URLhaus Database

You are currently viewing the URLhaus database entry for https://ukjas.com/wp-admin/rl-7w-8008/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431982
URL: https://ukjas.com/wp-admin/rl-7w-8008/
URL Status:Offline
Host: ukjas.com
Date added:2020-08-13 14:04:19 UTC
Last online:2020-08-13 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-13 14:06:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 25 minutes Good (down since 2020-08-13 16:31:08 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13invoice MSO7160 159938163.docdoc 7e058242f7a064bad48c7b7a1e45ebabdb59903cabf069d79e145c9edd2408fcVirustotal results 31.67%Heodo
2020-08-13InvoiceQHKA8507178336.docdoc fca1b080bd37f31310426e23e3d06dff66c14e54fdc049af8896fd4970ea29c5Virustotal results 31.67%Heodo
2020-08-13invoiceZ9804052622192.docdoc f5bd9c57be4bf800068a06ffb19dc5d394c48f3536f3fb8af2af36b238e0afe4Virustotal results 29.51% Heodo
2020-08-13Invoice-VP06-1084292.docdoc 002e4e23a241c1fa930bf374dd4e1c871a0f19a6abb1fe7e34e0a7dd479a0744Virustotal results 28.33%Heodo
2020-08-13INVOICE-WV5-6806891.docdoc fee712637002c8475f30aa70617736faec255bed242c89f24aaba602691101a5Virustotal results 29.51%Heodo
2020-08-13INVOICE_VIO299_8887865.docdoc bd24e35406ae73f24ce2429c9c4f8b1badc523308a416c6125179767a924e4d3n/aHeodo