URLhaus Database

You are currently viewing the URLhaus database entry for https://himalayankangaroogroup.com/wp-admin/bkmglyugbg-54/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:750942
URL: https://himalayankangaroogroup.com/wp-admin/bkmglyugbg-54/
URL Status:Offline
Host: himalayankangaroogroup.com
Date added:2020-10-26 09:41:06 UTC
Last online:2020-10-26 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 09:42:04 UTC to dcundiff{at}a2hosting[dot]com)
Takedown time:4 hours, 58 minutes Good (down since 2020-10-26 14:40:28 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26Form.docdoc 0b28aafc9c3a3a6c6108c222626c51b1f5840f4f5fe9484387ea3af62d715537Virustotal results 37.29% Heodo
2020-10-26invoices 561 & 0484.docdoc 040873cd03efa5769638b4eae9be50a3983a879a78d1e018d53bbf57227c6528n/a Heodo
2020-10-26invoice #5468.docdoc 0fadf140e2f2793463ea31ef4b20e33848cdf060db811d9ac7fbab6d93e31e0bVirustotal results 32.79% Heodo
2020-10-26LX-100120 DJDI-102620.docdoc 05d23786837f4fda591dcd1fd6e3505c416947521ed1664a16f2da45f774dcf8n/a Heodo
2020-10-26Inv. 4190502869.docdoc 30805773badbdb9de875c8c401a34eee69b6935c13a891da7b100437a9c76142n/a Heodo
2020-10-26081672.docdoc e50304baf418b794765ec3e14c25137e509a3670f0877da91666c85965993c23Virustotal results 33.33% Heodo
2020-10-26form.docdoc 9793e78a00a7f62a7b97eabab2bac7e0c47a4fef19b064fea4e839986760f219Virustotal results 33.93% Heodo
2020-10-26Invoice.docdoc ff2b4921249a74645095e01d292a40c3171d4c58a57cfe068ae978c9aa5df17cVirustotal results 33.33% Heodo
2020-10-26Invoice 0605573.docdoc 27e9000918433f7d6c6da561ba9ccbe9c1b5f39fcc35c44412c256523d9637e3Virustotal results 33.33% Heodo
2020-10-26invoice #478130.docdoc 2e90362549f361c65f023ecb6decce30e24d49f337b7127fdf8a2981b0e48f50n/a Heodo
2020-10-26invoices 8600 & 29697.docdoc 628fed623605c3ea52b5697e305dbc0c2e0ddd53dae6711ed1d89873c5e2f831n/a Heodo
2020-10-26YT00268 invoicing.docdoc 3644f728f8493e0b5ac1765cf86477f7cac2fa0fdc468ec6862b2af0d930dd27n/a Heodo
2020-10-26INV_777911.docdoc de8f1d660d3503e393ef82fd2f7989f03ec3671dca272bd17f06d68cd057f1acn/a Heodo
2020-10-26Electronic form.docdoc a2dc4080bb426f76c6182b98e4aba3b80c8912559d461039e4ff47fd7f2ea5d1Virustotal results 32.08% Heodo
2020-10-260095601.docdoc 0db761318752265daead2f33be7b9724ce5f262d370b8ccc175d3b7f0706e0e9Virustotal results 30.36%Heodo
2020-10-260074722128.docdoc 5076ce194b5a2117e9a5b76ce5a46d19f50d311972c90f247c56c509fa2791dfn/a Heodo
2020-10-26invoice.docdoc 3af5d11d48e38f6ebee51394386947a215718feb565ae8360f15b5ecc740ebfaVirustotal results 30.51% Heodo
2020-10-26Payment status.docdoc 73b2a8d09987c4e12440df5a5b85b763875a85119e900235550a3ce8ba1cda72Virustotal results 27.59% Heodo
2020-10-26Electronic form.docdoc f7fe94f74e26dd8d16087e9be2f1fc16e41600aa56edef4bbdc2a9281ce50f1dn/a Heodo