URLhaus Database

You are currently viewing the URLhaus database entry for http://mandlevhesteelfixers.co.za/cgi-bin/docs/wdp5f0hf9m/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:293404
URL: http://mandlevhesteelfixers.co.za/cgi-bin/docs/wdp5f0hf9m/
URL Status:Offline
Host: mandlevhesteelfixers.co.za
Date added:2020-01-21 08:52:05 UTC
Last online:2020-03-27 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-21 08:54:02 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:2 months, 5 days, 23 hours, 25 minutes Bad (down since 2020-03-27 08:19:32 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-23BBX_00507255.docdoc 639ebecc28d4bf2303763cc01f9652bac3afafbe7044f58e3613a30787047422Virustotal results 21.88%Heodo
2020-01-23FGLK_64978119.docdoc 369488460f5d15f277924ca8f7c9da9046f082c111d528e799ea1d2e9407c794Virustotal results 21.88% Heodo
2020-01-22SW_721383783494270205167.docdoc 5b2393131c65f5e870b831a4119ad0214a8c2be24562d24aba92b80b69e61439Virustotal results 29.03% Heodo
2020-01-22INV_GLO_010120_WDO_012220.docdoc 186ed86938f3cf8a4a1803391f5333e4f35f62cfee871a5a21baa250b5146f7dVirustotal results 26.56% Heodo
2020-01-2270343710.docdoc bd2bd7e32f116b6afb94c471be1359cf19b441ce430f91dd3deb202b3c0838dbVirustotal results 29.51% Heodo
2020-01-21ST_SBX8TPHWB5CKE.docdoc f50a744154021107fa93bc0cdfe9fa4f39f03fa06ab1e063f2c28104e189f158Virustotal results 20.97% Heodo
2020-01-21FILE_IRI71H23CD.docdoc a79b6d679ba1b7883c876d0a0ba74362973d6ea780961faeb2c4f1e7caf736aaVirustotal results 19.35% Heodo
2020-01-21SI_113135024713601.docdoc 5fd6ec312654d263689e335748f1296c2e1cc8b5d84f2f28e4f0af1686d55715Virustotal results 19.35% Heodo
2020-01-21SW_HUJRR5TNRU.docdoc 616b942341fb4aa9e7ef9a9812fc490798f6d57020915c7fdeeb4d6abd868b77Virustotal results 19.67% 
2020-01-21REP_KE2955924926FV.docdoc 3971d2f8dad1df7ae025551c02c685cf456405eb7ba164f380e38518f2d228eaVirustotal results 19.67% Heodo
2020-01-21UOH_NAP855J8XVPSCM2S.docdoc b27efe734620499ff72dafb2bd9cf0650ea42d6b08f670e80149d1a7087d4f51Virustotal results 19.67% Heodo
2020-01-21OET_8KUJUY8K.docdoc 0ba2bc2d8ddd7c95e3a17870d34c390e31968ea645b5ca3c5978da28719eeb99Virustotal results 19.35% Heodo
2020-01-21V_25978419.docdoc 0ac7a98f0bbf451a51cb75aa5b065d00e46c0860c7cd1c90a194e8a40a56aa93Virustotal results 19.67% Heodo
2020-01-21CZJ0FZFTYME.docdoc ce7997a982cda9e7c2591ab8566bbdc583595e079b68bb121820bd81bc0f5c7cVirustotal results 20.97% Heodo
2020-01-21X_45121141.docdoc 3fd7f5dcc627af3f5f832b508d626dfa8691089e643a00c47c88bc2fe760fb23Virustotal results 23.81% Heodo
2020-01-21XC2611953876DT.docdoc dfe2815ab27e806aa38d3a86f0c43e7aa9fca4b580604411f1d339c734d038e3Virustotal results 24.59% Heodo
2020-01-21BAL_IXI_010120_HLQ_012120.docdoc e4932995a94e0c841f96d023503d1a1bb8e8278fe5478a736b9a4cbc83283ab7n/a Heodo
2020-01-21A_PO_01212020EX.docdoc 3d7638d3dfb9736e90003021fd9a8a5dde3aef6a2d13539f6734043630d1d035Virustotal results 22.03% Heodo
2020-01-21B_IGV_010120_SIC_012120.docdoc 0365d1f1769485733cc40ee24570539fe28f85e5d646a9354f51b47ee5a3507cn/a Heodo