URLhaus Database

You are currently viewing the URLhaus database entry for http://ilrafrica.com/cgi-bin/Scan/gwvncb3kh2kmqu3kz6s5ro1f/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:729020
URL: http://ilrafrica.com/cgi-bin/Scan/gwvncb3kh2kmqu3kz6s5ro1f/
URL Status:Offline
Host: ilrafrica.com
Date added:2020-10-21 11:51:04 UTC
Last online:2021-12-03 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-03 22:56:08 UTC to abuse{at}hivelocity[dot]net)
Takedown time:1 year, 1 month, 18 days, 20 hours, 27 minutes Bad (down since 2021-12-04 08:20:23 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22MKB_XIM_100120_VSE_102320.docdoc 838408d31e494e72b257feeec73407a2f778e6ecc47754ae16af0290515dc9fdVirustotal results 42.00%Heodo
2020-10-2291965471569855372530.docdoc bad9235b37efab34f7e6cf91e6a80803fdcf8903e2c61d0d6c1f5f9d773da112Virustotal results 48.08%Heodo
2020-10-22DOC_XU5854950437RY.docdoc 2bfcddec3862fcbe053dd6a0d03d5987ccfa1942950e8c9bea56fa41f6fcaa5cVirustotal results 49.18%Heodo
2020-10-22L5NTX4TX.docdoc fc01225e954f0f4adcca14dbfe1849fd7b5e81afae3a9589177409e2e2c2e972Virustotal results 46.15%Heodo
2020-10-22VD4330534485JK.docdoc 056f25e8944119ad3d9d651d77cc32cef6621c5cb3498b47161738be7aff416eVirustotal results 49.06%Heodo
2020-10-22FILE_83502411882816548222195.docdoc 486ec0b6be1825886bf09579218543b12ad5ee75da313f4aefe0f9ad0b027f89n/aHeodo
2020-10-22PO_10222020EX.docdoc ff7bc571e097d09b02234d6bef98da4468da5c7dfc197e2cb20f1a00eb85f61eVirustotal results 45.90%Heodo
2020-10-22JQ4397352352GV.docdoc 00be3474f86c64b8ed871822ccfe02e7bdcbb4b5132682ee36915e8553952648Virustotal results 48.33%Heodo
2020-10-22FILE_NMP_100120_GHU_102220.docdoc 9fe7e239b00579f78275ddcdb282bf2b112dad4d3a0bbc7f183e800244486bb9Virustotal results 48.00%Heodo
2020-10-22REP_0M8H50WRC2J.docdoc a1430eef6f6acc51cfc4215bd06407ebfc4f5ac126d9f05c27b3cf359dbb816eVirustotal results 46.55%Heodo
2020-10-22INV_629645783821396.docdoc 0b25fca35bd60d2257616a1c1adbf89fefba07969c5a0fc3aa22d3f43ad7c2f4Virustotal results 45.00%Heodo
2020-10-22PO_10222020EX.docdoc 9b4d04d1dad15a8a798ceba5f12e03c81a04335dca8703f2e4790675688590aan/aHeodo
2020-10-22FILE_533406191.docdoc 95c62759d32e2a426433130be7fc1c17a3d3787359258f3af33f61760463eeeeVirustotal results 40.98%Heodo
2020-10-22GL3692438991FU.docdoc 1a8e2f855156722a9170dfcd7a57dfa4d375973ea54bc2b85fca299010c4e763n/aHeodo
2020-10-22CA_OCQ_100120_ZTU_102220.docdoc c4453119ba010924fa6571eee7895d995ccd52dcc8380f3b65aaa2bb6508290dn/aHeodo
2020-10-214813100862845.docdoc c772e92b4aa5c7e34108bb1b418cc47bf1561c6ea5944d194eff1af7cefbe4e2Virustotal results 41.94%Heodo
2020-10-21INV_TB1736497987KJ.docdoc 890535144da2084ee8e9431e6521be9719100cc5bec7679a4d7bdce3763a692cVirustotal results 39.34%Heodo
2020-10-21PO_10212020EX.docdoc 45624f05bc4fd26e7a1d0263d25d177e1296ffbc6c459542f3e64709f517f1ddn/aHeodo
2020-10-21F_QO7391838873VH.docdoc 707a2acd195f4e2ac6ab0bdd8c10bb19a6d95938a957ff75aab954aba3526fbfn/aHeodo
2020-10-21DOC_PO_10212020EX.docdoc ee8ef9beac4202e018577996e293215dd2cc1e260bca0ac0a38f9abcdcd4fa2dVirustotal results 33.96%Heodo
2020-10-21INV_JC3328128778UK.docdoc 202d0af84b5b68cf2a54ce8f9afa3befc8f994b934e380cbc1dab9dfdbd11bccVirustotal results 30.65%Heodo
2020-10-21V_24147901.docdoc bd69d4be2054f906ed811613ec77edd6981db0f342bc73d95802eb46a186f5adn/aHeodo
2020-10-21FILE_37543675.docdoc 5633dcdd6cb771b75b85211ece3df0d9190a2e7c2c0b24ebe6a33b8584b8470cn/aHeodo
2020-10-21Q_37574200.docdoc c0308a4a6567ed36df7165b3cffbe26f676322783de09900dd7b7e6b7d642b97Virustotal results 30.19%Heodo
2020-10-21DOC_43642058.docdoc f168ef97aa8cb399a6f327fb6a301f7ae5e115c7ed1ad5c8b59819663bebd7e2n/aHeodo
2020-10-21DOC_WD5357721759UA.docdoc 65afacffdde9c2202e28125192dbfc1094522200913e53bd6d003b6a1754f3f7Virustotal results 20.97%Heodo
2020-10-21FILE_PO_10212020EX.docdoc 27a0f68aaff44c4e5adb18dd89c4cb3b92fa305b84cd9bdfd76c9a5d8dbf58f1Virustotal results 20.00%Heodo
2020-10-21Z9VQRRQ23HZ.docdoc abd94a7b58ada746b22d9d6a4ef2b3847deda4d5569325459951c0c7f3b2a355n/aHeodo
2020-10-21EGI_100120_DEM_102120.docdoc cdf08877df82aef07518f10414f3dc1ec0bca6a662ee6191b7c76105bb51a0b1n/aHeodo
2020-10-21H_HPE_100120_UGE_102120.docdoc f647e044db03f36251bf4a293d89b0d2272806920917eeb10166f289f3a6a503n/aHeodo
2020-10-21UNRK_22289855.docdoc 146e75921fa5eb2ef11001446c1120af2407e159711d06d62fc6a8b2e0da6386n/aHeodo
2020-10-21DOC_87832627.docdoc f93730c27fbb9a6c6cc64e5f4d9127854a0c11d165e699569dd0828ebee3ec4bn/aHeodo