URLhaus Database

You are currently viewing the URLhaus database entry for https://kofamonline.com/wp-content/ZPLNMAAfAbbu40BVNZmHDTvi0TJjG4L/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:760543
URL: https://kofamonline.com/wp-content/ZPLNMAAfAbbu40BVNZmHDTvi0TJjG4L/
URL Status:Offline
Host: kofamonline.com
Date added:2020-10-28 11:13:04 UTC
Last online:2021-01-22 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 11:14:07 UTC to abuse{at}hostinger[dot]com)
Takedown time:2 months, 25 days, 12 hours, 48 minutes Bad (down since 2021-01-22 00:02:52 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28FILE_KZH1N9NY2IVM.docdoc 2a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7Virustotal results 25.81%Heodo
2020-10-28list_ABL_100120_ZZY_102920.docdoc b004139f56a3790ffec0ba6852e8ead3947b000f2cbc61be1754b91a69633354n/aHeodo
2020-10-28File_PO_10292020EX.docdoc f22f6b796d73cadef21281fb4120d425395b7c6457e38524dde128830ccfc02dn/aHeodo
2020-10-28Mes_YPA_100120_QKV_102820.docdoc eb056d51f99a6aeefbd8db271b24784e988b456f939812f40b9b6108a4805941Virustotal results 22.58%Heodo
2020-10-28Doc_6490358137301110.docdoc ad10b386d964b6056e529c2bdb70ccb19ba21b3b0a59ac606113fedc49626b81Virustotal results 22.58%Heodo
2020-10-28MES_57824032.docdoc 7384af9684329dd3916fa070ae356428bfb6f43d3ca6aa725f92d696dea83f41n/aHeodo
2020-10-28list_PJJ_100120_KYC_102820.docdoc c2d24878a478d12f42849ded89565fe77905f7af790b6a7272ece4fc9db45fe2Virustotal results 19.05%Heodo
2020-10-28file_327088438045383.docdoc 5da940231b1ebc70e4c974d89da825e72365c081f4b224b0308a7298de66a788n/aHeodo
2020-10-28Inf_87117048943597421014024.docdoc c0a2014dfca67b622a9a96e4d169601563264a29bb55b9e9b8f1934d610183bcVirustotal results 17.74% Heodo
2020-10-28ARC_FHP_100120_XLM_102820.docdoc ac9272ebdc022c3e93ef6dff217e30a0434094ccb3b6c5ab79cc97a94cf1825dn/aHeodo
2020-10-28INF_PO_10282020EX.docdoc 93d882200983e8ea91da547916ade52e52c5f684c19434eb8e3312b4d4251bb1Virustotal results 17.46%Heodo
2020-10-28ARC_7430959103.docdoc 6c0cb9fa14216686237503039df79f6ee1a2766d5878c2e3ab77c9ace4204c11n/aHeodo
2020-10-28XJRA9JPC6R.docdoc 5ce0046c606a280f8d74e5263eaa3e9912f6f232c7508ed71f50e8a4972b47a8n/aHeodo
2020-10-28List_NX5130474668PF.docdoc c3ab88e066a71a81d82954f02589e7b1e912add8716a76fbe482904abb954376Virustotal results 17.74%Heodo
2020-10-28doc_NQ9EY506CJBO4.docdoc 19377c68fd4d0b3d66624ba4a1aa465efb840857e142ec38ddfe4e1e9c573b8bVirustotal results 18.03%Heodo
2020-10-28mes_PO_10282020EX.docdoc 7f6ef7fd6f76a1ef0eed201b10fd39944874e657f56271aee75d090d57672248Virustotal results 26.23%Heodo
2020-10-28Attachment_NVAO5I529R04HDL2.docdoc 1bb8a0d1e93744c80a39b6c4fbbcf82de0e0ad276098c7ef29a556daa1d0fa15n/aHeodo
2020-10-28Attachments_AF4228250139TY.docdoc 771ba9743eaa7a81ea01d78249e8ce6036aad863239b14e7398d964e75af7364n/aHeodo
2020-10-28List_HW3776526007YN.docdoc 193422b30b299a52450704ddbc93cc49c2bf39fb28b197b01d27bb4ed99c09e7n/aHeodo
2020-10-28List_47456101.docdoc 245da199877ac955b9c2640666afb19d13d640da90766a000f6fc8b2c909582eVirustotal results 19.35%Heodo
2020-10-28Attachment_ZWI_100120_JDK_102820.docdoc e3f985d78f34ecba84d0385e8f3eb538aef89ae24be739e98166ce3c3422b236n/aHeodo
2020-10-28PO_10282020EX.docdoc f976e3edc1892c2009a8000edb80c5329f8ca920af116372b2a274488ddba5e8Virustotal results 17.74%Heodo
2020-10-28Rep_BXN_100120_UCF_102820.docdoc f6534e33c00179aff63a48e6ebadc4d2bc15c3203361b67264ce1894ff12517dn/aHeodo
2020-10-28UNTITLED_PO_10282020EX.docdoc c7a9fcbd5e7cf2f7c00c2ce737e5f37d79fca2af4840700fbec2812fe888df80n/aHeodo
2020-10-28DAT_PO_10282020EX.docdoc d424fcc461427fd257e6bd50b98d81df0efc3254426388661e5ec4d9a4815fe4n/aHeodo
2020-10-28Arc_YL5547680112MC.docdoc 7c5cba3f361edbd305005728464aa36e44d98db05cc52860a979780b6036fac6n/aHeodo
2020-10-28FILE_AZN_100120_MDQ_102820.docdoc 06604f59215e3e640ecafb3ca8ba3151c4ef3dbd390ac1c996becc39c0540e24n/aHeodo
2020-10-28arc_RK0816588371XY.docdoc 320e1d251976122a8a99eb8cea6215aff119aaa931d99ff58c30e220a062044fn/aHeodo
2020-10-28FILE_HUS_100120_VHM_102820.docdoc 6a3681628d5e90051c68dd3bf6855abcdff9d8b6e25447bad58745cc5406d4e2n/aHeodo