URLhaus Database

You are currently viewing the URLhaus database entry for http://afrikhaya.demo9lec.co.za/ug1jxvd/THR5214/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1973542
URL: http://afrikhaya.demo9lec.co.za/ug1jxvd/THR5214/?i=1
URL Status:Offline
Host: afrikhaya.demo9lec.co.za
Date added:2022-01-13 10:35:05 UTC
Last online:2022-01-14 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-13 10:36:07 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 day, 5 hours, 33 minutes Poor (down since 2022-01-14 16:09:34 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-14GFT147377.xlsmxlsm de7e4158f8c853cec334533366fbfa1568ec9384f0e5d07d1bc57298aab905b4n/a 
2022-01-14N-76947661.xlsmxlsm 32247831bfb72b23c944a17a6881f8865b70f9d60875ba5c2f080c845d01c90eVirustotal results 26.98% Heodo
2022-01-1416753443.xlsmxlsm 5e5e12a3a114f3edcabd2e37239ea81f03db5f04ae7c6a5b5436f8898489f84fn/a Heodo
2022-01-14s_048.xlsmxlsm 9fc43645a59ffc54409d20d58c7198ee61f8ab3a982a0928bf62523b1c61a575Virustotal results 26.98%Heodo
2022-01-14497438138_8212.xlsmxlsm 38aa8bb59cfaed48d361e496e1682f677a3f58223fbe1a6a9e2e1fcd5d837c43n/a Heodo
2022-01-14379-92893.xlsmxlsm 15b5006b335aba5547f75fb7a9399251115e8ae410691b568fd1064c2facafe8Virustotal results 25.40% Heodo
2022-01-1443DHRBYGOHOO-11960.xlsmxlsm 3b63ba5e81eedd06656eca70b56b6d9490b598df1646dd83dacefe8cd52d6a77Virustotal results 23.81%Heodo
2022-01-14CH_692.xlsmxlsm 6ac14b86db1b807b8bdc126d8e1ba66536ff55b5fcddb9ba068bd70b176c52ben/a Heodo
2022-01-1485278-334574.xlsmxlsm 0e2db8bad325d450826ee98740532c44b36d70a95f31178c85a50f4e8ee9c8b0n/a Heodo
2022-01-14719025955131522.xlsmxlsm d7e424ccc4f316f9abbabc2a3b0bc47b61daf071111fed745056ffc823c541c1n/a Heodo
2022-01-14bdv_441439374.xlsmxlsm 77f9047608db228251671697e703de19448819776d18446a1c5cbae840087e02Virustotal results 25.81% 
2022-01-147336_520350.xlsmxlsm 5388d17d28ba671fbe8a27779a4ff0a97c15a00c1a91e946824b81b38c6d8e90n/a Heodo
2022-01-14SI-62849274.xlsmxlsm d55979fab69e6383de91fecd3232f4f013cc7eb8de5a4a0090c6e0a371765b4cVirustotal results 26.98% 
2022-01-14MYm_979795287.xlsmxlsm 28d2e274a082c7de870cd52bde0f9bb929bcb9331d7ce9e85f5c9bb6948a59dbn/a 
2022-01-1495499784_22.xlsmxlsm 5e752b11e5c8a995688ec34e8bacbf253a0450479c1c2582dbd770d004babe51Virustotal results 27.87% 
2022-01-143158_87362.xlsmxlsm 9914b76a0ba3fb9da5a56e91338779ce902665c925d401d929aadf7974293d79n/a Heodo
2022-01-14RHJSO_518.xlsmxlsm 948bece3441056d04af338e263063315d45921d28cf536276011fab5b2127a00n/a Heodo
2022-01-13nHmkKL-231.xlsmxlsm fbaad03de2f185ae958c7192e2215fb6678792763d4872c4d3081d8980edc463n/a Heodo
2022-01-13DW_43164.xlsmxlsm 88422e6f6a8baaf355add1168faec3c2cf520438933d982dcff40a31f2468a09n/a 
2022-01-13385437390_7.xlsmxlsm 7e9d46cddda81be61354089d761d2fd16244b505d6aed655e1fc0a44203cb37bn/a Heodo
2022-01-13QWWN_342421.xlsmxlsm 792a7b8e75aa51f90c66ee711faf429dfe3220b038cc3725ee935083fcb60e0fVirustotal results 22.95% Heodo
2022-01-1368765-7.xlsmxlsm 274a22a285c15f1070acc2711097ff652815cca8ec948def6056702cca72731an/a Heodo
2022-01-13HU_37.xlsmxlsm 93eff588c9152694a19cbbf9dcaf7e7185dd1a6b7e1165b73555bab7bd468d6an/a Heodo
2022-01-137510336326203.xlsmxlsm 8956b950352fe247497f8aa4a0738a1fd22c1e32a643a1e98ecc416229fa29f4n/a Heodo
2022-01-1365494_170007.xlsmxlsm f1ec4f871b40968083790f9f1e19eaf6c17301f20743055e00b6382b3d5b2f55n/a Heodo
2022-01-1316046GQSVJA_26.xlsmxlsm f82aed370591fd8b536179975bac82d0c6c17f97b74d1dcf5c235fbfb66dad72n/a 
2022-01-13HZ_2.xlsmxlsm 3be68616e8943e1a8b35ae8d39c7e26e6f949d3f5ce41072a3037bfafe766c14n/a 
2022-01-1317461260DMQAGNB_62263297.xlsmxlsm 0282a5f27aea18bebe2c3a6406c3145994755a9f37ec1e941ea0dcc1f6978550Virustotal results 33.33% Heodo
2022-01-13exjb_074.xlsmxlsm 8b8691c729c4aae4cda2049c3fcbf3153562829da68bfd3121e61dc3f9bf2cfbn/a Heodo
2022-01-13VWD_51.xlsmxlsm f6319e708e7c942acfec28dcc5e23df293475f01d892e4992d9717277f79d6eeVirustotal results 30.65% Heodo
2022-01-130112990344.xlsmxlsm 4a3a254a975f87ed78ab0ab53de0a7f8ab2235a1bc8abea99ade0593d3c2c450Virustotal results 31.15% Heodo
2022-01-13sn_35549456.xlsmxlsm 67db098ffc37f7ee91efe9d171ee286e1f72b744f50dce8d4e83309ba5f21593Virustotal results 30.16% Heodo
2022-01-1374354JGXNIRUKUJ-309.xlsmxlsm 8731dcd378702d6a9d4a679e338cbd69e94a5030d0dc0520456e30760f81cc6en/a Heodo
2022-01-136059233134.xlsmxlsm ac680177934f28cf84fc94b0e1f006de320955fd9f17bed4d39699cda13c8bd6n/a 
2022-01-13S-496860.xlsmxlsm dc8adc8e13d3e5a64f2d69f2163da90a19cd80594bf4db6b8d17c381312d28b6n/a Heodo
2022-01-13spaaw_9621.xlsmxlsm 3e8ac5b89fdb8697813438a75aec6df15ad029e5c499a023f5bc7a209ff1b13bVirustotal results 31.15%Heodo
2022-01-13815832176.xlsmxlsm 603fc4bf5e141be1b30fb64551545d7f757d7f508891d17256ffc5564f3ccfc8n/a Heodo
2022-01-13067174_7956.xlsmxlsm e07efb44e73f01e1cd957c1874bce0e453c91eaa561f46efb373edb97100320aVirustotal results 29.51% Heodo
2022-01-13cifumze-8291.xlsmxlsm e8da2349f8ec549d999a3e63b1f859f0452b0301aaf4fced70ecbba675b81247n/a 
2022-01-13DRB_133820.xlsmxlsm 7d20451deedc42248ceeb3cc205328d45bdc50d6d9a652f08773d052e1c598cen/a Heodo
2022-01-136483926.xlsmxlsm c9d6e67d61769e32b703185a1035e43bbc9c7c053cc1d06594fad3979da3cc9en/a Heodo
2022-01-13bC_93.xlsmxlsm 1070ee81825904e9b69247d5ecd09aa91e0be9722ff1b627740e98e0bd48ee7fn/a Heodo
2022-01-1372312_552.xlsmxlsm 2d009791d777c752c4fddb6e32e5d123d7ecf80145baef849436bf4879259b8en/a Heodo
2022-01-1384507-6084.xlsmxlsm ef6d3769be0a033960b0fdc9fe418e301fcddde93d9555c853849c3d8b9b173fVirustotal results 26.98%Heodo
2022-01-13311011303_7.xlsmxlsm 4624a6c75a73e206d26cf23225ddf8c14c9bd3fac85edc04aebf63a281aa8bd4n/a Heodo
2022-01-13LJAS4.xlsmxlsm 399fd8ce9218a6b24bbf3c9e307934df9b2954d45119371365be1360c88ec6f5n/a Heodo
2022-01-13432664-785.xlsmxlsm e867e8691b17fd95fce36eb933b1c36744f45513e44d931d07bf95229e47bef1n/a Heodo
2022-01-13336836-6393.xlsmxlsm b3a8073712469f70329fad465825f867bd6dcf83420de3004730f91ecc938138n/a Heodo
2022-01-1322487687817.xlsmxlsm 125468fda9c224d8a3ccdf92f08037a343c0341a8e64dc2c1182e1d3d4e496a7n/a Heodo
2022-01-13315-52.xlsmxlsm a64b918b227ae002b52f8ca07c1e57fbf11e0f6a0c5a06abbf79e2b209bce48bVirustotal results 22.22% Heodo
2022-01-135311_57343795.xlsmxlsm 13f975538e7e72ac755218c6a35604d36e0278e74fed8e2270476b89268a7f2cVirustotal results 23.33% Heodo
2022-01-1305146012_818869.xlsmxlsm 726be01c1600c33b9a3d322885ca12383ec5b64546bb389670176f77f7faf162Virustotal results 19.05% Heodo
2022-01-132477-7056.xlsmxlsm 6a8fc7cb880a404032161e81d67152873581b6614b238faebd731fb7fbd8cb92n/a Heodo