URLhaus Database

You are currently viewing the URLhaus database entry for http://kotikirkko.fi/logot/au/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432783
URL: http://kotikirkko.fi/logot/au/
URL Status:Offline
Host: kotikirkko.fi
Date added:2020-08-14 03:22:04 UTC
Last online:2020-08-21 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-14 03:24:02 UTC to abuse{at}euronic[dot]fi)
Takedown time:7 days, 7 hours, 57 minutes Bad (down since 2020-08-21 11:21:42 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15Inv-6647-9683537.docdoc b9d2bc9624f1e81b007fd1d89170294eb6eb29c779f83f4e75576a0fa3fa421aVirustotal results 41.38%Heodo
2020-08-15Inv MZR8 2654345.docdoc 62832607fcefbef56ee871dd3ef7d35bb36d9b2837e62a50dc05ccac097c6b72Virustotal results 41.38%Heodo
2020-08-15INVOICE-CVJ80-7772570.docdoc 9b779c442f3460b404b04fd470d6529c0e3cc8e33a2879e274c11f72a1a8c356n/aHeodo
2020-08-15invoiceJGNZ09941597.docdoc ce612572675e02e053cb7c1dda650bb088de566ec6624740daef65d7886bdcb5Virustotal results 38.98%Heodo
2020-08-14invoice-NH3150-02782437.docdoc 91c79c2700e5e6e2b89cacab78340312b79127e8201a5d13ac61060f4d6160bcVirustotal results 37.29%Heodo
2020-08-14invoice-4-095807.docdoc 4a01c8e6ec280343403441c5e17c55359032885ef2cfae8ad4fc165f3911bac3Virustotal results 38.33%Heodo
2020-08-14Inv-AR10-952630943.docdoc 30c3f5870ae2978c2842580f829a9c134d504639afcdb54eac7d626453fc194cVirustotal results 38.98%Heodo
2020-08-14invoice-5-842844323.docdoc 3faefaec25266917cdada868fc8076b16e9b42382e82bfb5018562978d0085a1n/aHeodo
2020-08-14invoice 8403 123277.docdoc a4a28205cafc8bad9f4887c857273508e7324991fb3b765e7019cef1f0192d4aVirustotal results 28.33%Heodo
2020-08-14INVOICE-RIH55-5629456.docdoc 128c5726c5cf18e1c6c4a02c6778e3825ba73ed0e90c6af71c14aaac7c34e526Virustotal results 25.42%Heodo
2020-08-14Invoice-XKSL68-782210.docdoc 0bd1c09908f6c09ae5217b631f5041669b722d5961f9471365b074d51d9a7a36Virustotal results 23.73%Heodo
2020-08-14Invoice-MBZT891-75335489.docdoc 73d4b0a7ca15e61e87a8fe48a88037618e4b4aac3d8a94cf4583f52cbab9bcc1n/aHeodo
2020-08-14Invoice 00 135664041.docdoc 0c8f2829aa051a5e6c46de5538877492af65802d40d49435dccb05882ec52308Virustotal results 40.00%Heodo
2020-08-14INVOICE-FX984-54350853.docdoc 538aec1c87a88d78a75a417c253579be5fa18cefce592109122505cf70f2eea9Virustotal results 40.68%Heodo
2020-08-14Invoice-NX8-4015605.docdoc fb17807621969c33d345882ad5ae95cd5294c32509e13a6fe8ce1d317a5c3f4dVirustotal results 38.60% Heodo
2020-08-14Invoice-EGG5-444815395.docdoc 8b725e5a090dcb30815c5df978e72af9a04372b9fda6729678004e9bdd617ce6Virustotal results 38.33%Heodo
2020-08-14Invoice 37 48779064.docdoc a54000794f084b7b28acdd57f0e839bcc31a78890df1368195cf0f49782ddd6aVirustotal results 36.67%Heodo