URLhaus Database

You are currently viewing the URLhaus database entry for http://www.uasingishu.go.ke/wordpress/wp-content/uploads/docs/xx0z8r61p-0096/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:723332
URL: http://www.uasingishu.go.ke/wordpress/wp-content/uploads/docs/xx0z8r61p-0096/
URL Status:Offline
Host: www.uasingishu.go.ke
Date added:2020-10-20 12:07:05 UTC
Last online:2020-12-15 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 12:08:02 UTC to abuse{at}ripe[dot]net)
Takedown time:1 month, 26 days, 0 hours, 4 minutes Bad (down since 2020-12-15 12:12:48 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22Invoice.docdoc ecfc89ef969dc50f07649db191efefa79a87ef3a766b56d53c5462c6abc2bf1cVirustotal results 42.62% Heodo
2020-10-21PO# 10212020.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 32.20%Heodo
2020-10-21Inv_6374.docdoc 2a603eb060abe8cf0ce5259b69da9cdd0e5c3015332a943828ef24212ae982e8Virustotal results 30.51%Heodo
2020-10-21Invoice #37950524.docdoc 7cb289ec6528b0539486ce3cfba77de2603160bea10cc4ffa3343920de3a2963Virustotal results 33.96% Heodo
2020-10-21Payment status.docdoc 9cdd0e1ab1bd327fbf175b974de32d3f5c7591a31c72a34a842e2d03d8706ad8Virustotal results 30.36% Heodo
2020-10-21Electronic form.docdoc 3c54fe2565b2e6ff66e9b1eb34fc93333f99d82c4c76d757292dd4e8c6af406aVirustotal results 32.08% Heodo
2020-10-21Payment.docdoc d6722700e4deec26acf704986fa3460027afa685e40acd627dd4d9b85c0f199bVirustotal results 31.48% Heodo
2020-10-21Form.docdoc ef59fe140a6b63b4aae9e7e31953441b4560e00bb76a3b2eef15fc04f5e1abb8Virustotal results 27.42%Heodo
2020-10-21invoice.docdoc 657afd533c3b3e60cb28b901496d7a4d42a96b0fbc931ca2630509aeaedda2bfVirustotal results 29.09%Heodo
2020-10-21Payment status.docdoc 23fb1844a3cad0f727d5bf74d8ed76b134681db7486450782109d760f792863eVirustotal results 26.67%Heodo
2020-10-21form.docdoc e9a60c57f83826d551499e5bf6d5e52d163e80c8348699eb508d92f926cacb91Virustotal results 25.86% Heodo
2020-10-21Inv. 09583353135.docdoc b60221fbb29e77ac3d7f84dbdeaeb51c021b9072f430873d8b52f30eafcaf81cn/a Heodo
2020-10-2100609955299.docdoc c197a6840f019226e39e14128490f861eb67b738ccfee85a256e97847047b769Virustotal results 25.81%Heodo
2020-10-21Form.docdoc bbc988f48c27a605a1c866c1165c802ecfbdb2c892889a0862a87d07938fb99dVirustotal results 25.81%Heodo
2020-10-21Copy invoice #5605.docdoc 51ab187886aefdddbe682cc0044049fd5c06bac5f1cda813a77165f3ad31548an/a Heodo
2020-10-21PO# 10212020.docdoc d8e0f462d8d75918d376254506d8d9ca846f6fa1f33076a091cd9f61832efbc2Virustotal results 50.94%Heodo
2020-10-21form.docdoc 31658c6055bda692c4a944b0dd23ef5f0ef7d312df172a1eafb6317a110f286bVirustotal results 48.39%Heodo
2020-10-21QL975 invoicing.docdoc 19a709ff8ecb374af7e40714b3ff541cc7753c7e69a7f0250d797356cd4ccb59Virustotal results 45.16%Heodo
2020-10-21invoices 4303 & 3218.docdoc 33931df25bbfed2013a987a32738c165a5799d274381e76cbf534ba189be293eVirustotal results 46.15%Heodo
2020-10-21Payment status.docdoc 58a681865ea454572eb661486c8e06854e90cc7cd2d5ab95ae331a724f5ce97dVirustotal results 44.07%Heodo
2020-10-21Payment status.docdoc 15680f3d4397a2ea2191e960421dd8650642415c14be15b1495f859bc6b9d7cfVirustotal results 40.98%Heodo
2020-10-21Payment status.docdoc 916c5fa5d800ce852e4e0e1c215daf1e813c868e5b1d9b0c7956b16ec6649adfVirustotal results 41.51%Heodo
2020-10-210032468.docdoc 663930eb12ff6afb8cd3d0410fcef8fa32edf4964504e10f0cd56af546b0ecb2Virustotal results 41.51%Heodo
2020-10-21Copy invoice #65083.docdoc f75dfd9100b7fb7c93a95812e11a04f911e4ed1f61fafa8b73c747df9898a212Virustotal results 40.98%Heodo
2020-10-20251720.docdoc d590ed65aef80ecdc7f0a44755ee436937f30c0b05287ce6d177b654512940e8Virustotal results 40.98%Heodo
2020-10-20Invoice 0078274.docdoc 368608fc48be7d6239425f9a9e23b2aa19d22aaa001796c8c0e391858bd2932eVirustotal results 39.62%Heodo
2020-10-20Form - Oct 21, 2020.docdoc bc671ede4242e59e050fff534673dd447ebcdb084f7e7504d004ca446707d409Virustotal results 38.98%Heodo
2020-10-20Invoice.docdoc 4b4c3539bff4d5461f5c5a5ceae568c2e301a62f273ac881508f6deaaea89835Virustotal results 40.32%Heodo
2020-10-20invoices 11015 & 92757.docdoc aa207e703858f3b5b98f6dde826e16108e94a533e26cc478693b1d39a14c7135Virustotal results 37.10%Heodo
2020-10-20Inv. 05605643.docdoc c1a2f053ac0b9cafe6d08072e6971d0dfad8f938cc167753df413b1a5ee4065bVirustotal results 32.79%Heodo
2020-10-20Copy invoice #788994.docdoc 2da7885a305894fb4a3cb76ff2aeafc9899cb7c590bf1179feea80f8795f9c30Virustotal results 32.26%Heodo
2020-10-20117971.docdoc 36bf9ecc1a8a1ba3e8b3adf9e916e0f5d5e7f0247f6c4efc53dcdc496443de74Virustotal results 33.33%Heodo
2020-10-20Invoice 0008617.docdoc c9804b898a9d2326b05f4037b2eace298777d1a387273033692c9f6deede6cabVirustotal results 34.62%Heodo
2020-10-20INV #000820839 FOR PO #5442525.docdoc 36a9973c36b4c8891b4ff704670f49374aab0db27ba22546659b76a7f9c942d7Virustotal results 33.96% Heodo
2020-10-20Copy invoice #13263.docdoc 1fad7db33eae6c2158f57709f82ff40f10276a88a34414418c06ad738eb22299Virustotal results 32.26% Heodo
2020-10-20E-100120 VNYS-102020.docdoc d725a9584594c0da62483ec85e99ce8baa89ab5be45320176bb3576abddcabe9Virustotal results 29.82% Heodo
2020-10-20October Invoice.docdoc 2c393e1c62282d084b3c0dd82e7795f08d0af0f150b7e6dacf81de3116186969Virustotal results 32.26% Heodo
2020-10-20Electronic form.docdoc 61835e08172767d73a9e6c5dfb1fcc8b904d60c3b9cd7b382bcfe43aeab5c2c0Virustotal results 30.00% Heodo
2020-10-20form.docdoc 7e136d3bc68a6578cdb157624c2783f78b48a13944133de3d0f5b0d34ce6ffa2Virustotal results 30.00% Heodo
2020-10-20invoices 421 & 48516.docdoc 5048d7b27c53cf32d071bbfbe3a208164d350d1d9ef8d2bcd423631b5d1b21dcn/a Heodo
2020-10-20invoice.docdoc e59ffb1d8684c5f593de0d953edca68b56546935b4c9eb2bfc7b55958865826fVirustotal results 31.03% Heodo
2020-10-20Inv. 028927.docdoc 781cd226d6af840c9c4fa2b90e0db5c547da1bd80ee74329a3fc82b164e69c38Virustotal results 28.33% Heodo
2020-10-20DG3942307720NN.docdoc 9a38f5de80aabc7bffe47ec6c557d18157418ea9a3d4fa365463c32f6e102abeVirustotal results 33.96% Heodo
2020-10-20Form.docdoc 47914da6e4ee4b6892b42cdb0076cc23a9887a862a7b366434d7c77c0a21123dVirustotal results 32.26% Heodo
2020-10-20XEE-100120 JBBS-102020.docdoc fcf66fd33f42c75abf852452c661e3ccc4f85c48a721dbc4471bd28332760145Virustotal results 51.61% Heodo
2020-10-20October invoice.docdoc 302086907da36d9af34abfae68ae96815cfd530e20bf3e4d40d520fd6816fe5aVirustotal results 51.85% Heodo
2020-10-20Form - Oct 20, 2020.docdoc c31795e9d2a3b7bf6e19d054a2574f0ea3eef997e49bd9318316efd609cada94Virustotal results 50.00% Heodo
2020-10-20form.docdoc 5cfa1457e7ddb2e7c49419cabef1c969debc4d677e7ca6f72d6edd8e2ac88a32n/a Heodo
2020-10-20CS15 invoicing.docdoc 9fdb062ded6d82fd2d2d452643f3eccce639b07b20b205b0ce7cb8ceb31ac487Virustotal results 50.00% Heodo
2020-10-2003506327.docdoc d2fe08b3c831101fc944a5ca54cfa5e7358df511efb6f8cb39d5036034553bf9Virustotal results 50.00% Heodo