URLhaus Database

You are currently viewing the URLhaus database entry for http://expresstv.ma/assets/INC/kp19w2w1fjb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428796
URL: http://expresstv.ma/assets/INC/kp19w2w1fjb/
URL Status:Offline
Host: expresstv.ma
Date added:2020-08-10 19:09:03 UTC
Last online:2020-08-11 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-10 19:10:12 UTC to abuse{at}ovh[dot]net)
Takedown time:12 hours, 25 minutes Good (down since 2020-08-11 07:36:11 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-11REP_VV3805429965WZ.docdoc 4a4a4dd5d1a19053ad3e765787b01d9dffb8b06be5faf5ce7a36efc5285df326Virustotal results 43.33%Heodo
2020-08-11J_16583646766368363280.docdoc a5231ddcc0dd60b8e592e26d19adc81ec13162c2ec100b3df902c514c88bc75cVirustotal results 43.33%Heodo
2020-08-11INV_UDY_080120_ZPZ_081120.docdoc 5577b4e9c441d81ac1cf74f1246a297c8b4ae3c3961704f988761f670a9d45e8Virustotal results 41.67% Heodo
2020-08-10PO_08112020EX.docdoc 1701cece68d9611b07097a1e331039dc38649b44d3ea02351e0b494b6bca4fe9n/aHeodo
2020-08-10VK8619859604TH.docdoc b5e1229c49f51eba4bb306aece6c81e4190cbecee9196e2f46b4076a3c563cccn/a Heodo
2020-08-10PLL_080120_FZV_081120.docdoc 2f1b5cb9bd5c444ec8eaf5094a1363f3eef3096e76438b53b8bcca63f5240eadn/a Heodo
2020-08-10801445330832088832920.docdoc dd27fbe8edac24db562a13614357e380f49894285fe1193552a3b71bb887d478Virustotal results 40.98% Heodo
2020-08-10REP_IPK_080120_YPK_081120.docdoc 2e208fcdd2050bf5d14c07221f5ee1ec1ed1f7e309a6368b1adf744235987f22n/aHeodo
2020-08-10QL13OET9K87P.docdoc 7162b8aa0d13c1f17afe429527b6e4a0cadad96b24928b4b0729e34488edb1b8n/aHeodo
2020-08-10BAL_75794863.docdoc 9872b30ec02cca1d3a1e99556d047ce25619a15bdc75e08242b514e0e54a2a87n/a Heodo
2020-08-10FILE_3MH6135EH0EM7IR.docdoc 2ce7d1abb43d1868d575ce543f8ce6d0c79ad406264308d9ae8e25cf75673e1an/a Heodo
2020-08-10FILE_L66ERRLNG3A5S8S4.docdoc fe21493280e923306b2814e03a02fe978f4d0179c15049984f9205344b9015d1n/a Heodo
2020-08-10J_48951468.docdoc 13148aab5424f38defa3f0ea8809d41033c90cb647f12b565975d6d79c91bf46Virustotal results 40.98% Heodo