URLhaus Database

You are currently viewing the URLhaus database entry for https://ofb.milbaymedya.com/wp-admin/attachments/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:288487
URL: https://ofb.milbaymedya.com/wp-admin/attachments/
URL Status:Offline
Host: ofb.milbaymedya.com
Date added:2020-01-14 20:21:03 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL :Not listed
SURBL :Not listed
Quad9 :Status unknown
AdGuard :Status unknown
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-14 20:22:03 UTC to info{at}nosspeed[dot]com)
Takedown time:1 day, 3 hours, 34 minutes Poor (down since 2020-01-15 23:56:04 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2020-01-15792010400904.docdoc c1c7fc8ee76da4f1696fa2d918472cacd777e5fe281acbaec5d12a85d98fcab5Virustotal results 33.87%Heodo
2020-01-15PAY_PBZ8KEFGBDU4S2.docdoc 61f43d8d0d62618d329f18de21403cf9df1977bfb0eacfe1e3466df8f00a15c2Virustotal results 33.87%Heodo
2020-01-15INV_32150194.docdoc 746e56dfeb31eb76ca54c4260082c53e799a6cb532561b12c98ee1496f3055f4Virustotal results 32.79%Heodo
2020-01-15L_PO_01152020EX.docdoc d497afabc9f95e52de2b44e62a03de53764ad772a44b5435500de43e92434a9fVirustotal results 32.20%Heodo
2020-01-15BAL_PO_01152020EX.docdoc 287ae14e3b1562662edbf0da35eff337a49d911c07fb02c48b681dc3cb8aa7bbVirustotal results 33.33%
2020-01-15U_LS9075195402TW.docdoc 1ed83f7ed0265fbb7fa1006f405773d31c4b7069ebfbbb6086f0196160f3d143n/aHeodo
2020-01-15U_8381941580774062.docdoc cd776c68266bdc9dc86cee87e3c792b2100546c13632f5404c8ab9016484c8feVirustotal results 25.00%Heodo
2020-01-15H_TNY6S7YCY6SC.docdoc 4f0095c259ca3e1e3f0cbbf9295f33bbeefdf8271b1f3d8b97ee9ba5626eb8e6Virustotal results 21.67%
2020-01-15FILE_96866073126.docdoc 2d5822aff83315cc778085dcd69fd73f82a4cfe94592529b93dacb256fb97713Virustotal results 21.67%
2020-01-15SW_PO_01152020EX.docdoc 0e0a399c81d33e87b7aab322fbf562d8c4aae27cc067a553ee092f13bc71221dVirustotal results 24.19%Heodo
2020-01-15BAL_S3O4RH91F.docdoc ae23c3284230d31527a8b2f8a4721cfa9d31535c93604fcd9be10894eeffc01bVirustotal results 18.33%Heodo
2020-01-15FILE_8039815435901.docdoc b58af543a114f02eefa12324cd48a81e69239da04a6fd4bb9cec8b32fedc9cd2n/a
2020-01-15PAY_FQT_010120_OZU_011520.docdoc 5ce93c3671dfbeae75d738d2ffd0204b72b6628c8aea98ccda37891eb1414614Virustotal results 18.03%Heodo
2020-01-15ST_22043566.docdoc a7d4e714a1656fa280fa345e1956d3b62141ac7b29d8fc4563c85a5616f886aaVirustotal results 37.70%Heodo
2020-01-15ST_TLM_010120_FMS_011520.docdoc 632e28a523c920e3035782ad086e6d3f0e39445486e86e7ce6a05c0e4f337292Virustotal results 31.03%Heodo
2020-01-15ST_IJ1132158741JJ.docdoc 53316d2f235578afb76c4e839aa953af8e9dfb9e6b17307c324a88e42d7e47f2Virustotal results 32.26%Heodo
2020-01-15H_YGW_010120_YOH_011520.docdoc 958b22bd337775f2226fecdcadf9125b8bbcad2518c23d026fd87b0714af1b63Virustotal results 31.67%
2020-01-15RP_NBN_010120_QNY_011520.docdoc 64a7bbb5697dab97fb723824a2f3456c67f88435cb51e3be9f99b0b9c6652186n/aHeodo
2020-01-14J_ZSX_010120_EVP_011520.docdoc bbf79cb4aa35f097ee65fbf27c2808626e53c4460eeec58c2a828aa669b50b74Virustotal results 26.23%Heodo
2020-01-14VY3BWN8Y.docdoc 6ea68ce4d24f0f499b02dc10acfa5ba8a428ce1eef46e6423899ce4be5f31b4cVirustotal results 20.34%Heodo
2020-01-14SW_41200508.docdoc 7f831b1e70be159d8194b2022de5a66d9784ac6959ddba38be95dbf6b30ea93fVirustotal results 19.67%Heodo