URLhaus Database

You are currently viewing the URLhaus database entry for https://ilrafrica.com/cgi-bin/Scan/gwvncb3kh2kmqu3kz6s5ro1f/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:728425
URL: https://ilrafrica.com/cgi-bin/Scan/gwvncb3kh2kmqu3kz6s5ro1f/
URL Status:Offline
Host: ilrafrica.com
Date added:2020-10-21 09:34:12 UTC
Last online:2021-12-04 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-03 22:56:08 UTC to abuse{at}hivelocity[dot]net)
Takedown time:1 year, 1 month, 18 days, 22 hours, 37 minutes Bad (down since 2021-12-04 08:14:32 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22FILE_67776134293.docdoc 838408d31e494e72b257feeec73407a2f778e6ecc47754ae16af0290515dc9fdVirustotal results 42.00%Heodo
2020-10-2291965471569855372530.docdoc bad9235b37efab34f7e6cf91e6a80803fdcf8903e2c61d0d6c1f5f9d773da112Virustotal results 48.08%Heodo
2020-10-22GHI3MHDHQW.docdoc da03a9b55b6989c3afc8a859785e254418322eb601e9fcf2ce58da55d9bc7d0bn/aHeodo
2020-10-22Y_PO_10222020EX.docdoc fc01225e954f0f4adcca14dbfe1849fd7b5e81afae3a9589177409e2e2c2e972n/aHeodo
2020-10-22REP_752355693684438196653602.docdoc 74fdfd61d063ce1229044436c55ac1dba3e3c765e8b26674587cbde6704601a1Virustotal results 49.06%Heodo
2020-10-22REP_PO_10222020EX.docdoc 5216126689ce29d0ead65c0774e9b395ade4b5c2ce71e69d464f3a603a22bdb4Virustotal results 50.00%Heodo
2020-10-22INV_KV0924579773KS.docdoc 24ca326ece108e2ec02346c32536bd5cd2a990364f8d8c9fa35b082ba4a68f2fVirustotal results 45.76%Heodo
2020-10-22INV_73806411.docdoc ff7bc571e097d09b02234d6bef98da4468da5c7dfc197e2cb20f1a00eb85f61eVirustotal results 45.90%Heodo
2020-10-22WZN_92098230.docdoc 2622c411514e2ebeb404ff72a11abb8b36da194d0f09dcc95869802a01cf4a20Virustotal results 45.76%Heodo
2020-10-22FBV_100120_CQR_102220.docdoc 4876b24f79e4db4a3df03efb480f32506ce94c7c60c1410d47b6722a66765552Virustotal results 45.00%Heodo
2020-10-22INV_629645783821396.docdoc 0b25fca35bd60d2257616a1c1adbf89fefba07969c5a0fc3aa22d3f43ad7c2f4Virustotal results 45.00%Heodo
2020-10-22REP_PO_10222020EX.docdoc dae6b8c95721c04d04a27385380dcf54fac171308904c972b9dd2d78235cc453Virustotal results 40.98%Heodo
2020-10-2276162323.docdoc dd44fd55293b9113d93ec32356861c6813ad6c23d399625147eb4ad930d71f24n/aHeodo
2020-10-225ZS6V1TNA5.docdoc 2da1ed7b630f4a606c6c65a41dc9c852015d64174113023eff5a63c64f5eac0dVirustotal results 41.51%Heodo
2020-10-21I_PO_10222020EX.docdoc 3af63f662ad3afb788f4f65538788a97811e2a45d869bf83d5ac6dfa9a2251e7Virustotal results 41.51%Heodo
2020-10-21INV_TB1736497987KJ.docdoc 890535144da2084ee8e9431e6521be9719100cc5bec7679a4d7bdce3763a692cVirustotal results 39.34%Heodo
2020-10-21PO_10212020EX.docdoc e5c6d836a7fa994928320dbfced86beeaa1fca7178acfcc05d083304f539cf88n/aHeodo
2020-10-21FILE_93930334.docdoc 6ba57b23af759ecff46938a23b32591f453cbc4d14eadc9dd89d08ff1d38fdb1n/a Heodo
2020-10-21V_03285526.docdoc c3caf9f914df7b8d90ac3dd35fd1ad24ec34a4d1af94293e9002a9f8f943703eVirustotal results 33.96%Heodo
2020-10-21HA3333135832MO.docdoc 7606c587c9a22687f99deb394aedd9be63d066c53c44d9cb78dc3a03319f670cVirustotal results 29.51%Heodo
2020-10-21INV_ZLW_100120_SLF_102120.docdoc c92778df4ae556cc2ad66979e6fafa9256ce4c9c7d0457c6525711429def55fen/aHeodo
2020-10-21Q_37574200.docdoc c0308a4a6567ed36df7165b3cffbe26f676322783de09900dd7b7e6b7d642b97Virustotal results 30.19%Heodo
2020-10-21DOC_43642058.docdoc f168ef97aa8cb399a6f327fb6a301f7ae5e115c7ed1ad5c8b59819663bebd7e2n/aHeodo
2020-10-21REP_SEJTM9P8Q7.docdoc 638d2c28c891f1eb997a450dbdc2f6f1a83b000d7b617d3000cf2b937275de99Virustotal results 21.31%Heodo
2020-10-21FILE_35294810.docdoc c795410a11e049b4c007e1648b82c47fcd32c76a3bdae2cc72ebe46aad435854n/aHeodo
2020-10-21CE0902575636HS.docdoc 503fdf65f1c044ed826175a175b354f7dfb32e1fb66e83065827d7365f1b9dc9n/aHeodo
2020-10-21FILE_PO_10212020EX.docdoc f0b8a05a58d78e1d29514ce3290a796d2b88e573e0ef4e917150153a2bf083a1Virustotal results 33.87%Heodo
2020-10-21FILE_PO_10212020EX.docdoc a002bd15074effe4548ccc07946e51276be1d1ffbdbe1e474aa78b2f629a997cn/aHeodo
2020-10-21941832900362.docdoc 0ee34b08635cebc909a2b1768d921c645fb1cf94ddf18ada0c4a5bf5f9481bf2n/aHeodo
2020-10-21R_610704819480920.docdoc b77d2293e1769638ff23750ab476d2eae143a5bbf834e756d17505298ffc2776n/aHeodo
2020-10-21DOC_8691870615047665323.docdoc 2da9ff6b9857ded2d05f53a3371381ce3ba9e5142ba1205b0089dc24eed9c7a2n/aHeodo
2020-10-21KF6559909998BF.docdoc 64c0402c0b906a218b1e4c2101145066a57b5a034a16a82957081f8ca15b4763Virustotal results 27.87%Heodo
2020-10-21INV_PO_10212020EX.docdoc 88c45b613e6367cbb58e012779f1cd95ff6a44efc175b2163185aa309e18573fn/aHeodo
2020-10-21INV_QUDIRW3S972J2.docdoc eecb224f52b8de54b58ba589efb3044d6c88f70246ec6dd1c134b186d1d8c388n/aHeodo
2020-10-21FILE_464150331223450283266.docdoc 2e56fde4acc7cac043046e86b999a37aeb702d863f9024c4ce83e95d7c787d70n/aHeodo