URLhaus Database

You are currently viewing the URLhaus database entry for http://www.theculture.co.ke/wordpress/FILE/t2c5bvkm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:624502
URL: http://www.theculture.co.ke/wordpress/FILE/t2c5bvkm/
URL Status:Offline
Host: www.theculture.co.ke
Date added:2020-09-29 18:50:36 UTC
Last online:2020-10-02 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 18:52:38 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:2 days, 10 hours, 58 minutes Poor (down since 2020-10-02 05:50:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30DOC_87799275.docdoc a3d743d11312e842641d3124985266cfd1471f8d21881fb7dfc8dfa9cbd1fe47n/aHeodo
2020-09-30INV_NDC_090120_QTB_093020.docdoc e8a8b9fc12cfa3ee4f3cd91504cbf5b9af3281a25798c9c23c319044b39b551fn/aHeodo
2020-09-30INV_PO_09302020EX.docdoc d46320a38b414b43c59ca8d4290d2da2129bafa4cacc5de0162242e761f1dffdn/aHeodo
2020-09-30K_PO_09302020EX.docdoc f8436c00fcf874848a7d3c13607746123ab1f7c3926648ecb627363ba243de66n/aHeodo
2020-09-30BAL_Z8KREEHQ2OR6.docdoc d1cf503fbba6cc08731bec93c969a61a90d2e0a3f84c4a913535c9ab77e41160Virustotal results 25.81%Heodo
2020-09-30BAL_PO_09302020EX.docdoc c7b170de74bd23faa6d777bed0c29b826d7a0588fed94fe5ce051f61da72c9cen/aHeodo
2020-09-3072633333064472990637756.docdoc e0598f2efbf03596b6fc2d73a58184b9a4d4277d2fc01322308e86a132582e2dn/aHeodo
2020-09-30N_DJHN79ZB1SG4GK.docdoc 340edbbc6b875bfedadf402c810c9fbdde4fb3d9fee5d5f9996b9723d9fd5c94n/aHeodo
2020-09-30REP_43DUW8W8KH3OU.docdoc 1d5daccb3ffdca9e417370c654eefb0f6a0b2c3de51d7ca751c676d623cd57bcVirustotal results 22.58%Heodo
2020-09-30INV_2930919425647690189034889.docdoc ea04aeb35f3ee924c978225fd95f2fa3df8a4847a761685ad79f96c82886f80dn/aHeodo
2020-09-30BAL_TAZ_090120_RMH_093020.docdoc cdc88da9dc92cd4bbf8e6de747dd552a54b99dce8dfc68b79373710fc7938e52Virustotal results 22.58%Heodo
2020-09-30DOC_69984027.docdoc 08bda1ed5fe14e5198b9ac6497ef066c83189be44ff6fe663d6a708bdab3c8fbn/aHeodo
2020-09-30HA1973801039YA.docdoc a5bc68599f8ed3a4cdd8e4894aad9cd9fa0753278b8a44af04debb277960d44eVirustotal results 22.95%Heodo
2020-09-30KJI_090120_PCP_093020.docdoc a8dae6d86f2ae529335810a70a6f959f195bf9fd10f2ade7549334ff2767cd04n/aHeodo
2020-09-30RCY_RNL_090120_YEX_093020.docdoc 0011ab40a58a959e83c30fbf446eb4c411fa3d23826c53000495816bf6bd0e1en/aHeodo
2020-09-30INV_NF1048736213BN.docdoc 04c403355d94ec532774b1b6cfd66ec108e775047e9896e68823ecc5e6c9a027Virustotal results 22.95%Heodo
2020-09-30BAL_VGH_090120_JZV_093020.docdoc 06f0f241e0f9d72b7bfa912752c572cef951ebe5403388f20bc330e2dbda3c5cn/aHeodo
2020-09-30DOC_QK9731436017YJ.docdoc cdd0c1df94d8411b9502cbba720232d682901752e9c2adca68104f2d07f1b2e1Virustotal results 21.67%Heodo
2020-09-30BAL_VX2341929106ZD.docdoc 19377355e91331d5f2438275b1af46c6f266bd250c9e6a421feb6deaa86f7cadn/aHeodo
2020-09-30M_TZJ_090120_ZUM_093020.docdoc 5bd1dec77e268f1da221047d95d57981748b9f359c04a76b1b80de3a2144c67dVirustotal results 21.31%Heodo
2020-09-30DOC_C4PTHEC.docdoc 786c646aec87e25c98dfbac09f886f13f05a1e6690baf9974f99f1b37b6f3713Virustotal results 20.97%Heodo
2020-09-30CV_PO_09302020EX.docdoc 119dab813d43139ec7ee0f953f68341391776f7f5cdbc1fc6eeabf95356a8a21Virustotal results 19.67%Heodo
2020-09-30ROK844PPEUZ.docdoc 9db3206fcf75456b25ae104157caaac6beaca60e9105c9e6e0eb08d78616b1c9n/aHeodo
2020-09-30REP_MLLSYHE40JYM.docdoc 0a2e10583a6c70298eb3c353e0a15ebd98c8a9ae09db8e6cc9cef513e39c95dcVirustotal results 21.31%Heodo
2020-09-30305231655059004426.docdoc fc6f0ac3e38b970866e30342911b1f72bc2a028a33a093badc8c5694321d5808Virustotal results 20.97%Heodo
2020-09-30Q2507FNO.docdoc 8ab2e6cb8892b88bad960fc01887038298cebc93804c11f3bf92624541fd00den/aHeodo
2020-09-30INV_VE3699512238ZM.docdoc bf10b7e9f1ff0345f426df6b7da95cdb75284d378f7ea29d192e24623e35f3a5n/aHeodo
2020-09-30BAL_2001119953466920147.docdoc e9ea0a15b6b1599685f85932e8f8621ebe49b8a64c3376cb3819d4b9f5b536beVirustotal results 43.55%Heodo
2020-09-30REP_UH0186195430WY.docdoc 09920ec2c5029cdb6177cee45414e34e9307a6f40548df1ba80385c44cfcc613Virustotal results 43.55%Heodo
2020-09-30REP_LPMYS1PDGK7.docdoc 1f7fb407f4aa9c2e8d59826ce97d6fa642f0103b0c140bb54dc65cbe8f8c92f4n/aHeodo
2020-09-30X_UF7702988121NT.docdoc 58ac8a64e7d1de26e8f6081b9ae7bfb57cf872206ae1e11eb6c00dfc798752eaVirustotal results 41.94%Heodo
2020-09-3014PX3IXDFU.docdoc 1a2856f6dfce0f239bb89c2fa41ba26f9d1761dd09caa8312e58c26aa1411369n/aHeodo
2020-09-30Z_PO_09302020EX.docdoc 0bffbb268223d255d4ebdcee53bd0d8e990843600bf96f811f47a550d1e366can/aHeodo
2020-09-30INV_DY8051984079FM.docdoc d8f8b40e6c0fff5344fce0199e4fd683f50bc846af26963d53ea1554aa202e61Virustotal results 35.48%Heodo
2020-09-30BAL_VWJTQXGYB.docdoc 8c21463a0b127e2db497f399810180572cf5e4027f3942919aeeccabf1d3753bVirustotal results 37.10%Heodo
2020-09-30DOC_22449361574151.docdoc aabd54aa244d3a19daa025d685a63495581f02a35c44e11bdb76ea7bbf7360baVirustotal results 32.26%Heodo
2020-09-30FILE_EQ2226020019XJ.docdoc bf8dca92c415f9441d506b7b5aace8b6d6bfbd8d67351b32abc27e2ef1e242efVirustotal results 32.26%Heodo
2020-09-30REP_PO_09302020EX.docdoc b3e10600287dfaee56f53325acb38c44c75d92fdda24bce58c9d231eebc0bd06Virustotal results 32.79%Heodo
2020-09-30BAL_PO_09302020EX.docdoc 48e23cb77f6629ddf1c1b70ff1af00789fe9ed39014db2e97b4be24c2e13a168Virustotal results 30.65%Heodo
2020-09-30BAL_78442519.docdoc 75f032ed1b4c5d9738c4ebee1d878f1fe5307cba5c43dc44ce2443a640e7fb2fn/aHeodo
2020-09-30INV_16325747.docdoc c7e94b09a7bf83d363a7949d7aef5bba5516bd5b0e0c149bbd1dc341b9cd5180Virustotal results 31.15%Heodo
2020-09-29FILE_PO_09302020EX.docdoc 5bc9314961b874f09854775cf9f6bce09cc9c8106200074edb961cd544efb675Virustotal results 30.65%Heodo
2020-09-29INV_ZRL1W4D.docdoc defbca721d5850239ce954155a629ed1728ce578781b3e387d8c6305144f0838n/aHeodo
2020-09-29FILE_PO_09302020EX.docdoc f3156f2dd9bbd4c0f1164e92165433c3f689d7777297b5149c47299dfbb1d840Virustotal results 27.42%Heodo
2020-09-29O_24855731.docdoc d59faf29c8fe5f632a3b7d91802b08434241b502d47b2bcdf2276dc68e4e7d48n/aHeodo
2020-09-29INV_GP9975069918ZG.docdoc a7bac9b6662da2eb4c3fa6f12c10d790ab6b8ef1735241fcd2a4d35a152a8965Virustotal results 27.42%Heodo
2020-09-291VZH2T0.docdoc 14e6ea40cc1e124fe353ed7aeb27490dad58d6a116bfddc62aacaa02921c5d88n/aHeodo
2020-09-2970505785.docdoc 33c16dca57826043e0e0e906d157fcde3b15178d62747fe0ee0f10f1589d9498Virustotal results 32.26%Heodo
2020-09-29REP_UQKDILB98TX.docdoc b84c2da4ab10a702decf8a1bd04eee1ccd250b8b792bd32957cd1bcac6c50861n/aHeodo
2020-09-29BAL_ZJ7439307939GJ.docdoc e4f489cca030944314421b5bc6d72833515d692b991be16287fb9a642785294an/aHeodo
2020-09-29BAL_TRQ_090120_SEQ_092920.docdoc 610f9f088ca6f20a7baa29fceb9bbea541e2e1820131ae7015e9cf236baf1ef8n/aHeodo
2020-09-29G_VI1374186381SQ.docdoc 2e997b7baaa8519fff2a756670247b75a5b9fd00addafb830d7ad6ebc7ad18d1n/a Heodo
2020-09-2904757657330119.docdoc edda9cda5227aaf1c5490691422022a91aac808a0c2b6707291068ac611dabaan/aHeodo
2020-09-29FILE_SB1932428846NC.docdoc e294f57a535adb7cfcec6ecf45ef8b940a1e67e3955a2b8ade573d84fbc1322fn/aHeodo
2020-09-29MV_0420740835941.docdoc 9243618e3533ddf75d1106555b3aad908b5a34d8ae7a1065a683bf73e6b21a4dVirustotal results 31.15%Heodo
2020-09-29BAL_YY2367133773JU.docdoc 9025b7b53a4f4ad612a95f5a281a443768dea8de3c043f33a0f6fb1f9bd0f763Virustotal results 30.65% Heodo