URLhaus Database

You are currently viewing the URLhaus database entry for http://www.uasingishu.go.ke/wordpress/wp-content/uploads/NDaCRDn00nCOXaDrkn1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:767301
URL: http://www.uasingishu.go.ke/wordpress/wp-content/uploads/NDaCRDn00nCOXaDrkn1/
URL Status:Offline
Host: www.uasingishu.go.ke
Date added:2020-10-29 23:32:06 UTC
Last online:2020-12-15 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 23:34:11 UTC to abuse{at}ripe[dot]net)
Takedown time:1 month, 16 days, 13 hours, 0 minutes Bad (down since 2020-12-15 12:34:50 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-31UNTITLED_PO_10312020EX.docdoc 858159295a83a85ce85a8e18a4398873eb02dfa32012325f963ab2de57c8c0aaVirustotal results 56.25%Heodo
2020-10-31REP_43628556.docdoc 4bab596233b6ee4131996d95b9d863e6833d285d6f87dd2bd841f2682b6146a3n/aHeodo
2020-10-31REP_75533371239.docdoc 396b664fbdde301d1ebedd54f4beacf4726ef9fe1d0807a86fe0b00e0a71772dn/aHeodo
2020-10-31UNTITLED_05102537.docdoc c21fd3f4bfb11db1fc709bca4079eb7f97b6001e5695a430566b61e5e630053dVirustotal results 50.00%Heodo
2020-10-31MES_MVE0J2S8YIPR5U.docdoc 615de4c01c61e261c017bd338c822b21b294728d9f7bac3199e139be0d1c3675Virustotal results 30.16%Heodo
2020-10-31Mes_TAV_100120_RGK_103120.docdoc 03b477c67a30f1cc63aa897f954709c42c74cc2907d8639805398a4615cad1b6Virustotal results 52.38%Heodo
2020-10-31Dat_ET2514393473EW.docdoc b48b7231ac7d5bc0a2ba5883e7a634a557c606b06b97bf45b2842523959c4a37Virustotal results 53.12%Heodo
2020-10-31dat_PO_10312020EX.docdoc 6b199ce53786e4647258111798d4a9f14df4220415ed15639338c5860d98695aVirustotal results 53.12%Heodo
2020-10-31file_PO_10312020EX.docdoc d7c0fc3658da4a6040cab7aff29764849e26c699642492446759314c94586b6dVirustotal results 26.98%Heodo
2020-10-31list_PBU_100120_VNC_103120.docdoc 0406910d3c48dbd18d57086dcab9b4f73a8081dae9fac3010f0ae90b73c7c34fVirustotal results 54.69%Heodo
2020-10-31file_U95SZN4E.docdoc d0173484a8073ed5336acc965770f3875b704785bf08f59a929f20c65512e1fbVirustotal results 54.69%Heodo
2020-10-31REP_99801741.docdoc ffc63081ade619c07061526c15e53d5dd012da2e842f479fefc0c27f46ce2bebVirustotal results 55.56%Heodo
2020-10-31Attachments_PO_10312020EX.docdoc 9c96edb7b23fe316d7ea6705b137c283da2aba4f7dab4537a681e7e5d031b0eeVirustotal results 25.40%Heodo
2020-10-31DOC_RJA_100120_CUZ_103120.docdoc 4eabd4dcb81c28e86bbfd9ac62090d51aea5a733c96a8f3a7ad130a9841bce71Virustotal results 54.69%Heodo
2020-10-3144136693.docdoc e5cd96964e28663db382662eddfbd4bcd53693acaa9f14bf3c7382c61a16aff5Virustotal results 26.23%Heodo
2020-10-30FILE_ZW8138256728GV.docdoc 26b30e58ed2342d042367ba0487873439d5c9c28920ddd000bb94b3eac79d94dVirustotal results 54.69%Heodo
2020-10-30mes_FU5596022844ZD.docdoc 14a8572928770f8d61fa05890c3e0a5cd4396bfde2ce2763d533e89d05120d34Virustotal results 25.00%Heodo
2020-10-30dat_PO_10312020EX.docdoc 07cac58fbfac34bd4e22b0dab98273a45a147dac7d38266ec0749fb5fd85b98dVirustotal results 23.08%Heodo
2020-10-30arc_PO_10312020EX.docdoc b79376701bfc97b082e9d8d61f6886b399692a2b154c6095559ab1da86e4c518Virustotal results 53.12%Heodo
2020-10-30Mes_19601798.docdoc 5041a2eae4b04f23df9804031b3a30e815e0c2310bf42d82176cb89618617933Virustotal results 55.56%Heodo
2020-10-30FILE_62385626.docdoc 4a1ebe8938ac9ac6ae7b502c4561bf514bc47ccdb87abae9777a5ac526d6540cVirustotal results 54.69%Heodo
2020-10-30LIST_EFE_100120_IFR_103120.docdoc 78bd1c6e03aab90ba0350183bb9aba52148938c5c4384fb2695473c6540e139aVirustotal results 23.44%Heodo
2020-10-30Inf_RWJ_100120_KEC_103120.docdoc 0df4e83145becd16b2074bb93563596b613e43856bbd653b98a316f5d92ab817Virustotal results 23.44%Heodo
2020-10-30FILE_86146415.docdoc 2004d64ee603572e13a168eca558d2ade8169581208022e51896e0589e07116dVirustotal results 32.81%Heodo
2020-10-30inf_PO_10302020EX.docdoc 6263b8ea9431ac48bf402098737c84a9cf49c01488319875132ef15ef7d5c6e7Virustotal results 34.38%Heodo
2020-10-30Z_PO_10302020EX.docdoc b86e09a5bdebde57bd67e1fa11ddbd3381e5972d091fdc61b68e34226fabf084Virustotal results 33.33%Heodo
2020-10-30UNTITLED_G1XL4MEO48P.docdoc 1b230d33228fd383eaf4cc6faa376c0173fb8ff8d70c42dc9ab1ee5eacb411den/aHeodo
2020-10-30Doc_48849449.docdoc 023fdae311195c64889d2c87831a470d7c4826a755cd385729dc6bb02281c4e5n/aHeodo
2020-10-30INF_U4LBXB8U.docdoc cd7af62b6cdbf35cdd60b11e87084e9e0c08ae9a790abe502c3a9d5a62c4e8d7Virustotal results 42.19%Heodo
2020-10-30Attachments_FW426V7NNSE8.docdoc 5aeb983f62e296373a25bdde163ab799f0bd688f40567310960f16b815921687n/aHeodo
2020-10-30dat_52299869.docdoc 578a7143a40755b7d7601a1b0e3f660137971473556e817d2a0e2ca57bc91053n/aHeodo
2020-10-30ZR2620528182AY.docdoc 33478c951541dfc62cd1b974afa9e6be46b51b140a5228aa4f34f417a17b8a64Virustotal results 42.19%Heodo
2020-10-30FILE_69148756.docdoc be0b7b1655cf76359f685b7367592ccbacace133e9a4b1180b5dd7c364d6be29Virustotal results 42.19%Heodo
2020-10-30UNTITLED_80498324516182834021840.docdoc 7c159d17e809a78bad3e024cda533ebab493cc8519755e2946af59e11eac9eben/aHeodo
2020-10-30arc_75393153.docdoc a3c09116b3564a812d894ab750990565e22b18b97a47c138b3b271f1e7e5f666Virustotal results 42.86%Heodo
2020-10-30LYPT_AE7788010610HZ.docdoc f47484c61c7b2b0541690f5cfb219d2efe962b5204064435481f99e8ba92f95en/aHeodo
2020-10-30FILE_MP8477359827HW.docdoc d6f5c2f6c473a5df7285cae32d8806ee2c6ee513400416463c34c7f6b3dcc703Virustotal results 42.19%Heodo
2020-10-30DAT_16493133.docdoc 0a44f2d88bdf47cd0c75648b07e6fd7ac80b20ebbe7f6509fab11f28872ae12aVirustotal results 38.33%Heodo
2020-10-30WDP_100120_QLB_103020.docdoc 6270902fc810af901f9685bb0b3251f8cf96445514e9bd288b51d51156701665Virustotal results 25.40%Heodo
2020-10-30arc_PO_10302020EX.docdoc cdb79e413c85c2fa4724ac77b430ab5a6a0c770f7f6a640fec00d946a93f5e09n/aHeodo
2020-10-30Attachments_651Q6HUGZUKR3K9A.docdoc 289f8b4babc8f697bcbc3125ded9cfddefa96b986243538034beda8361d69a26Virustotal results 26.23%Heodo
2020-10-30FILE_IZX_100120_QWU_103020.docdoc 39991605b314bb39a573ea29a1b1cd2904615afe76292c0f3b6afac181a0d6d0Virustotal results 26.56%Heodo
2020-10-30FILE_WEVBEDFPAT9DS.docdoc 9210f9032280641d080e5abde6a49a3032839cec91f757f2469a4eeeb4080afcVirustotal results 26.56%Heodo
2020-10-30WQ1354832597NO.docdoc 84f8bd87a1f8207da3a4722b9eee322be498919fed6323fe33c0ce60ef7aadcfn/aHeodo
2020-10-30mes_SZJUE1H22KPFL.docdoc 621f149c8fdf5abbc449baa3bc86423a799301ca3017950f0b173a6977033e88n/aHeodo
2020-10-30LIST_68114352531803824208.docdoc d577446435b94d0af2a829f1160b594e95c8051f6b069400ff61fa38d151ba54n/aHeodo
2020-10-30FILE_71413565.docdoc fee7c3d92d847b227a0310837bdd5bd774db43c7793d9e83c31405a79a35b9cbn/aHeodo
2020-10-30Inf_61504696.docdoc 6061326ca1f6965d9ff04a37eb1defb55b410556500c197c6d8c9207a4432fabn/aHeodo
2020-10-30Mes_OT1736136650VE.docdoc f4983c5881da987bb4dcca9069e0134657dbd559cf50165c0f35c3f1c4595948n/aHeodo
2020-10-30FILE_38676613851903866.docdoc a120ab7f12256c4b260034ecf26910f2eb405bb2c41ea9d1d78fcd2f529d2debn/aHeodo
2020-10-30file_QB9607607614NW.docdoc 3619ca27723e87006b7061bd608e1e02d5087392ec513cfe82ecec069074fbd7Virustotal results 41.27%Heodo
2020-10-30PO_10302020EX.docdoc 8c5ec7de8acd87d586e9bf7a74458c2a96f88ddbeacbde0ae3791d84594cc983n/aHeodo
2020-10-30IRL_100120_QHX_103020.docdoc 6b88f01b98b04205fdeaca9ab7f387ea479efbb68e1e0a940c909d66e6ed092bn/aHeodo
2020-10-30Doc_BB0806002891KU.docdoc c5464029a0c6ac085492b9e9e1380d0304bd195c8de6e1dd71b51d4c9f8a5433Virustotal results 42.19%Heodo
2020-10-30DI56KMU4VQXZ7.docdoc 8cb962ad1798941eefe7a5f826ea5bebc726304af0337e53e6e34d59a7715795n/aHeodo
2020-10-30ARC_662330266536207.docdoc d77f9d8ce192df999a4c7c9564c086962623dc1a6e020f14bf19f264f59d316fVirustotal results 38.71%Heodo
2020-10-30FILE_ES3324914624RD.docdoc 0b7f26dc76b83127cdf687f818e652f050a9b3726aa76bc30947f94e4e25ffd4Virustotal results 39.34%Heodo
2020-10-30VH9558183466DJ.docdoc e4c4aa874feb371209199ddd6b159ed4a677b94568dfe6b09351807263dbef9bn/aHeodo
2020-10-30dat_PO_10302020EX.docdoc b2f80aa2efc9abdf137f78f830f2366b29e5bba74409138f8db1ed6163e25819Virustotal results 35.94%Heodo
2020-10-30FILE_9409228962364825993.docdoc 401b08eb1c58500e67d4a452cf053775266c050d2e5cf3abc7b7d3ab0ac5bbadVirustotal results 35.94%Heodo
2020-10-30file_TQ2044553435ZI.docdoc 3faba02f0eb970ef25a2a874736e4f758dd3424cdba2637795ada41385024679Virustotal results 29.69%Heodo
2020-10-30MES_FQ6585751178FR.docdoc b33622a59cee3ca443a74701f86f58ee524e9901c05d359270575f52d7d37380Virustotal results 31.25%Heodo
2020-10-30REP_PO_10302020EX.docdoc 87582434c0b62f10bd24d5f8fe2636dcef3e0046373b8e05dadb27942be901f0n/aHeodo
2020-10-30UNTITLED_85503615.docdoc 1e2927648e6c1e230ea519611dc8ffc414549f3da0fbe74854b2b2431a5731aen/aHeodo
2020-10-30File_RNQ3JJIZH14.docdoc 8f0e22d23596c232df3d527d5fb36ca404eb518bbe7c375b7a7cd037354b02d5Virustotal results 28.12%Heodo
2020-10-29Attachments_82622551.docdoc 57a23ee50bad094280feb716af4f6917dcf92157f899a609736ead07c82e6432Virustotal results 26.56%Heodo
2020-10-29INF_CKE_100120_YFG_103020.docdoc c8a48cd16e560bb22ad74fe50ff278db8d542241f7ee298dfb9a902614537a3cVirustotal results 26.56%Heodo