URLhaus Database

You are currently viewing the URLhaus database entry for http://www.noor.me.ke/wp-content/lODcgYB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432040
URL: http://www.noor.me.ke/wp-content/lODcgYB/
URL Status:Offline
Host: www.noor.me.ke
Date added:2020-08-13 15:29:08 UTC
Last online:2020-08-21 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-13 15:30:03 UTC to abuse{at}ns1[dot]bg)
Takedown time:8 days, 2 hours, 15 minutes Bad (down since 2020-08-21 17:45:19 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15invoiceBDQW1131387.docdoc b9d2bc9624f1e81b007fd1d89170294eb6eb29c779f83f4e75576a0fa3fa421aVirustotal results 41.38%Heodo
2020-08-15Invoice L468 626147.docdoc 8f88dd80520ccf01a78eb649cc1a7918ff8a0c36019a7b5ecf59ae9c79afae7dVirustotal results 40.68%Heodo
2020-08-15InvH1035608502.docdoc f7ce411b7421d1de9b103f8f163473e958f59f43df8aada43e0a13c56cdd7547Virustotal results 41.38%Heodo
2020-08-14Invoice-93-167688201.docdoc a3ad36ba5e2f29b182462c4bd4ac3e327b037ed3726031ebc106081eb157016eVirustotal results 37.29%Heodo
2020-08-14InvLTQD66321519250.docdoc ecad5745af706bbb7ea9c6ec69d389e2e6c4899ca17cb7fdf29ac1230375503cVirustotal results 37.29%Heodo
2020-08-14INVOICEPOJ006408447857.docdoc 95cc5ce9259454f349e823d4c1e4c546a303dacfd17dd01c60af5f9dfb171cb6Virustotal results 36.21%Heodo
2020-08-14invoice_KY15_02914910.docdoc f6975e399a20403d7fa740561dd50360525589b049dea235f163105219d0cb99Virustotal results 37.29%Heodo
2020-08-14INVOICE-1-567389914.docdoc f05c3c3c5f5f34aa116627c7125bf1a8c6601d0fad0762c759d77d20ffa45726Virustotal results 38.33%Heodo
2020-08-14INVOICE QC61 529889728.docdoc 33a8aa9764e02d87f0cec4eefb1f0a698ad48b39a10a8a9f2d62856a30cce1bfVirustotal results 30.51%Heodo
2020-08-14InvoiceOKWG3042626538.docdoc 7547919d586a1ab27cf87b4e8b7031345a0ac4b24ac352d54627ede945055aa2Virustotal results 28.81%Heodo
2020-08-13Inv_ON1183_8343015.docdoc 286f7949f545a67074545aa0830816a560a993143774c4468d041d5e656d2897n/aHeodo