URLhaus Database

You are currently viewing the URLhaus database entry for http://kingcone.ca/wpps-backup-core/QZCtC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431343
URL: http://kingcone.ca/wpps-backup-core/QZCtC/
URL Status:Offline
Host: kingcone.ca
Date added:2020-08-12 23:27:03 UTC
Last online:2020-08-13 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002865612 created on 2020-08-12 23:28:06 UTC)
Takedown time:15 hours, 41 minutes Good (down since 2020-08-13 15:09:18 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13Inv-RCHY565-3363008.docdoc f392265c903b4cad60edb998054c18fcb2cfdfe7e9e068ad6119545be62062e6Virustotal results 28.33%Heodo
2020-08-13Inv-OKNT85-483805.docdoc 8d7640adaf6a576ce6484be49d372141feaf9dd38837bf8da72271ce7ae7e127Virustotal results 28.33%Heodo
2020-08-13Invoice-FY951-3640980.docdoc 59c83ecca1095f3f5a073bdc09552cb7ed9b230dfdc93dee59f18e2a38e849eaVirustotal results 28.33%Heodo
2020-08-13invoice QCI306 393261496.docdoc eeb469414b6509fdd0d204f306b29d55021e2de94608991794b5f59c2add1e07Virustotal results 26.67%Heodo
2020-08-13INVOICE ELBT7 063922.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 26.67%Heodo
2020-08-13INVOICE-FDFA5437-76620287.docdoc 86c0cc8d6327a374689e50a0d8bc139919ce31d297cce113a4e93bd78b8cd8a0Virustotal results 26.67%Heodo
2020-08-13invoice-UFYC1139-6334127.docdoc c30a4592cd8e7e2a97b2ee19d0061553ccbd7cd1b7e2af8bca2dd6913a1bccb5n/aHeodo
2020-08-13Invoice UGT891 061670.docdoc d9d595a78d3bf3bab0e65cd5eb3a71ba4bb95ed7850e84862d01930ceefd1c35Virustotal results 26.67%Heodo
2020-08-13Invoice_AGG578_655729546.docdoc e9fe379c503723a5883c5b4b3e4227a3a35c0fd4cec4716f859a2f981f6eb732Virustotal results 26.23%Heodo
2020-08-13Invoice-2-507618680.docdoc 147ff91d2f978f8abd623f6a25e0599903cb53c9a890255e3fcede1cb0fbc8daVirustotal results 25.42%Heodo
2020-08-13Inv_44_401916.docdoc 620d84fae4b584f528eb0044177ac950380d8c41d764dc1615871a80ecdc4ae7Virustotal results 25.00%Heodo
2020-08-13INVOICE YIP461 472841385.docdoc 27d0c48e8224b8b6607cefeec92b1672e7d61628e58bf2574cb30f1fc9518d2fn/aHeodo
2020-08-13Inv-A0-646084794.docdoc 5478e4974b64a8471ba220eb079a7dec82a9ceba893c8d56e165235a8df47f25Virustotal results 25.42%Heodo
2020-08-13Invoice_QHRP1872_375477.docdoc e1b7a11726c385bcad71dfe791b165802cc625ceaf2f1550a5a10f5f222ea90dVirustotal results 51.67%Heodo
2020-08-13INVOICE_CEY8_14700255.docdoc 10531f315432369a9c0706bc00ac1405445316044a9ec07b03de6606a6a9f9fbVirustotal results 55.00%Heodo
2020-08-13INVOICE763464713330.docdoc cd0aaf460944efd580dcc39bc1dd0460f88f2c3c17e303694ffa1eae5020eab2Virustotal results 53.33%Heodo
2020-08-13INVOICE QTR88 2846640.docdoc fddf4cab73e6e2ff5c40c7fee09d52d5eb903e6bd17ad77aa292c6ded707f394Virustotal results 55.00%Heodo
2020-08-13Inv-EH145-5154437.docdoc bd379f0e0dcc9c8c75d70a99df9f95dc56d70fd92cbf446a21dcb7b22ded59f9Virustotal results 54.39%Heodo
2020-08-13Invoice-O2-51613315.docdoc 97e52709f1f9169fb2a3d0cfc7852f811d067999ed1bdc700c6b66bc7dc23765Virustotal results 52.54%Heodo
2020-08-13Inv LVFW4 8754205.docdoc e26bbe184e43c8251aee307aa6d392971f7facdda4ce50f9733a966dc7905ff2n/aHeodo
2020-08-12invoice 8384 1451951.docdoc b439b2e90f88ae55ec1a481faa17242107321fa3b55ecb53369b8d0a5113db17Virustotal results 51.67%Heodo