URLhaus Database

You are currently viewing the URLhaus database entry for https://mayradeleon.net/wp-content/0g-sg19-846324/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300838
URL: https://mayradeleon.net/wp-content/0g-sg19-846324/
URL Status:Offline
Host: mayradeleon.net
Date added:2020-01-29 05:39:04 UTC
Last online:2020-01-31 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-29 05:40:06 UTC to abuse{at}a2hosting[dot]com)
Takedown time:2 days, 4 hours, 44 minutes Poor (down since 2020-01-31 10:24:22 UTC)
Tags:doc emotet link epoch3 GandCrab link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31Inv-HU902_68356002.docdoc 6bf02ed6ce271b7b41f52e119fb8d366669e9b26f307aecb1620315034e4443eVirustotal results 34.92% Heodo
2020-01-31Inv-KIZ537_262551747.docdoc 813226187f75c12909c10d00dfafe96c916ad768979a68def760048753fdea9eVirustotal results 34.38% 
2020-01-31INVOICE-UTE6114_5833746.docdoc ed5859306a9e6bd5508a498220dedddb4871dd6bbf6e8438a27a6f393822fd52Virustotal results 36.67% Heodo
2020-01-31Invoice-6247_94709563.docdoc 5cc9b80f9de781a2bc9717ed8ae9323422aeedca1df3e663869ed6a168f1986dVirustotal results 33.87% Heodo
2020-01-31INVOICE YC12_49940776.docdoc 1c2d2dcc9e0140fd9e9055a697ec4c2c969590ba93a2f5ebf75bde37cc7ba0f1Virustotal results 33.87% 
2020-01-31INVOICE PXM93_606206789.docdoc ae370246a5b55b8f9dc4d3d0d7041d03f466f3d4260bf0beb48ff4dfa85a5b11Virustotal results 34.92% Heodo
2020-01-30invoice_EOQR6734_862470.docdoc b93c176b25e95c8538cc6e80bf1dca7b57ab9a7fe306415caed9989f1c306dd3Virustotal results 33.87% Ransomware.GandCrab
2020-01-30Inv NVQC5_978974804.docdoc 9755ef1672fe2fea84ded8999cf71bd62d9a3873bd4fa6ddafab57f59f0527f4Virustotal results 33.33% Heodo
2020-01-30Invoice_FV784_544411.docdoc 55e09691a61d983f8bb5cb7d81ca1c07171d3248c62cfcd4f3b1a89f5e9a66f1Virustotal results 33.33% Heodo
2020-01-30invoice_53_80440673.docdoc ad23200b4b35cf861876a41444203cb74f57e2be7bfddbc92b3fc7a07ecfe056Virustotal results 34.38% Heodo
2020-01-30invoice_940_696130750.docdoc e2511be44651aece200405b1e826c57ea3f3e0fdfd2335e457b7c6a70628f1b0Virustotal results 38.10% Heodo
2020-01-30INVOICE-FE9021_763260720.docdoc 4b8c920544a36d2b2fe8e35aafddad4a1052e8cced8e159cf4b9753d1c1a82eeVirustotal results 38.71% Heodo
2020-01-30Invoice_ZJ68_34138474.docdoc 70029b2efe245977665727cabe746a92f951297bf034a85f96c12a828c18a682Virustotal results 38.10% Heodo
2020-01-30invoice_VR91_705535.docdoc 444380961c88bf398e9078529bf648cf7f4cc69a583fea9d036c4427e533d8c5Virustotal results 34.92% Heodo
2020-01-30Inv_3_619370816.docdoc 4a3077b819873dbaed2f26fd4cddd843ea14f4c339f797b60eae4543fe33971fVirustotal results 31.75% Heodo
2020-01-30INVOICE_U6681_893025.docdoc d204a8808c41d9dbf3ad604139c838f916986ce563143b7e41b33c85d22d5973Virustotal results 31.25% 
2020-01-29Invoice-GDR3906_788800322.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 22.58% Heodo
2020-01-29invoice 9984_994594609.docdoc e14bd51bea91be160aefdfd75c853ce85ef348e87400f0d1e14b64c7d46eb748Virustotal results 33.87% Heodo
2020-01-29Invoice-L2456_858188261.docdoc 8f114fa9732298d525aa216d90905f24142f129d79e62500f139a3c09db00fd2Virustotal results 29.03% Heodo
2020-01-29invoice FH234_473647227.docdoc 4491676350c083084299affa5206946e8a9d6b63632f236d119e24cbd1239a38Virustotal results 27.42% Heodo
2020-01-29invoice-V1_114495.docdoc d965b7c533614e4ad1f1a9090edd5e83a4f4aae50a67b1ab1158ceaa31cfe7c0Virustotal results 29.03% Heodo
2020-01-29invoice_DC1_825125942.docdoc 7522a47f398818f54f95582e8d122a7bbd81f69c9807cc61fa12d0fc15a2e39bVirustotal results 27.42% Heodo
2020-01-29Inv_NQVD9_0667156.docdoc 3be00db967f63065494037f5de7659deb23f83c948d103057222421fc50cc775Virustotal results 28.57% Heodo
2020-01-29Invoice-FUJ41_165410366.docdoc ae350e475f5f34203313d523d6a5b8eec86357ef06ca6c9cc222d2c353506387Virustotal results 26.23% 
2020-01-29Inv OF68_345750.docdoc 19f29957bde797c4505244aec4c78ca3ff7e264967215abd6444d9f7c31da7edVirustotal results 25.40% Heodo
2020-01-29Invoice_KZ5252_1417214.docdoc b14d70827d5d668aeb31e94be512fea9fb38ead8ec12cdf7617616801c76b6e9Virustotal results 32.26% Heodo
2020-01-29invoice CMBH216_081820452.docdoc b9b47debd4d9fb932401d580847e8c3f82b770c5163dbc7d405aefb5cc704a1bVirustotal results 31.75% 
2020-01-29Invoice_O6196_4698779.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29INVOICE-I9253_56578469.docdoc f51d2aa766b1b07701a52e866f50132c0fcfaad288c1aaf13c781a66db3168daVirustotal results 47.62% Heodo
2020-01-29invoice SVVM269_22032341.docdoc 11b4519b76957b0758381f8e19c5e15d8744f7974716642aeb586c615dde38faVirustotal results 48.39% Heodo
2020-01-29Inv-FS1_151763.docdoc 2437ef90b60cf3d6bd0c3eebf3f41ed1e403bc31b024b52b0f41ec648d80a583Virustotal results 46.77% Heodo