9d409abda624fd7c2cc80f314Virustotal results 47.54% Heodo
2020-07-30Inv_CUOO1{:REGEX:.docdoc 2ccfe3cb5c9044e383e930aa33fb0e74fed092845982048455384c26475e9149n/a Heodo
2020-07-30invoice-3{:REGEX:.docdoc 37e514cb14ca3f023b15dcb7c93568c37ff32da0ba32eacbf318286053027f32Virustotal results 48.33% Heodo
2020-07-30INVOICE LU98_280923715.docdoc c26948855f4ff48cabef919e4728ee8fee5fed3d1c0a191b3bfcf7607a57e820Virustotal results 48.33% Heodo
2020-07-30Invoice_QTG79_167295110.docdoc 2c12a7e0edad866945a8690d526d40e53fb973708e021efcd252bd1178c14544n/a Heodo
2020-07-30invoice-93{:REGEX:.docdoc cc06acb431a4a55c35a64b9125b3b8637e155d4685b1e3f1593df6729c84560dVirustotal results 48.33% Heodo
2020-07-30Inv O2303_06208514.docdoc 8bfad89deb0c7bc99a6838342f6f6044ecf0031ea21397874c52b3b2a616786eVirustotal results 47.54% Heodo
2020-07-30Invoice_RUOG426-30498220.docdoc cafd2c780bab54f0e196d1960af4f5ea207d883461efe818b373828eb21e92dfVirustotal results 47.54% Heodo
2020-07-30invoice-GAJ92-395296743.docdoc 796909dd292cb26f7fd13c689c83321159681e5900bd3ffc094363465611696cn/a Heodo
2020-07-30invoice TAU06-884201348.docdoc 89e20dbcc8e8d14df0055e98cfd6bf380fa8cde12d9cbc1045ed4a521c08496bVirustotal results 42.37% Heodo
2020-07-30Inv UCJG119 2685389.docdoc 1fc84f486f34f0abdf95db1b68634335fa43314bb24e9c28c4545b0cdb1566b9n/a Heodo
2020-07-30Inv-FY13-46307319.docdoc b2b5bb52775d354ca1f715aea58d03f84ed213c90247c3ad861790ac7483b976n/a Heodo
2020-07-30Inv FZS2-1557000.docdoc 46d310c17da858517554fcf0b0167e0a7f33f71e6bb42873207343ee1ba29b09Virustotal results 45.00%Heodo
2020-07-30Invoice-3901_43161400.docdoc 57cd3c6667afd66293fe85bc6632764caa8217677ecf64f34c72677367fd9472Virustotal results 46.67%Heodo
2020-07-30Invoice_AEFI2-361899974.docdoc 8d9bb420fd3f8a710096cf3e67e7694308cf65921bc6f9ed1870825d2e1c0d02Virustotal results 42.62% Heodo
2020-07-30invoice-IU9-1619773.docdoc af2f5bff87733abafd89d9b126cbd36dcda3a98458e4f63e67eeb15aafba997bn/a Heodo
2020-07-30invoice JILM79-486320439.docdoc ced0a2a65f3695dd4cec0afa9f1e135710d7dccd015e6b539d89ad09acd8f3adn/aHeodo
2020-07-30INVOICE_MEO6125{:REGEX:.docdoc 2d52d74f498007a80c0f955b4004ffa43f9a156616527223b12166fc5e396742Virustotal results 39.34% Heodo
2020-07-30Inv RYVB3639{:REGEX:.docdoc 8e78935c6ae4c5164c54350ae754eee471aee652bbc37521c1fe2706c62303e3Virustotal results 40.98% Heodo
2020-07-30invoice2_684056839.docdoc a12c802c14ee523d5fe6b5ececa5018201d45d0f57281b23593be0117029d867n/a Heodo
2020-07-30Inv-AXX4782-8413123.docdoc 4fc258e1d97be191b9316641ade4df2be7dc40501cbdb9e2d495abfdad6f8426Virustotal results 40.32% Heodo
2020-07-30INVOICE DAVA4613-766928.docdoc c171e3eb929b57d92d6a1a2e4e81a36dc1233be6abf5dce5e51dac677ec50017Virustotal results 40.68% Heodo
2020-07-30INVOICE-Y0-5585457.docdoc b831558e10d067342a4e9ac952a95de0a3054302bc7b79610b6649784442e013n/a Heodo
2020-07-30INVOICEG98 729030.docdoc 84f1793acc6d7c229aed03c0334fcb223eb89415c1d96b08822e988c1a5652afVirustotal results 45.90%Heodo
2020-07-30invoice WLM735-421162463.docdoc 72e418e68d70107f35d0b84311d2fe8e97b317936f99994e6cbb0567b9931275n/a Heodo
2020-07-30INVOICE-X6_424078139.docdoc fd4e7761b18405677fc5c8737a34ace11283a0c1503a19a20120c9f36af7c004n/a Heodo
2020-07-30invoice-E4{:REGEX:.docdoc aa6bbf739a15097060f35839f8bedf662f371e5d1f27dfacd0bd8863b46ab1dbVirustotal results 46.67% Heodo
2020-07-30Inv-QOT119{:REGEX:.docdoc e4253aa05a6d37a3938d0a58becfa9533a305a661d68cefd0c7aa37561fa5c41n/a Heodo
2020-07-30Invoice-3897-287002559.docdoc 7579d4a1d6d4da73019950ba9cd7de417560465889ccbc12fffbebff6b87ca3cVirustotal results 45.16% Heodo
2020-07-30invoiceY6814_1587633.docdoc fcc525f6dd0c743849afb4e000a0829d47f24999eea8c8689721e2afd70df51bVirustotal results 44.07% Heodo
2020-07-30INVOICE-AO0926-461349728.docdoc 35dfa0b9a11dcd3a2920e7da86c66da6b2b94ab67c9aac6e3743e53bd3346f80Virustotal results 46.67% Heodo
2020-07-30invoice RUPQ39-01130428.docdoc 1a36bd245a9053a5742fb8aca3169f91382921c429bc62eaef3471cb4bfc743eVirustotal results 46.67% Heodo
2020-07-30INVOICE HJC54_736821961.docdoc 133d58f3c65e1886b5480e277bb845f9d97a7177d1da22625c6a977553b374cbVirustotal results 47.46% Heodo
2020-07-30Inv-094 478386.docdoc c444016d70224a2cb4808352f39232719d705243dbaf2321c3aed6cee511890fn/a Heodo
2020-07-30Inv_TMF0_8706605.docdoc f1761ccaa75c38c0b7a7816b613688bcc01590af8717fef82dc50d9620ff7838n/a Heodo
2020-07-30Inv-F0399_8487973.docdoc 47c3d5ad152badf3a17ebce781f3d060a059bdb107a1b8c7726469a95025e911Virustotal results 45.90% Heodo
2020-07-30Invoice-V6776-492790.docdoc 4e55de6543c564fb58c03b66c1d5ded780d350f7c135a72663dad5b168b28371n/a Heodo
2020-07-30INVOICE2051{:REGEX:.docdoc 2ebfcb3a012fefed6779dc9a99fefd03e27f24621cac89362926b5e589af06f6Virustotal results 45.90%Heodo
2020-07-30invoice-9{:REGEX:.docdoc 299b8c34cfaa47a3f884d83e3b6ef10c75f0552bf3b16350d44d8ca86f89c8baVirustotal results 44.26% Heodo
2020-07-30Invoice_YWDH11-527249740.docdoc 4e0a207adc8d98c528137c91938100b8095dccb87c1ce94b293ba27824b6835cVirustotal results 43.33% Heodo
2020-07-30Invoice_M2084_13387278.docdoc 9073425e395c1b7a8d42cabd461cad86cd0646bd77f042e13bcd2f98979fe12dVirustotal results 43.55% Heodo
2020-07-30invoice-OZ7-932290467.docdoc ace615571a462ffd982c237516c0ab3803378966e9d62efa0e12e5992e5c1d4dn/a Heodo
2020-07-29Invoice AR6 5015590.docdoc 9682cb3fed20b168899452201908168de9b2c2d82530d7227a4474b8b2587eb8Virustotal results 43.55%Heodo
2020-07-29Invoice-AASO5-0622622.docdoc 95a7f27115ec0027c6e80a07bfbe83181bf8cb2236bec3e8b13e7c7e59dcd3f4Virustotal results 45.00% Heodo
2020-07-29Inv_EVY4-379578.docdoc 4c620acfa4d837bab69227d52e1e1c2ad812ee779e76d3c8ae271956d8320550Virustotal results 43.55% Heodo
2020-07-29Invoice-QCBG7636-0810608.docdoc 504c84d3083058366a68b164b12c19ae0a928586ff465b3f5199ee572d5ff953Virustotal results 44.26% Heodo
2020-07-29INVOICE_3_36962482.docdoc c3377b3629b8c303b746f6c962e5cf76043bf78dfcee3f14369d1dc90e5d383an/a Heodo