URLhaus Database

You are currently viewing the URLhaus database entry for http://meca-global.com/wp-admin/LJF_053824/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1977709
URL: http://meca-global.com/wp-admin/LJF_053824/?i=1
URL Status:Offline
Host: meca-global.com
Date added:2022-01-15 00:47:06 UTC
Last online:2022-01-18 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-15 00:48:13 UTC to abuse{at}godaddy[dot]com)
Takedown time:3 days, 5 hours, 28 minutes Bad (down since 2022-01-18 06:16:44 UTC)
Tags:ArkeiStealer link doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-154626775JTYN_057.xlsmxlsm d8c07f93d53cd970c597ff94a8dc92c5b0e489a7e0489883fc86a4bd6d261f27Virustotal results 33.33% Heodo
2022-01-15x_354828.xlsmxlsm 6948e534c2e2cf5d79c9c210e98e900c3c00e4eb86b46c34ff57c29b950717d6n/a Heodo
2022-01-15787091_596659.xlsmxlsm 40c5e372942e0b9b1ddd00e203c67676f96fb761373fbe9bf108613a593ee57bn/a Heodo
2022-01-15RBI744150.xlsmxlsm 2fcf005e25f8417cd55b6e4eadadd73f73f66a4d167f98d82daccb6756ac1609n/a Heodo
2022-01-15loxozq-690.xlsmxlsm 8463333f274f70052520e2419d87787a7d26dba8fd42ce3636bc31648459c391n/a Heodo
2022-01-15802890202821724.xlsmxlsm 295b5684fd4d6da1bb6287b0bade91c880432d8d299e7788a254c9c9738dfcffn/a Heodo
2022-01-15NVS-88782.xlsmxlsm 5e522b60a9aa3694fe9ff31c028d85daee8a4df5011ebcf7a44ea1661dfcf547n/a Heodo
2022-01-15QBZP-418580.xlsmxlsm f598b21f793991155297f197efb6282ea424e9c846ed97cb61f9e2e2321ef57fn/a Heodo
2022-01-154859623_7740.xlsmxlsm 2e5d9260f3ded87b56eb1a493b09ec187c0deea70d4c32e9e7ba0741b9b37d22n/a Heodo
2022-01-15bOKm_11.xlsmxlsm 7bd561959295ba5aad56e198caa95e3b1165906ae704be0dea8874044e92aad4n/a Heodo
2022-01-15E44687237.xlsmxlsm 97a7bf62bcd75bff44e2ec53cecbfb4be386b7ef16c983ca0c5ac1733810f284n/a Heodo
2022-01-153852MRRY58475515.xlsmxlsm 0045b20232732fb2c4598671f7d31824da64275a796b6da748355d3aed6af989n/a Heodo
2022-01-15de_094062.xlsmxlsm 87a3b24117e7f39be9bcfdce77aeb0bdc0bdd0c7a6b6a508d4252d8d547f68c3n/a Heodo
2022-01-15QNXNK22.xlsmxlsm 92b75d16d13348770c16fac4253587736d813b5be5efc510d13adbe505c3019dn/a Heodo
2022-01-15T-5.xlsmxlsm 4a50690244ff1302df056492fac462a3d8604d6657f79f736e2ac9527722b4c2n/a Heodo
2022-01-157014640.xlsmxlsm 6160bd3b3820942851b4c56066611bd4c01ac70d8a520be8e9abff7f3aff45b7n/a Heodo
2022-01-1569697954814.xlsmxlsm 100411c1d9d483e285fb39e5aa3a00df0433e418629428d90b9f9a7f9e393735n/a Heodo
2022-01-15600067-875.xlsmxlsm 62339184034e6ad69c9803d78caf51eb93963736899000a79763942bdb54b751n/a Heodo
2022-01-1507RITQ_08099737.xlsmxlsm 5be4fdc379541be75fda56d996fd5380b4f68fc14a295a5c39baf258f67636c1n/a Heodo
2022-01-15zhiwn_07.xlsmxlsm d60a0d354b47db9947cccf869113e1fc3db29e6dd52da4de97e3f597c8413126n/a Heodo
2022-01-15629-973007.xlsmxlsm f1279014845146db7dab4550b6d0eb55bea5448b467ce7198148a6f80036365an/a Heodo
2022-01-15A-153.xlsmxlsm c1a965ede59ecf82604f9e28dea05524ca8c4c5f826c417c629bfbd5cb21602cn/a ArkeiStealer
2022-01-1532191_3.xlsmxlsm 103ebce0fa6518db55234f954a8cc2f199225e8badf6cc45d82cba723101a60an/a Heodo
2022-01-1558405293_2438.xlsmxlsm d87ab959d62f1eb3345d4933f565c01a1d068976efccba5093401902ab6cd52fn/a Heodo
2022-01-152375539791780.xlsmxlsm af4524f85f636f8b929b04a779bee53c82da66d25d3be5a761b49d081af082f9n/a Heodo
2022-01-1586870.xlsmxlsm 9f593a4d8c3165dc5052f06fac8f6bc92bfe45012131fc75cf27ec63ce1f3adfn/a Heodo
2022-01-15COB2979990.xlsmxlsm afde85c0f3400cdd70d59c378196695e4b64b7b6b559a7d481e1679f0dd8ed09n/a Heodo
2022-01-156817_5143000.xlsmxlsm d7818be62c9a6e0eefdc0fd0a685debddaa7d58bdc9140d59be286e46b7bb766n/a Heodo
2022-01-1538146657418.xlsmxlsm 65e1cc84b8a1679ab3c2e79303871473cc6de700c9557e8f61ea1cf619652e66n/a Heodo
2022-01-15251541732520.xlsmxlsm e37e5c57c8ee2c0a6920611443300efbaf70d3070a387ad075818f869ca3de35n/a Heodo
2022-01-154558_07099083.xlsmxlsm 5f18c310f5253557bd4e3db65b76f929de0a63e9228508432f417be214cb1c6en/a Heodo
2022-01-15OIR75.xlsmxlsm 18407ac6698ef4bcd8d03f4a6e0934e0f737014d3da7b8b9f9573aff85531e86n/a Heodo
2022-01-15410033_08.xlsmxlsm 24e6bb90d4b84c8fb6769e7637035f9154e23fa9ba28b65c5162f1d5e3b9a0cen/a Heodo
2022-01-15PXX_27.xlsmxlsm fb7c16b68e16a83ed7216a2bfe42c42fd4ae7398dee6ac9b70be8d95aef4fac9n/a Heodo
2022-01-154454_75372.xlsmxlsm de6733eb50cc7fad43c6861b199e19e9b1c03eb84a214c35008270c9479492bcn/a Heodo
2022-01-155057-71931308.xlsmxlsm 604e011f3b1701d6c0f5c814de83490df5f06fba4e310a5bfa54e07e616f1702n/a Heodo
2022-01-15LBDQ5010.xlsmxlsm 3167677ab5e6b101543905b4fea63254721d35dc44ea8645aded33d27dcdf2a2n/a Heodo
2022-01-1511390589595.xlsmxlsm fd84a93128488e641cf2f10b5d20a612a8d37912289ea1c353422037d3c3ebf9n/a Heodo
2022-01-15kwiax_57776.xlsmxlsm 5e30391d5d85457e108e57ab22c74023533d0a7fe89478cc6a395e184770debfn/a Heodo
2022-01-15II_7931709.xlsmxlsm dcd8553316bd6d1c5c51abba8441a036123a20a17ea2e495df7edcd3873e106fn/a Heodo
2022-01-15v_373300.xlsmxlsm d88a7ac3b8616da5e351a91188251a68584ec2d51a5c491c18f661a322ce9319n/a Heodo
2022-01-15BPI108172.xlsmxlsm c8ae806c1fad8007f17331fc0ea71d000140443e4596a430f7cd80332ac3c2cbn/a Heodo
2022-01-1539768820709975.xlsmxlsm cbabf31062db7ba965fddcf8a0309fd8f045f20c5fd0baf6d086f52878f0ed03n/a Heodo
2022-01-157047452806838.xlsmxlsm d90488474a115987753f7d96f2810900bd6abfc52ac05aeed67710e18e0314adn/a Heodo
2022-01-15ziiqya_84009671.xlsmxlsm af74adf2376ab0a8fb16735d44fc3e72bc4480a91b2cf9de85cd2f9ab7fe1fb5n/a Heodo
2022-01-15zt-6.xlsmxlsm 55609e9411de2aa6dca0995747f89cc0b89081e6722e497433da8f8d02e9a2f2n/a Heodo
2022-01-1586665YLGGMZV-41287.xlsmxlsm ad1b7552699a3ccef19229a0eff41da0233a54e065123850af66488c3d64c266n/a Heodo
2022-01-15819HCVTKQZQJA-68.xlsmxlsm 7048b590b47e71cb6a20b35c192d264bc4bb1fb4213dbb9a9a2c9748d53af762n/a Heodo
2022-01-15ceNhB_68.xlsmxlsm 1f93c92652672883150a833d6bdfdf434bde9d61121c95b4a0b77740afa8479cn/a Heodo
2022-01-15KZKRB01.xlsmxlsm d103b5352273217cc252966b5d072c39b0340845aab3513ec3d17e07e1a5d410n/a Heodo
2022-01-15XS_92885.xlsmxlsm 2966763dc88ba44de5f3aa8ff82addad4bb4b567bdfe60a067f169098258c418n/a Heodo
2022-01-15UG_56232.xlsmxlsm 20f452bb488539a7e3a4840a8ed88bff9a700b89e50439e71b40181a71ee604dn/a Heodo
2022-01-1567412-54425.xlsmxlsm 7a75b8d2c5567ef0c4fc7270b77c7deab2f2a81ea2f1b969f66d680a781b5065n/a Heodo
2022-01-15Nibz35875928.xlsmxlsm 0400c5d7c8ad85387bca95f3beb4be0b192f8a53aaf64f60e631ac66c60b5504n/a Heodo
2022-01-15231557148.xlsmxlsm 5225cb80d26dfdd86adfb738e4bd1db0465b96e113af141c8cbd9d0bf4dc1e45n/a Heodo
2022-01-15I_583.xlsmxlsm db676ef714ea818edca3ff4a25da38808cbec2a6d7b944a237e44ad29d8932daVirustotal results 36.51% Heodo
2022-01-15fr_249.xlsmxlsm 7502d81e1850ddeca8f2a9b2b5b986b1402710ac10ba7247fa34dbde1e9f1399n/a Heodo
2022-01-15427_284615.xlsmxlsm 771e8eb9454d09d3f655f55713b1791583aaa6f813d896737b38d1da511fcb15n/a Heodo
2022-01-159117623_1.xlsmxlsm d6d33e7076e3ff778ea32c349701dc2c599fc78d287883f2ad9c16a820386e37n/a Heodo
2022-01-15914807-50.xlsmxlsm 77ffacc52c59a0eb5b6b3714889a43cc959b49088f530582dc6481df50f843f1Virustotal results 38.33% Heodo
2022-01-151238-56.xlsmxlsm ac7bc114197f00db5cdc8220478ccee911aaa8a17481da2be5bd05e884c00b2an/a Heodo
2022-01-1584006408_709325.xlsmxlsm d23b6087f9c63fee7bf5d8e620cf88ca2c38fe8ee342deed923d705fa9b6d68cn/a Heodo
2022-01-159193_255274914.xlsmxlsm 35101e24e0d9b97edc46d35011a21e505ee4b05036998544ad3dad3444e09376n/a Heodo
2022-01-15R-17.xlsmxlsm a59149fcacf8a5c564f48dc446b7cef1203a0ab92fec9dead2b3645bb24d3e51n/a Heodo
2022-01-15529687_47.xlsmxlsm de54a7c99135db230ba151e513f7813ccca74b08201d7592958e82c51b152386n/a Heodo
2022-01-152777081417.xlsmxlsm b8121edc6cc2e93b9a7832beca7e11a32f3c0b8214816c8276a2d2eeec251050Virustotal results 36.51% Heodo
2022-01-152883202572789.xlsmxlsm bd6f9bc0e68e1508ca81f61f53878f1a5567ee9a16d80d3a7f0384862c6b076fn/a Heodo
2022-01-15LJF_053824.xlsmxlsm 9915ed54114eb4fcbd6b9a3b29c0f635a185ee8c8c13a8970bb16a62600cdbb2n/a Heodo