URLhaus Database

You are currently viewing the URLhaus database entry for https://kichai.xyz/wp-admin/3eJkZcUr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:764978
URL: https://kichai.xyz/wp-admin/3eJkZcUr/
URL Status:Offline
Host: kichai.xyz
Date added:2020-10-29 11:37:06 UTC
Last online:2020-10-29 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 11:38:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 12 minutes Good (down since 2020-10-29 14:50:12 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29dat_40635339.docdoc cd3fe863b543b7cff0caa09fe57459ed428b05158a34dd748438f0f7a671fabbVirustotal results 27.87%Heodo
2020-10-29Arc_MNZ_100120_GXQ_102920.docdoc 9fe969fee626debd81e116bda0f8fba99a6adf05e1a8265e3e9d93df703da84bVirustotal results 26.56%Heodo
2020-10-29FILE_5Q24AQ54H0.docdoc 0cec6f211eea415989b964dbdbbf4da0f4d0dfc4b70990a7d27491cf154615e8n/aHeodo
2020-10-29DOC_AUN_100120_BSI_102920.docdoc 3a2e90fab180e4802d87707829a02157b25a93f71da8a2a62796b59483d315c7Virustotal results 26.98%Heodo
2020-10-29Attachments_ZFL04656J30CWBEI.docdoc ac100d3e7a4985580d980cb7dc26527d01d4166b7bc89405dd21918ae03f7faen/aHeodo
2020-10-2957376384.docdoc fa68a64196793116b8b029723e9a7fd7d6a7e5c8bbcc752be10b93c5575ebb03Virustotal results 20.31%Heodo
2020-10-29REP_LVT_100120_SQV_102920.docdoc c56962ccf0f482b04c168639afb894430e7cb71c873faac02d8f3a34107f33a8n/aHeodo
2020-10-29Rep_RKZ_100120_JGS_102920.docdoc ae454b06f63308de7e1a613281feea2eef089041c67af45e72ceec804482b526Virustotal results 20.31%Heodo