URLhaus Database

You are currently viewing the URLhaus database entry for http://kangologistics.com/wp-admin/gCZIuuduy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431845
URL: http://kangologistics.com/wp-admin/gCZIuuduy/
URL Status:Offline
Host: kangologistics.com
Date added:2020-08-13 11:45:43 UTC
Last online:2020-10-30 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-13 11:46:07 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:2 months, 18 days, 4 hours, 11 minutes Bad (down since 2020-10-30 15:57:18 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26n/aunknown 56bc0b66e2f31843988063dc4ec5c011c929ca267d5aa37b0cab184aee69409cn/a 
2020-08-14invoice-JG198-71497626.docdoc 33a8aa9764e02d87f0cec4eefb1f0a698ad48b39a10a8a9f2d62856a30cce1bfVirustotal results 30.51%Heodo
2020-08-14INVOICE GJLL26 83348004.docdoc c2af257a8a40028722b621eec7a07631530b6ad0a75733f89eb70aad03b1e4b7Virustotal results 30.00%Heodo
2020-08-14invoice O2 62676396.docdoc 47e583738beea94617d095118319318193630be4e2ddf5ae8ce66ebb131df7ffVirustotal results 27.87%Heodo
2020-08-14InvoiceVSB224448735719.docdoc 9d6676d7926e7555e55f55924ee0a8082d62b5b813ac98704090a5a23e7a1775Virustotal results 25.42%Heodo
2020-08-14INVOICE-793-2768788.docdoc 4935ab1182453885ea821cc714b1679ae7eeb54bb744fe13f52ad6e954a7f785Virustotal results 25.00%Heodo
2020-08-14invoice 5767 857416954.docdoc 9f48ee817d634981b3bf2419fae553b17bbd85ae489e4d7efa83364c7b7b286bVirustotal results 25.42%Heodo
2020-08-14INVOICE-H2-77396920.docdoc 4b1f4de38d23df072402ff46c59faadafed1bcd11b7158106edc189d8433845cVirustotal results 26.67%Heodo
2020-08-14Invoice 5535 471115224.docdoc 31fd17ea13411b2b4c8a726012b7e3390527519bfcb805d9d895877a627c8f7eVirustotal results 26.23%Heodo
2020-08-14invoice-LF8-45871317.docdoc 187f385bef1fda1bcb05ef62b9e4189a16432875e3fba2d0b7cf1fd6e6739de4n/aHeodo
2020-08-14Invoice-LNSG2-24393640.docdoc 3d1d9383eb8fa943d9a30683c659bf8dbd0728daae34c9e0227d1585f26cb327Virustotal results 25.00%Heodo
2020-08-14INVOICE-QW1-218007.docdoc 799b3f65b6c1c9cef2426765a3c0d3551a058285292161ddedf98b1bbd6020ddVirustotal results 23.73%Heodo
2020-08-14invoice-JTR0404-970022030.docdoc 4af3cc1ac4ee4610fa7671fdc8b02ad17ad4e71433250d2ab04291fc1f5e657cVirustotal results 24.56%Heodo
2020-08-14InvoiceJX33885702397.docdoc 9767bd56721afd6905bab6c3a1a8790999605c8e5b91b2dfded3a0849c7e5d60Virustotal results 23.33%Heodo
2020-08-14invoice33088766528.docdoc 8aa7b26f53f2ebc1a1678bb6f61704527478b875e9c4947c3193d966f0664efbVirustotal results 23.33%Heodo
2020-08-14Invoice-EN276-367095383.docdoc 99db7baf30cee72146c4791d36d158ca3ed62a58dd3bd57b7bfa60d0f13b08d9Virustotal results 24.59%Heodo
2020-08-14Invoice-BE30-15916706.docdoc 538aec1c87a88d78a75a417c253579be5fa18cefce592109122505cf70f2eea9Virustotal results 40.68%Heodo
2020-08-14invoice_1_59309026.docdoc 48b521df0053cf6d3e0a666218d6db914feccfad8513435589675afe66247870Virustotal results 41.67%Heodo
2020-08-14invoice 210 522460253.docdoc bef80c676faefc196703bfb61cf9459a8d09946d366edffa5810dcf3345f927eVirustotal results 38.98%Heodo
2020-08-14invoice_91_189894735.docdoc 845f584a4b58e05f5eabb64041142baac8b97a971f88d4cb2544c4ac3af97a3aVirustotal results 40.00%Heodo
2020-08-14invoice WLSF06 46846410.docdoc 382eeb05e0b37509916697e88d5f58e00cfd17db07cf9b27240fd84aa4bcd26eVirustotal results 40.00%Heodo
2020-08-14invoice ZSOH5463 2896163.docdoc d77766273a903661def8286676499fd3cf8f2a337cd8fa867e5788e5509db0e6Virustotal results 40.00%Heodo
2020-08-14Invoice-KIM06-806520988.docdoc 8b725e5a090dcb30815c5df978e72af9a04372b9fda6729678004e9bdd617ce6Virustotal results 38.33%Heodo
2020-08-14InvoiceKINC0056271723.docdoc 2da551517d3d24f3485bb7c1edd4dc79031582d5cc3f4066169ecdbe26b4df18Virustotal results 36.67%Heodo
2020-08-14invoice-LK5559-60128015.docdoc ad1c63f07f872f3b37453d29dce7654dc1b79e4f3e875dd8090977c30093b6f6Virustotal results 37.93%Heodo
2020-08-14INVOICE BY984 93363594.docdoc b912946f86e61acf37130b179be53f6dfa2fdd31fa0e158dd2fd19f557aaf059Virustotal results 36.67%Heodo
2020-08-14INVOICE 0286 259192055.docdoc 60f8488fdb7df1654b540cffa5a6b15006c90ab03e4cfbc618d7594c813c252dVirustotal results 36.67%Heodo
2020-08-14INVOICE-FO2139-69263738.docdoc 2879a9d705300779c0269f3a6847fb725a3564c7ae27f44226fe17f422474ca3Virustotal results 36.67%Heodo
2020-08-14INVOICE-TP74-915551452.docdoc 532d6be9513e3dea9cfb7040d4e2b0878429f90b84e8c3229ba775ff99dcfbbcVirustotal results 37.29%Heodo
2020-08-13Inv P7019 07203471.docdoc 3c2103ec1e6af0ce039524d58d70a4ced5e2845549def894d03f836978afa09dVirustotal results 38.98%Heodo
2020-08-13invoice-P206-413646.docdoc 1903fc2590537417ead798a7e0026a3f89c338018d0ff2942e8f984a197b930cVirustotal results 35.00%Heodo
2020-08-13INVOICEBY31959129.docdoc 2700c5a0f48e93d064b77b0179fc337d59ed7d100dcdfa5f29c2f1d035e03204Virustotal results 36.07%Heodo
2020-08-13Inv 778 4123543.docdoc e1ac6201887f008a8beef8eca74076739b93dacf2d0d366f3329ca55dbc3c827Virustotal results 36.07%Heodo
2020-08-13Invoice-LDT400-079450439.docdoc 9790de78c7614b7690b8f35d421b7704eb89e5eb5cabfe24dcf83485d90e2949Virustotal results 36.21%Heodo
2020-08-13INVOICEC759445740.docdoc cf0b0c4bf2dec3979bd7cc8606c1c911299845f9f97067fd4ae7af1985e6f6b9Virustotal results 36.07%Heodo
2020-08-13invoiceBRNM208488270255.docdoc 5068ac1fc3ea1af3eb637bed169df3a72f14ab7db56ff2996f718fbe8c05642eVirustotal results 36.67%Heodo
2020-08-13INVOICE_E55_209655.docdoc 4dc091daaf9b2ff460f2d3494beb83445f498784dce48abf4d793b1fb6955f07Virustotal results 35.00%Heodo
2020-08-13INVOICE S222 538826195.docdoc 894dfe7d84439530c0f7bdca76e92f6d9ff10fe2121e0ff8decfea3153f5e91fVirustotal results 35.00%Heodo
2020-08-13invoice-TTUD51-10447456.docdoc 7f84ffec8d67c90cf874b1c63419a909e57b6e610d050a800bccfef7de037607n/aHeodo
2020-08-13Inv_RA83_8399393.docdoc 17c0ad7fe3012db3c5ada59ba1d21436aa344ab57a37ce699684f8bbead66de0Virustotal results 33.33%Heodo
2020-08-13INVOICE U9615 80876426.docdoc 9c555a84e2b325b4c2d60e9dba477c087791380312f4c5c664d3ab4f1c47ab86Virustotal results 31.67%Heodo
2020-08-13Invoice-XE522-2898879.docdoc 196a89c54cda70af31877740ead0a738ead3533d3ef89e87e31b193044fb42f7Virustotal results 31.67%Heodo
2020-08-13INVOICE_O34_694843.docdoc 53012447056c43d98e67bc063b1016fc1330216796dcc7c1eaed32a4aa02b45cVirustotal results 31.67%Heodo
2020-08-13invoice XBXN6 499265022.docdoc 286f7949f545a67074545aa0830816a560a993143774c4468d041d5e656d2897Virustotal results 28.33%Heodo
2020-08-13InvAEDX3104793653.docdoc 56301f606789e94e8da7b88c171cb8e282a451a8c3c719ddd073a2840c9f3976Virustotal results 28.81%Heodo
2020-08-13INVOICE-K40-6535709.docdoc f392265c903b4cad60edb998054c18fcb2cfdfe7e9e068ad6119545be62062e6Virustotal results 28.33%Heodo
2020-08-13INVOICE Q7714 438544615.docdoc 8d7640adaf6a576ce6484be49d372141feaf9dd38837bf8da72271ce7ae7e127Virustotal results 28.33%Heodo
2020-08-13Invoice_1474_88982963.docdoc e9bc4332a3fd2de13d8f4d58aaf749131a93e652fd663f83005b1437936a715eVirustotal results 26.67%Heodo
2020-08-13Inv_XY3_338880.docdoc bf2332d7bb2fe3a48644b9436beaccf7cc4015b5954d8d012f2b095e21023629Virustotal results 26.67%Heodo
2020-08-13INVOICEE14447532231.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 26.67%Heodo
2020-08-13invoice-ICI29-73031793.docdoc d2cc4f61f498dbddde048bbb918416d73f063a0bb46c960ab7fd6fe671ed9bd1Virustotal results 25.42%Heodo
2020-08-13INVOICE-MVRJ32-272639207.docdoc 549d4559782f6c11783867db78579ca723c90e7e4399b952fa14de9aa84d1bceVirustotal results 26.67%Heodo