URLhaus Database

You are currently viewing the URLhaus database entry for http://kmklawllp.co.ke/bin/closed_disk/verifiable_warehouse/4454466527_R7Ojkf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422018
URL: http://kmklawllp.co.ke/bin/closed_disk/verifiable_warehouse/4454466527_R7Ojkf/
URL Status:Offline
Host: kmklawllp.co.ke
Date added:2020-07-30 14:58:16 UTC
Last online:2020-07-31 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 15:00:03 UTC to abuse{at}host1plus[dot]com)
Takedown time:1 day, 3 hours, 0 minutes Poor (down since 2020-07-31 18:00:03 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31list-EL956591.docdoc 242a7cf61d7a50d7a5eb9a2a9ffd61ac47f061eabbf92f8f2d57c70eca976871Virustotal results 49.15% Heodo
2020-07-31list-EL956591.docdoc 242a7cf61d7a50d7a5eb9a2a9ffd61ac47f061eabbf92f8f2d57c70eca976871Virustotal results 49.15% Heodo
2020-07-31DAT_20200731_26161.docdoc c54a83ed7df0a40d62a865853af530ffc4372e2bf7255a43bd6e352ed5ec9868Virustotal results 47.54% Heodo
2020-07-31Doc_2020_07_31_709.docdoc 810d5899f085d1c3160e9a069dad7915609292c8666fe0e02c0438d997827753Virustotal results 46.67% Heodo
2020-07-31REP-KON332196.docdoc 3807ea27c87ef220916b55deb372a2eab386ffd18028cfee853a34521e6fd377n/a Heodo
2020-07-31arc.docdoc 4c6a9e9d068aaa2a313b10f83cb3f03ba7afdca5c5cf699fb7da411be652526aVirustotal results 46.77% Heodo
2020-07-31REP_20200731_RTO5885.docdoc 6dca66df42bd8494a68b0844baf9a74e4bbd8da25633bca4914817f18657e009n/a Heodo
2020-07-31REP-NOB77431.docdoc fe4039c80b51bb184604b056d4e86b3e69fc8cb7278e61887d8c8c63155f7cd7n/a Heodo
2020-07-31Arc-8905076.docdoc f64a9838ba01f483ffcc11baa109003b47d7055e26182f079bf5feb482256906Virustotal results 45.76% Heodo
2020-07-31FILE 20200731 V611.docdoc 1075f783527ef766efb3112e479815c4b3b867007f1dc9b8bd24fb6a5adb3d0bVirustotal results 45.00% Heodo
2020-07-31REP-2020_07_31.docdoc b932f9fcbcd3c278483655fe0f75a06f328c7b36c2ecef394d07e8413adff2b5n/a Heodo
2020-07-31FILE-2020_07_31-K74305.docdoc 4d2ba508dca9a3ce899aa342252f786c29c81a735433b98163b27a7c1f76c646Virustotal results 43.33% Heodo
2020-07-31rep-554.docdoc c5e1be1f3b4b0978b9a8d32d545c5d775db521592c4b0c41ee29dd6353cb0190n/a Heodo
2020-07-31file_20200731_C349.docdoc cd29071298cbab67d898b5cbcf4b56f1b7d725f85267037659bdd2da3083f57eVirustotal results 44.64% Heodo
2020-07-31ARC 2020_07_31.docdoc d0ccb581b7783b4608f10c7c373d9e7971531c658442d9cda6e20f62f972e964Virustotal results 43.10% Heodo
2020-07-31mes_2020_07_31_7019361.docdoc 596669e4ee62dd88d2ad8cd5b9f66d21a243874280e56566b6530cab61ed15b2n/a Heodo
2020-07-31Mes.docdoc 67ed4b0c64b53843652c30e3d24300496d59cbea3def00912b82490ae3057394n/a Heodo
2020-07-31Inf_2020_07_31_892133.docdoc e5b7ca03743efe37bb95aa3800a1a6cce4097f10559da6e89c52d20e0903069eVirustotal results 42.37% Heodo
2020-07-31Dat_20200731_5736103.docdoc 1f06f99ccaa2b0a351246decee26a614ec47a68326df652ec9f0402e359b755fVirustotal results 40.68% Heodo
2020-07-31Doc-2020_07_31-R64873.docdoc 5335d6881bf6a2b0776a89724043b6693dec8ffb4848b0c66954f6373c38cb20Virustotal results 40.68% Heodo
2020-07-31dat-20200731-891241.docdoc 9e87dfaaa75485ee7142925ae35b276c46c0c17d4d0eec4b4b7740513c84e4d5Virustotal results 43.33% Heodo
2020-07-31arc 2020_07_31 137682.docdoc 7172995d1d5b54353bce9bbad1ec7900ca7175b8a7e41e5d86bd80df42e1014an/a Heodo
2020-07-31MES_AJ03694.docdoc 1d075da8b51be2231edf1a9450db095e374e7d2200b6d3c3e7088dcad1557bd1n/a Heodo
2020-07-31file_STM0506.docdoc 258716c1b844469ef3bbd672d2b8bca6911321fb1ecda3f00eee7d1fb6cb94feVirustotal results 40.00% Heodo
2020-07-31ARC-2020_07_31-5492783.docdoc fa3e81294239894ab6d187ff561319cd3f23649f9888593ae2c7bd734af6ecfdVirustotal results 49.15% Heodo
2020-07-31List-20200731-7933.docdoc f50fb4e4eb9c8fd7caa059bb20573d67a0a47bfeda1c3d0efb6a2f4faeb77ea4Virustotal results 49.18% Heodo
2020-07-31ARC-20200731.docdoc e6a1cc45ec979b40952950438c59cd9dc2a3009a942d9fff7cd793d7518e0368Virustotal results 48.33% Heodo
2020-07-31REP 6094046.docdoc cfb9e071cc0b8abf3bfe496027745ff1085b24dafec350195422d545c337001bVirustotal results 50.00% Heodo
2020-07-31mes_2020_07_31_MTD892923.docdoc 73729cfbc98f25d4dbdecf63cd27eb82bff9057cdf78e160440e41c9d553f4c2Virustotal results 48.33% Heodo
2020-07-31Inf-20200731-62024.docdoc ec84b8ef96a741db3076da6349e1a2aeb1d497c3c7b9eb5f6ac62ab2fa8f8c68Virustotal results 49.18% Heodo
2020-07-31MES 20200731 5866.docdoc 624aa2e87b85c4c93a21bf0b764d1594ddff016da7f44040918cbcccdfb017c5n/a Heodo
2020-07-31INF_20200731.docdoc 06bb12ac0adffba3f0f1286ef26927750fbe1438a8953b91109ec4890e548404n/a Heodo
2020-07-31doc 661237.docdoc 8fa1a53141a9745f824ecea3c830850c7b798488ba6e3e33382229bf495c1d5dn/a Heodo
2020-07-31inf_4094007.docdoc addf33127e24d9d42ec8d7cf743353a7dd9f6583dc091a3120ba319e1cd75675Virustotal results 49.18% Heodo
2020-07-31ARC.docdoc 2af35203a78ab48a45126f959aa05f3037e941bc7ff22d04decb13d88846a967n/a Heodo
2020-07-31rep 2020_07_31 R48090.docdoc 61e8635da3b4dad36cbca3de124b4e2d07a5de346e069517354f0e063bb9ecfdVirustotal results 49.15% Heodo
2020-07-31Mes 20200731 ZO508.docdoc 57b075be6438184bf527bd055363a33f851ee9acb765aaff3c717f2ca6ea7d5fVirustotal results 49.15% Heodo
2020-07-30arc.docdoc b9c357adce4a39fef2bdc25779951e2f40307dade90e05fdd0f95b77cf77c786Virustotal results 49.18% Heodo
2020-07-30MES-QME089659.docdoc a31ac933ff656e241da9b1316d8b23d8b1d3bac6ee533fcfb046477c76accedeVirustotal results 49.18% Heodo
2020-07-30ARC-2020_07_31-P9284.docdoc 16312617256751866a6609cf1deb47b3605e122c7c756151d68c635960088c31Virustotal results 50.00% Heodo
2020-07-30Rep 20200731 13500.docdoc 71100778f6bc4fefc8bee7d8191d1a50ec140a1f8d30b57b9abfd2db06635274Virustotal results 48.33% Heodo
2020-07-30File 2020_07_31 73326.docdoc 80565d4ed000d2c561645c79096f5e2fe04ac3f5c7e9e34ac68cb4ed9306ceabVirustotal results 50.00%Heodo
2020-07-30ARC 20200731 R17189.docdoc 4122a94cf3814bd9e32328263e6b981316558b31ce38df659a1853a02274dc00Virustotal results 50.85% Heodo
2020-07-30Mes 20200731 S367074.docdoc 1076bbb650f5180bd85eead7b5411b8d601b04cebbf38dac7328ea86b4e7adb8Virustotal results 50.00%Heodo
2020-07-30MES_Y5628.docdoc de22f3d159bf17825aa2c83805068b8ebe5d690f6981d2e8102613087fd3b6deVirustotal results 47.54% Heodo
2020-07-30DAT 20200730 M25532.docdoc 8afe6cc692747e8399748ac4d652b72ddea1515312f9530b8319a1b02e960eebVirustotal results 48.33% Heodo
2020-07-30File_2020_07_30_622.docdoc 48d8cbfc263814a895f4c3a14f14ea016f0ee51ae329063b61a0a2e4a541ad82n/a Heodo
2020-07-30Arc-20200730-16013.docdoc 0ae3792dfb7057e3264b21dd694ca5b3fc93502edf5829ca4797eb57f01170a2Virustotal results 46.67%Heodo
2020-07-30MES_I645955.docdoc 0a20209c9b6d387dc569b4a5e5c2bb715254fb1f1448b3a09f7eae306a38efe6Virustotal results 47.54% Heodo
2020-07-30ARC.docdoc 46815e894a9b6f7e7ad9bcb948b69d2b4847dbfd865ad522641c8d73fac7cbafVirustotal results 49.15% Heodo
2020-07-30Inf_2020_07_30_L272.docdoc 4c8c34a44a9443ad04f4515f360a20869d42f7d631fbb637dbfcf146a029a181Virustotal results 48.33% Heodo
2020-07-30Dat-20200730-922.docdoc 9aa5ef4cd779c27d0db8683412281e9b128846b846c5cacbc8caada39b2b9394n/a Heodo
2020-07-30DAT 2020_07_30 WKO807931.docdoc eaa4dd75d2c824aaa995b6e53a0b0774107072eb2dc7d66551ad0886bf71efd9Virustotal results 47.54% Heodo
2020-07-30dat 20200730 AU834.docdoc 6511b1fde2ef072f82a4de1fe9124c05afea6eee427bb3f6e204d6d8f583bf8bVirustotal results 46.67% Heodo
2020-07-30dat-2020_07_30-038.docdoc 093e1000147aabe0b38214e2060d1d52e6592e7aea8e0f1ee01e0735f5421e89Virustotal results 44.07% Heodo
2020-07-30arc-20200730-ZM614318.docdoc 8a47aede1c01b49c2d649a74e6a6708a81d61a8e196ef0584735e31b1d8504ben/a Heodo
2020-07-30arc-2020_07_30-727.docdoc eb1d46511a0c9230195926574582e81fdab2b7080d49a1c21e668ae1beb492fcn/a Heodo
2020-07-30ARC-20200730-0402061.docdoc 25cafbcaa169e7b33aacb6993e04413dc440de3425698a848701168658bc34b0n/aHeodo