URLhaus Database

You are currently viewing the URLhaus database entry for http://meca-global.com/wp-admin/3077692-44569/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1968729
URL: http://meca-global.com/wp-admin/3077692-44569/?i=1
URL Status:Offline
Host: meca-global.com
Date added:2022-01-11 22:39:04 UTC
Last online:2022-01-12 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003883227 created on 2022-01-11 22:40:11 UTC)
Takedown time:7 hours, 42 minutes Good (down since 2022-01-12 06:22:57 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1254124.xlsmxlsm 775e8ead32426df8843052b194bb6347952c58b1e93c88fcd4b5332c9cb72a41n/a Heodo
2022-01-12393107_455.xlsmxlsm 697527009070e730447f346637ff5ff6ad458be500e870bfed11d033c4015631Virustotal results 9.43% Heodo
2022-01-1253253_71.xlsmxlsm 0ac0e45bf6bddf2f149dc232e277e24170f4ae358af7a92e02ebe95eab27361dn/a Heodo
2022-01-122377-23.xlsmxlsm c3fa8b9cc4ef363ee4e4c3a85b6c193d7c5fbe880eeb049cf36feba33777ade3Virustotal results 12.70% Heodo
2022-01-1296520104_567018.xlsmxlsm e087892cbee4b113dea70123c9646198f3e1d0ca64f43e6d12861ace1b5c1429n/a Heodo
2022-01-12HZU_92328.xlsmxlsm f3d1334b346c1bab22c541a6fb05cb2f0bcbfe8ba5a055d111b1c05505d5baffn/a Heodo
2022-01-12LJN6.xlsmxlsm 599ee297e7f0005588a3ec6437b689e5c4d2c07be1d974d3b0011f4cd1b5cc15n/a Heodo
2022-01-12ZOM_8338.xlsmxlsm c42c6b271090675b57d6970aa659e468606dac00d39875f1dd85f57a9f203654n/a Heodo
2022-01-12ZXEE_265704.xlsmxlsm dd8a4718b16ebd639c4622884cc34f8f052f1655e71421c5bdc10898ffcd9c83n/aHeodo
2022-01-12nou-8398753.xlsmxlsm 18bb9fc6b0ed30350713c8e1f45feb512e0120b4fd7c052c74811b300fd597cfn/a Heodo
2022-01-123965356_1306955.xlsmxlsm 663ca3b8545e4e02572b5d348a1f77c7ef30d1810e8adbe25dd699b2cfb1792fn/a Heodo
2022-01-12vgalcla_03.xlsmxlsm c95bf0dd160b7a12ab600aee9220e652b1b1cc3b006f264c324a0c0a9d5aa257n/a Heodo
2022-01-12778RKPSOGNI_7398745.xlsmxlsm 90c68041ea2e1e9b44724b9e68a58b8490996a52a5c2eda58d2eef0247b37283n/aHeodo
2022-01-1229DQLRVJ_17314809.xlsmxlsm 947dc8d6c337a63466168a9efb2e42e692fad8da89af9c4c295fcd174a89c979n/aHeodo
2022-01-116537114798823980.xlsmxlsm d3e6a6a97ad6e4f79e73386e88cddd5b958d0f8745c551837dd366b929671704n/a Heodo
2022-01-11238046256802.xlsmxlsm e06e1cc33f42f59f86b44d17359234628540e287dc10a39ac66ae21449abd380Virustotal results 9.68%Heodo
2022-01-1146431_01814195.xlsmxlsm aaa2fbc449fbe3b4eb3c69e272ff4b1f3723b0741d5fe86ced352aece337439cn/a Heodo
2022-01-11exupn-8339.xlsmxlsm aa920a2c74b8982c5dd77f97f0dd2d6c7fd69f047983447d6ae43cdf1573b07dVirustotal results 9.84% Heodo