URLhaus Database

You are currently viewing the URLhaus database entry for http://jamesapeh.com.ng/wp/eyxyf3-9d4um6a-lfzpg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:200155
URL: http://jamesapeh.com.ng/wp/eyxyf3-9d4um6a-lfzpg/
URL Status:Offline
Host: jamesapeh.com.ng
Date added:2019-05-22 17:37:34 UTC
Last online:2019-05-25 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-05-22 17:38:03 UTC to abuse{at}24shells[dot]net)
Takedown time:2 days, 11 hours, 28 minutes Poor (down since 2019-05-25 05:06:54 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-24Rechnungs_Details_26981124290DE_Mai_24_2019.docdoc 4cccd050234aa4a04cf4400b4b0fdcb22ede36bc42dbf830c0a03853dce5fd48Virustotal results 28.81% Heodo
2019-05-24163721257712DE_Mai_24_2019.docdoc 9809cfabfb3890ef06ceb2b1af87238645b6f0006c1b8812e89ecb299e423f84Virustotal results 28.33% 
2019-05-24Scan_1309165738DE_Mai_24_2019.docdoc 1eead5084aee8b05f6170014ab370b78a4ed5bc891e6c9409c69a151dc82249bVirustotal results 28.81% Heodo
2019-05-24025697262414DE_Mai_24_2019.docdoc 41aea7ecbe2ffb931889169b5df96e12db742d0100f7bc6b303e047788b987b7Virustotal results 30.00% Heodo
2019-05-24Dokument_8854790945DE_Mai_24_2019.docdoc 7ffed07a52fcf7c172394b8dde5219ddfd505cf3aff363c9e0c5b9a4f6c9763fn/a Heodo
2019-05-2468695682512DE_Mai_24_2019.docdoc 4cc5e10c94d138330aa3096a394f3e40b9a204b6fa87682e84cb9975f62febb6n/a Heodo
2019-05-24Rech_7242500680DE_Mai_24_2019.docdoc d4211a69cc7c1942c7e7ab2152089f9c3517b1ba70bbf284beee7d190aff342cVirustotal results 26.67% Heodo
2019-05-2436502363223DE_Mai_24_2019.docdoc 98489fc90d217fce40c906524b68d9861626676214aa7b2326ed006cf457dd48n/a Heodo
2019-05-2484565723298DE_Mai_24_2019.docdoc 7e4542261715f61983de47f8c4a3f498250bc09c63aa837919f1d3577f479121n/a Heodo
2019-05-24Rech_8574704031DE_Mai_24_2019.docdoc b72cb826bd01e9dc5fb27b3c9fe077bf233f1b9e545b5857c7e120d8c1699146Virustotal results 24.56% Heodo
2019-05-24Dokument_220720471815DE_Mai_24_2019.docdoc 45ee87070c8898d0d2fb3d96c510ec733d06e7912f608722fb241b9d7e61d10bVirustotal results 28.33% Heodo
2019-05-2321935308826DE_Mai_24_2019.docdoc a0949ee3caa2c2972e977489141b19b96e6e4a4dd21c4698426eb228313faa93Virustotal results 32.79% 
2019-05-23Dokument_4737215694DE_Mai_24_2019.docdoc 5fe2b89bfcde3ff1c271102a1325ad4ee8d12901e3b2282376e024824a955e29Virustotal results 30.51% Heodo
2019-05-23Dokument_4260113877DE_Mai_24_2019.docdoc f78a998be6bc145d93e1511b55cc716e73e601d63eb9d07d3574b139ad63d6d2Virustotal results 20.00% Heodo
2019-05-239880858013DE_Mai_24_2019.docdoc c68e0427f3052c3256d56e0126a73e34e67c1c8c50b9e37487453084b79bf176Virustotal results 18.03% Heodo
2019-05-23Dokument_684849038507DE_Mai_24_2019.docdoc 04a6585af9f7a9ae90fb0fc3509ae9baaba60aed6a83295c28bd8d97291ed2e8Virustotal results 22.03% Heodo
2019-05-23Rechnung_18165163956DE_Mai_24_2019.docdoc a2cb13a6e2fb1f290d52f4e0dbb57286832cfce1f8f7d77225d1d23c9b1b45fbVirustotal results 20.34% Heodo
2019-05-23Scan_704756172827DE_Mai_23_2019.docdoc 402821d48b97ccc79c95a8ae5a3afb09cad7168e842ed5a9513185b575ff3623Virustotal results 19.30% Heodo
2019-05-233231427673DE_Mai_23_2019.docdoc a2f7be05173d2188d3e3ef994e8e41812050737cf5648697ab507b042adb99a0Virustotal results 18.03% Heodo
2019-05-23Scan_9632885071DE_Mai_23_2019.docdoc c46cad65924baf23f43df0f12971a7112cd63e4f7d0128ca8b47b4c1f1ec440bVirustotal results 18.03% 
2019-05-23Rechnungs_Details_0972284261DE_Mai_23_2019.docdoc b44ecb38a5eed68f75ccf9b8f5901599f5ad5ac74125fdb66459a3e6727702d8Virustotal results 18.03% Heodo
2019-05-23Dokument_5120091960DE_Mai_23_2019.docdoc 0876cbeb0f6c9ca9dd9f7092528f1eda0695888eec6991f853b4cd44da4e2428Virustotal results 18.64% Heodo
2019-05-23Dokument_257288031245DE_Mai_23_2019.docdoc d02dcc9468c80bf888294ece3755ca8b9d727e5645ce96a8efca314c80925ccfVirustotal results 18.33% Heodo
2019-05-2304833351646DE_Mai_23_2019.docdoc 4e82b20ca98af17b4361fe688bce991cd907e25c139b9da39340fd758a6bd22bVirustotal results 15.00% Heodo
2019-05-23Scan_61479136410DE_Mai_23_2019.docdoc fb293ec8ed25d255bc74389d655cce1ac0b34cedeeda6b9f75c0a8ddff81a78dVirustotal results 13.56% Heodo
2019-05-23Scan_666908153167DE_Mai_23_2019.docunknown 5a217e950f27df7da794e729b22980c2aa1417696ffa1ee861ce9e657fd35bbbn/a Heodo
2019-05-23Rechnung_197106683264DE_Mai_23_2019.docdoc ea6d7990cfe848b99d391ea3690e80fa14710973f3b7a3a151602e736062d3d7Virustotal results 15.00% Heodo
2019-05-23Rechnung_738932284616DE_Mai_23_2019.docdoc e3b73fc71fce5c6eb0769674687f1fc666118b06404f2f9578a2818e0cfa38e2Virustotal results 13.56%Heodo
2019-05-23Rechnung_9420190933DE_Mai_23_2019.docdoc fdb1e7e7fabc9985f4fdf49aa9ce9264034bcef8da36f2e804401af4e561d19fn/a Heodo
2019-05-22Rechnung_6513882703DE_Mai_22_2019.docdoc 2848325093685db4a9222a0ff907cdc127ac2483e7abc00192c8d3bdef83ac38Virustotal results 20.69% Heodo