URLhaus Database

You are currently viewing the URLhaus database entry for https://ukinvestorgate.com/wp-admin/DOC/2jMCfrrOzKM6Usmz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:609071
URL: https://ukinvestorgate.com/wp-admin/DOC/2jMCfrrOzKM6Usmz/
URL Status:Offline
Host: ukinvestorgate.com
Date added:2020-09-24 05:21:08 UTC
Last online:2020-09-24 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 05:22:02 UTC to CloudFlare Anti-Abuse API)
Takedown time:9 hours, 27 minutes Good (down since 2020-09-24 14:49:20 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-24LIST 20200924 470753.docdoc 3db5537afa72bac1ad7529d5026dc4962d42b2e6af1cb12235cfc1f8751676b5Virustotal results 32.26%Heodo
2020-09-24Rep_HR054884.docdoc 1bd2c4e63cc18ec616e810626207f2b2918063a299e4016df319fe82b8084621Virustotal results 32.26%Heodo
2020-09-24Attachments_20200924.docdoc a6a2cc6d2d1e9340181c5871b0900a88187a6290363210efa3197d0c024d9821n/aHeodo
2020-09-24INF 20200924 0915363.docdoc ab018f08c79d8a8f4335f9fa35e22f6d573ddcf82c5a1db98a8ceb6671bae1b6Virustotal results 32.26%Heodo
2020-09-24Rep.docdoc 162b68e90f80db94074b88af43ec09ef7e693ebc8626c339e22cc213b9433b0eVirustotal results 30.65%Heodo
2020-09-24File_2020_09_24.docdoc 813746f9ab7f5febeeae88626f82ec4c28390336a202a16ca16112e19c702d90Virustotal results 29.51%Heodo
2020-09-24doc-20200924.docdoc 337c448330447e39dbdc41539c6dc162aabc8ea6f9a703187bf2e2e3cd7f49f9n/aHeodo
2020-09-24Untitled 2020_09_24.docdoc 972a446499e3831b2bb7e46691fb3e7e927f60e8c86be2d49922cfbbfc1854f7n/aHeodo
2020-09-24REP_20200924_O7062.docdoc f639c68c402624a47119cf4e726a67b5eb1135e4d263382081fda1b0ab1842f4n/aHeodo
2020-09-24list-2020_09_24-T45052.docdoc 6d9593629624074aa0ff3f5beab0843fe2fd2ff42c041e36225bdb02d33b6793Virustotal results 25.00%Heodo
2020-09-24Arc_20200924_I8449.docdoc eef0320291fea4b857e373510a8f865102bf7eeabf6556cff02a87558c4cf776n/aHeodo
2020-09-24inf 851.docdoc 439df4997262d2db8e015f7449a8b33c9bf2c8db09f8b184d69c7ad6fe968c92n/aHeodo
2020-09-24list-R7717.docdoc 270f0d810118a907f70cfaf2095542eb0cdf2ae81079249b8f9c262cdc858568n/aHeodo
2020-09-24MES_835121.docdoc 6dbe352bb9203a1b268ab47b35f5d86b3f309a8e2595f8ece915bd547bc9c33fn/aHeodo
2020-09-24inf-QAM81290.docdoc 32723c361acd35dd884c3243982f32d78493255655f04ef6246b0c4fdb18f3f5n/aHeodo
2020-09-24REP_20200924_IK899.docdoc 528d22e4147caf0834320353578b1d3fb47fe97bd180e7d2bf9f764980d14bacVirustotal results 41.94%Heodo
2020-09-24Untitled 2020_09_24 JDE372483.docdoc 23db49d5886e034ad5ab63515e5c5c6b6374d5bad5c9b68cfb3d84f39451a301Virustotal results 41.94%Heodo
2020-09-24INF 2020_09_24.docdoc 4d3529cb9c98cae2816c1b943de1d50f2acb43769d288fffa8b7e28324faa8d8n/aHeodo
2020-09-24UNTITLED 2020_09_24 YOS008.docdoc e7f6321d905f4db566091d8d4520f4d128bf66917cc86d794f1d435352ed2899Virustotal results 37.10%Heodo