URLhaus Database

You are currently viewing the URLhaus database entry for http://www.uasingishu.go.ke/wordpress/wp-content/uploads/sites/2obddFBjbJyoraywh13/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:621490
URL: http://www.uasingishu.go.ke/wordpress/wp-content/uploads/sites/2obddFBjbJyoraywh13/
URL Status:Offline
Host: www.uasingishu.go.ke
Date added:2020-09-29 07:11:05 UTC
Last online:2020-12-15 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 07:12:15 UTC to abuse{at}ripe[dot]net)
Takedown time:2 months, 17 days, 5 hours, 0 minutes Bad (down since 2020-12-15 12:12:24 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-01Rep 20201001 27996.docdoc bca937c5b07cf43a6469fae63640f655c5bbdacff9c671b53965974a5203c262Virustotal results 37.10%Heodo
2020-10-01Arc.docdoc b2af72414cca6a559fbc5e9254b6080ce9d292ef4b2a37d8973118f7fffca277n/aHeodo
2020-09-30MES.docdoc ec9d596dea9e8934a188f8d65b878a79dd49654e8159980d96eadf857e90cf7en/aHeodo
2020-09-30REP 9815.docdoc be1d469e7f434641202ffde45e666cd4b1d255814f8cbf344a3aff1e78e86768n/aHeodo
2020-09-30Inf.docdoc f5de87215c12489f4834be4a1b71fda51d010a845429e71980e6024e221b86ben/aHeodo
2020-09-30Attachment 31408.docdoc 2bc311aff7d90ac42c818d1850c8eff0fca326e6c334899f8041c63a59753465n/aHeodo
2020-09-30DAT-120.docdoc 6532e0b5e7e0a65864bed3ff6ee62581be8b76f1d35bff0e9289fc95b851a992n/aHeodo
2020-09-30INF 2020_09_30 EZE03120.docdoc 71982d0bf9cc749ec9a19c977e29cd16ec613b3a2a3305de01a2c0f319de5f52n/aHeodo
2020-09-30Dat-2020_09_30-49970.docdoc 32df3c70f61588818db28100b3aa78cd777b526393d31f97a17cddbee56e12d3n/aHeodo
2020-09-30Dat-2020_09_30-49970.docdoc 32df3c70f61588818db28100b3aa78cd777b526393d31f97a17cddbee56e12d3n/aHeodo
2020-09-30LIST_2020_09_30_IQI412.docdoc c00ad151d1825f27639994f1a506ff8fb76d8cf3460cac3eb8351c1caafa8b71n/aHeodo
2020-09-30dat_2020_09_30_193339.docdoc 799ad9ba2f68222b08e1a3728b0e9ec9ba943db3978c06ce8febd8e74f57a0d8n/aHeodo
2020-09-30UNTITLED_2020_09_30_94380.docdoc 97a1dcdb0f512e1576b86aec1d69b7666ea402ee4259cc24fd6ae14892a6e584Virustotal results 21.31%Heodo
2020-09-30Inf_TH2270.docdoc a3f7b976b0c108284bf0de59187798f84d509ad7182c92761cedbb9b35ba4a3dn/aHeodo
2020-09-30C5088-XS731.docdoc 848472a593e725755e8a0b52a61189cab28bedfa9f8d62a7a528790838e7d9acn/aHeodo
2020-09-30file-20200930-C683.docdoc 665096dfe25e4e636f41d66df9cc4cfb35a0a347a0a1424b191c7b5834179dbfVirustotal results 21.31%Heodo
2020-09-30Attachment.docdoc 464e4eb4c4d1fe1f13e2d9a96e6ebbb73ccc5f8dc2bd333a286f1e07d85899b8n/aHeodo
2020-09-3075925855_2020_09_30_067229.docdoc a145c68d6733bdbef62c6d009986cf4ac6100b25b6e44571b92f9e5257fd3a2cn/aHeodo
2020-09-306258_2020_09_30_AF476032.docdoc 4b795f3870e608b6c61e4a7757d87deb5525949aadeb15393e2b83cb4b34e618Virustotal results 47.54%Heodo
2020-09-30MES.docdoc 6203971a2e4b246318cba558f864664aacc3cc5dae07aa3b8ce1fa6fb17d590dn/aHeodo
2020-09-30INF_HOR9958.docdoc 3bdee9fdd814363fa073be396eda19d9242d4bfd82702110dff7564d61ef4a8eVirustotal results 46.67%Heodo
2020-09-30rep 20200930.docdoc e0241059c22b3f4c297b2b6d6c3d0d854d45f39af3ec08495ca2b04025772414Virustotal results 47.54%Heodo
2020-09-30inf_20200930_638.docdoc 869911e995bc11a3a2e87a02de6611b59d26ddd5b21c6c77e72f327620f526c2n/aHeodo
2020-09-30Attachment 20200930 AI09125.docdoc 89512a4396d991ea5a6384037a7418d9f30bfe1d444f2fbef7a0c0b5f2f421d4Virustotal results 45.90%Heodo
2020-09-30ARC_766883.docdoc 6f99b89e5bfde428715216d919a8e1dd87475900137dfbb2e07c5ba58bbb2954Virustotal results 45.16%Heodo
2020-09-30mes_20200930_PUH257.docdoc 33477bed1839bb45bcfd3358705d97b3db5e567c2c551e666d8ac934ec20dd9bn/aHeodo
2020-09-30file_NZ2164.docdoc 26979e8912dc25e20f622985b767028de865e5719a3a559353389878b9fa0b64n/aHeodo
2020-09-30Rep.docdoc 9d14d3ff8abad95d71af0043f19dd1644cfa14ceb0a6ba617a49f3bd559523cfVirustotal results 40.32%Heodo
2020-09-307756-20200930-F79961.docdoc 10294374734e4bb56cbf03eba2d257784ac87c057586d27a97c2b8b30f1f0f6dVirustotal results 38.33%Heodo
2020-09-30inf-20200930-UK9156.docdoc 058c2e8f57729727ed29b3c713fb0147a3b79eb1ca1360453aad3185f45e41c8Virustotal results 35.48%Heodo
2020-09-30list 2020_09_30 15632.docdoc 1d44cd8c3d04874dc41108bc844eb637f657064927fc28927f68c95fe596bcaaVirustotal results 32.79%Heodo
2020-09-30arc.docdoc b6c45e66c35cf5d894ba5932c824d162c760459d59644fd0d41bc5ab63604b06Virustotal results 32.26%Heodo
2020-09-30LIST-20200930-LSB989007.docdoc b3209c6972bdb3ddba9f14b30f6a49d2ee49d09003fca07ae1f28646011f0a0bn/aHeodo
2020-09-30UNTITLED 2020_09_30 97655.docdoc e24108e3bfdc205fb409b17e7471d0fa880daa6a6ff8379a3195b0ce9b646d83Virustotal results 32.26%Heodo
2020-09-30Untitled 20200930 4042385.docdoc a87836e6fbf70862d74980ad32f16b6dfe157bcea1172817e7235764aae0c4den/aHeodo
2020-09-30rep 2020_09_30 3319026.docdoc 541afbe8b457f589a760cae7ecbf5d520a7f1ecb81bf9d2e2f5ddf90cad8a418n/aHeodo
2020-09-30LIST_0195751.docdoc 1d5392f655dcdc6f812366e57505b4f345c53a8c5ede33a7f7b9d6e05c3deaefn/aHeodo
2020-09-29doc-20200930.docdoc dc873a463b8cbee41eb8683d98db5a331553402391ba1c16e664c7034eb1acafVirustotal results 30.65%Heodo
2020-09-29515_2020_09_30_MIU56914.docdoc 1d742e585ed7b4c237726a945da11795c46da01716e9da561d98fff100ee938fVirustotal results 31.15%Heodo
2020-09-29Attachments-20200930-H050415.docdoc 2ce2a7979c53158a0e7454224e6755704290a5a16a092aec69088da9eb3571a3Virustotal results 29.03%Heodo
2020-09-29Dat 2020_09_30 86303.docdoc 08c3a51969b9ccfcd46ad14ef1a7599a798c21e693a582ac6d8f449f77f4fc09n/aHeodo
2020-09-29Inf 2020_09_30 585.docdoc 74f26e376ef3b8ea6b3b9d1599e98182897725563fcf69a3ae86f502acc7cdabn/aHeodo
2020-09-29Mes-7831.docdoc 7b65d8ab639b2e52bf89d1991cd330f6290b79269e2699b295b134f62689d29eVirustotal results 19.35%Heodo
2020-09-29Rep_2020_09_30_441.docdoc 4d320a36571c9892b7730fe7903d3eb8a96dd16575194e01c8b202f77930f86fVirustotal results 19.35%Heodo
2020-09-29ARC-2020_09_30-AM899355.docdoc e217a7b6b8d3730d1f902b14dce65e6146ed92bf808d911ff003e7dbb8f29a71Virustotal results 19.67%Heodo
2020-09-29ARC-2020_09_30-6140476.docdoc 0cb12ea9c119587b5d2e54790384725d78e44c9a9336299b99ee2aba6b9bfbb8Virustotal results 20.00%Heodo
2020-09-29Doc-20200929-25062.docdoc bbad3f60585528f0b63696a2bf16eb457f9835f17002bcde52da2a2a8e38821bn/aHeodo
2020-09-29INF 20200929 D77683.docdoc 336972f8cd7d0486f2c935261f8a871e5b5c97833931dc186a1acb6a24208fbcn/aHeodo
2020-09-29REP-M449.docdoc bf5207a0e4114c9e0f57a16e907f14cb4ab28ff7469262d6dc749d3960ddc67bVirustotal results 19.35%Heodo
2020-09-29Mes_XJ3696.docdoc e05b6ed555dc8741ddf076484cf7ce5f0167e49096c5f25549b9eb7c5a01f81an/aHeodo
2020-09-29Untitled-20200929-LG156.docdoc 30a41f457f62ccbaa26f3679ed88fd959c5cae23e1b9faa2799ea867bd7e916bVirustotal results 17.74%Heodo
2020-09-29doc-2020_09_29-Q166158.docdoc 67021d297ccd2620cef8e46962996c3a644bdf39577c1f4d02f360a7cb7ab0d9n/aHeodo
2020-09-29Arc 20200929 1482.docdoc 8dc94be7486bc7ed3174caa03f1f6a57dabcea9e39fc85e33505be2f1c6f7d64n/a Heodo
2020-09-29Rep 0475702.docdoc 054954c8adf177996d7b60d1f0f7490910c3d38ccfa915725432a3702b1fa6c7Virustotal results 36.07%Heodo
2020-09-29ARC.docdoc 2ca85c8780347f7e0298ce203eeaca8941cbcf4b2dbbd8e423a93655baf0417en/aHeodo
2020-09-29mes_QSZ7724.docdoc afe621cd44cd689287ad44e9d1728558887078487d74729709bf5e332f7f99d2n/aHeodo
2020-09-29File 20200929.docdoc fe5b85ffcc08f811bce57d1eb2cca479c679cc8770a6991f857deb2f95278b88Virustotal results 37.10%Heodo
2020-09-29File-SPG321934.docdoc ebe5c60d0f35c3d6f839899e01aef73d251b2ba41e0d7ca848d1302b1c9906ecVirustotal results 37.29%Heodo
2020-09-29arc-20200929-2002129.docdoc 23b449fb112ad9151ab2a3e4951ca38ed7ee57f9025e3c70de11fcdf956ffb98Virustotal results 35.48%Heodo
2020-09-29ARC_83005.docdoc af16fa450a1498ff81000094039ebdfd9d1517f0002b86d9dfa214e1ae474636Virustotal results 37.10%Heodo
2020-09-29REP DK30570.docdoc 253cd8373b9fef7b344b345f38bd10c5c6cfa760b422b98092f01d3925a51b47n/aHeodo
2020-09-29MES-2020_09_29-ZGO1684.docdoc 2b76bed992df2036c3068fd1b33abc390bae3f22b4679e650d5e02786347d6a5Virustotal results 37.70%Heodo
2020-09-29list-2020_09_29-SUL2702.docdoc d9037b8ee35fc9032dd2409ffa7ed2ec6c8edec5afc7de5429b4daead9664d45Virustotal results 38.33%Heodo
2020-09-29FILE 20200929 NQ029.docdoc ae306a6cc155bf68ece16f8f6a7b65692511d84af5c2d0f8375c31975b1b2769Virustotal results 32.79%Heodo
2020-09-294333 2020_09_29 PG12713.docdoc 76b5f9e5cb59fcac0d2e8109a019fc56b03e5a26b1a0406ffc15f63dbd6514ebn/aHeodo
2020-09-29DAT-20200929-TON805.docdoc 4b2e66beb92b80dd54225c378ccc4984d31d6f9fcc56c840a238ee0bfe643b13n/aHeodo
2020-09-29mes 2020_09_29.docdoc 90bbebfb3f41606e87b0e49c89747c7ca24e3ebbddd545016b8c9507390467d0n/aHeodo
2020-09-29ARC_03404.docdoc d0147b6f5c086e57ac825b58766d460a2ab5a539ade9ce0dd89949e61f1c77een/aHeodo
2020-09-29mes-2020_09_29.docdoc 0418247c7dfbc8ba73880608c948f3ae38510b9508c58d43c81d10f6dab119e3n/aHeodo
2020-09-29UNTITLED-20200929-BAL5506.docdoc dc0ebe3e384cfbfe906f970d1b368b69a1564f661b60bff736fb51f307de4197n/aHeodo
2020-09-29Rep_BET7651.docdoc 212c3f50968898aca48cd72bb7d9fb5dee45be187a58375479b5fa30e49f1725Virustotal results 22.58%Heodo
2020-09-29Inf 2020_09_29 54868.docdoc 741e14a66eb965aae9fcc7da6bc90f096cb91d8492405b53d81e9d13ea0100ean/aHeodo
2020-09-29DAT-2020_09_29-PZY811838.docdoc b22c2b23f9c9e6307d976a10c7f68cd48629b9d2b6907bc8fa739aca9f15438fn/aHeodo
2020-09-29ARC_2020_09_29.docdoc 5f6f6797c37bee110a5304856e2cd815e090fb9b40e67a1392d3a4d7310661d9Virustotal results 24.19%Heodo
2020-09-29UNTITLED-20200929-820.docdoc 1ef1e4c64715bfa17c60820cf15f98d2934c38911c568e96b65890caceb71651n/aHeodo
2020-09-29FILE_20200929_OO2120.docdoc 7846dc72ed56d56ae1eef1756a7217bc4f8e4f50efa99051b54f9603c5aa8ea9Virustotal results 24.19%Heodo
2020-09-29ARC_2020_09_29_744.docdoc 0fecfde61b7f7f3534c0bc1768d898beeef96c53f2ff2aea67835319b4c5fe91Virustotal results 22.58%Heodo
2020-09-29INF_20200929_FB02871.docdoc 5c9b61e7c24cc5d8b1dfdced53ee0347071660ed454abca451ec9ef2c1dca7e1n/aHeodo
2020-09-29DAT 20200929.docdoc 6e9744f364184b29485e6cad1604f0b2afc996e5216392c1dd695dd2e6d58bfbn/aHeodo
2020-09-29FILE 381.docdoc bc70f983f6aa5504724edcc00425cb54b3c6bba19d0e1b9d975107af678f841fn/aHeodo
2020-09-29Mes_VAN68864.docdoc c55d038ff7a51d4af92262c4d4c1cbc26f9a665407845e87f6602616035a1e2dn/aHeodo
2020-09-29dat-CN188.docdoc eafccb99b1d640491547d4449feb5cec8d14374e9d8cc833f6152cd684b3f5e7Virustotal results 24.59%Heodo
2020-09-29Attachments_2725.docdoc 99eae20e9f85e8f87d7559e43c98d5477c2931dfb5bedcf8cec0eb6cb1c93030n/aHeodo
2020-09-2990245IGV-D37214.docdoc db2827442fd94158d69409377c110fe47b1b4837baca1664d42e4090d1fddb32n/aHeodo
2020-09-29Doc-20200929-MPA75518.docdoc 4c47677a2b29a91e0a497ec1b4a35358c64a48568ab32bd9b24ca10bf3bee27aVirustotal results 22.58%Heodo
2020-09-29Dat-20200929.docdoc bd40e03f49d87ba4aa6366400edcdc932f81cc11fe0ddbadf1ba4c64981d421bn/aHeodo
2020-09-29Arc_1805060.docdoc 02b930d350866dbdcc07e0ce90a98efb7b5e4fd14c09e41f986d23fa5c79db21n/aHeodo