URLhaus Database

You are currently viewing the URLhaus database entry for http://wedohair.myap.co.za/wp-admin/ltcc4h-w7tiepi9wzk-module/404DgRY3-xE6N1JhlV-portal/66qbkgz9m4z-wsy717/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307914
URL: http://wedohair.myap.co.za/wp-admin/ltcc4h-w7tiepi9wzk-module/404DgRY3-xE6N1JhlV-portal/66qbkgz9m4z-wsy717/
URL Status:Offline
Host: wedohair.myap.co.za
Date added:2020-02-04 11:21:32 UTC
Last online:2020-02-28 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-04 11:22:32 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:24 days, 1 hours, 57 minutes Bad (down since 2020-02-28 13:19:52 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06mes 20200206 HPA4118.docmdoc c35a787d2ba6cd47cf26a8c0740f69adb1d1ff772426696ecc61f18ec86d1cd7Virustotal results 22.58% Heodo
2020-02-06mes-FL94655.docmdoc 6359275fa65b551a691c324e03fa5c3c73ace835ca4f3d90087dc3332f76ececVirustotal results 22.58% 
2020-02-06dat-2020_02_06.docdoc 7fe4afe59b087bf542c67a12ac54ccb89eab281656477ed8bfc41ebab0e0135fVirustotal results 20.97% Heodo
2020-02-06Dat-20200206-NRF00863.rtfdoc 7713e180e8a62f6041738a796b29f6efeab8431f8b6425016a4242f64df7061aVirustotal results 20.00% Heodo
2020-02-06LIST_2445.docdoc fa37e0cba4786db4ba847c2e4f9b4ee78aedbf0eea4491228705fc00980af4e8Virustotal results 32.79% 
2020-02-06ARC CS890.docmdoc 346d01cf657414934f8c87af6f0ae07d23875f613db84e483f2174b6353ab405Virustotal results 33.33% 
2020-02-06doc 20200206.docdoc 84e6bb18fc4d5994987feb9edc02eaaec7cc0988b27845fb8735d3c45591e5cdVirustotal results 31.67% 
2020-02-06List-2020_02_06-OCL110.rtfdoc 9e7490ea59c003826b03252f70bd3fc3a4c910d44aa5c1cf377a0cb24491118eVirustotal results 33.33% 
2020-02-06Mes JM375.rtfdoc 24bc1b322505611fc96f657f00be75ad4a096d02fc3e78d4b45369b13358575fVirustotal results 33.33% 
2020-02-06mes-NC136.docmdoc 5e5e8f41a5cd096c728febe9b8d84886133529c55cd22d17bffa8fa350edd2e8Virustotal results 31.67% 
2020-02-05File-20200206-370.docmdoc 335e92129e141d12928fdc17fbb6c1dfe8b6fa59b2ff2a4ad0c60f4f0637ee83Virustotal results 27.42% Heodo
2020-02-05rep 2020_02_06 D531755.docmdoc 061b77c1354bff1d5cafa4e10d903ee5feb16bb91c295298444e056ffefd1370Virustotal results 26.23% Heodo
2020-02-05Mes-82786.rtfdoc c1d36e9aab2030f23a10178cc432f92255b74c7e2382840bbae1ad7c099e97a9Virustotal results 26.67% Heodo
2020-02-05List 2020_02_05.rtfdoc 23f4a774007e2fc64a2824e5973bb695a64667d8d832fbc29806976dad67d7f7Virustotal results 26.67% Heodo
2020-02-05FILE_UW93421.docmdoc 408642c623b422164d2d5e79d498b439c267c0756121e7d453587702c3b9f50eVirustotal results 26.67% Heodo
2020-02-05List-2020_02_05-271.docdoc b03e332d75fae1c213d41742abe758225f46a5ae68755f6d57dd3cb44326312fVirustotal results 26.23% 
2020-02-05list 2020_02_05 5565712.docmdoc da0b1e331a89bd28e4338a886d224c01e9194a764a6ded30bac8b16670a589b3Virustotal results 26.67% Heodo
2020-02-05REP_20200205_F7530.docdoc 4bda34084014e21ceb2db8fb9003f36f4b3a7bd5a8bcfb9b1badbf13529a6d84Virustotal results 26.67% Heodo
2020-02-05arc_2020_02_05_A216.rtfdoc e9de053b8046e662771b320b25a49cd709591ac896fb6bd4c324ba0b13f37b35Virustotal results 25.00% 
2020-02-05Rep-59078.docdoc 6228be42f808ff1c2d59dc6df839b24c07a9e9640fffea33d21e69f3b2765a69n/a Heodo
2020-02-05Rep-59078.docdoc 6228be42f808ff1c2d59dc6df839b24c07a9e9640fffea33d21e69f3b2765a69n/a Heodo
2020-02-05MES_RX523586.docmdoc e017e89646b0d091bc67504f4318ea078b5a279edd898f418ff735e40c432e28Virustotal results 25.00% Heodo
2020-02-05LIST 2020_02_05 FTC37077.rtfdoc dbbe0d7dded778f388849d7ce83487c413292de6f83d4d8286e7b13bd8f5b981Virustotal results 24.19% 
2020-02-05Arc-20200205-6605.rtfdoc 6552a6b01beec690c8ebf79b58d1397c3e9449e2d59c4f17b1d0e24415fdc05fVirustotal results 24.19% Heodo
2020-02-05List 20200205 APB697562.rtfdoc add57fd6782c427fbdbab1e52f313746c594f78a352135f6961c6e7d3d9ea2f6Virustotal results 24.59% Heodo
2020-02-05File-2020_02_05-868194.docmdoc e88dccaec3107938ce2733cf049c5ace8f7d614e24a96f1b60da298112f6b5een/a Heodo
2020-02-05Inf 20200205 6370.rtfdocx 3002799efe2f36491f41e0c5e350a6c6ae06bdc8fbef3c1ddf753c6c2e206736n/a 
2020-02-05FILE F210136.docmdocx 3c0292963e5af1dfc8aa14b1b0408c3d3e0873fde4dd75962bd380b5aa67eb36Virustotal results 34.92% 
2020-02-05ARC-2020_02_05-PAM19396.docdoc e96b3b96851ad8f49fa155f44b5dad11bedded8a6c96898fa814e872822f3eecVirustotal results 35.48% Heodo
2020-02-05inf 2020_02_05 M336.docdoc a464fbbd0fd6eb2e09bb5c04dd46379d3cf1c4f67eeb3f4e9f0b9f7896a2192fn/a Heodo
2020-02-05DAT-2020_02_05.rtfdocx ab25cd8065a0df8608fcd69bd29689ae7657b263b8290a459052ff0cfcac3951Virustotal results 30.65% Heodo
2020-02-05MES.docdoc c88c5193f9ffea07709eeb7dbe053ec079f2a2d4f142fd26ca76ed7f55c6e6abVirustotal results 30.16% Heodo
2020-02-04Inf-XH12237.docdoc f2d5330b5aa423a1c21c6f960154447080fb0b6a7747307519ce8d57a310d1a0Virustotal results 29.69% Heodo
2020-02-04File 20200205 D994114.docdoc f189891eacbacefcd510376ad44060a48962b25cfabcdd82b7845acdb512bab8n/a 
2020-02-04inf-ES744.docmdocx ec4146a69e81f690514da6199f759c184964dbe031f6ca7850b4af5d0d365150Virustotal results 36.51% 
2020-02-04inf_2020_02_04_9546.rtfdocx cf00a0e13bdc326ecf08bd0238ee35c3600642133c7f84f69b0434aa63bfa291Virustotal results 32.81% Heodo
2020-02-04ARC-2324075.docdoc 226e3d9397801a0c20fc12e65373887d6b8e32d5d47ea818a8b891be4513e330Virustotal results 33.87% Heodo
2020-02-04Rep 2020_02_04 6956413.docmdocx b47eba67f3bdcaadc7e9116053d4a250ae71ce6031b8ae4c30bc22459a57ba0dVirustotal results 31.75% Heodo
2020-02-04dat-20200204-7386081.docmdocx 265e4a2697fbfecc43edb76419d9e4a8928492d01b548cd7d6804226d6b2a593Virustotal results 37.10% 
2020-02-04File 20200204 4041.docmdocx 12edeef0065331ab3b8644b9c14a1267b266a96e33ad20e9055315c454b750a4Virustotal results 37.10% Heodo
2020-02-04LIST 2020_02_04 FM35404.docmdocx a22639097a957b8debdfb4ff182eb2b6a288368b09b8427853ed91346b687737Virustotal results 35.48% 
2020-02-04List.rtfdocx 71504ffb2ac7323b2da494aabf013190544db3e4230b363b639d68878aaf77dcVirustotal results 36.51% Heodo
2020-02-04Dat-20200204-360.rtfdocx b71394268acf3acca757143450d5ccc9030bb60cd3e5e9e3245f81fa1b63e757n/a 
2020-02-04Dat-B1001.docdoc 3455fc14bf4bc55e2cd1a0d3e6ba9f195bd43d0a44099f3f23cb2c9b95310140n/a Heodo
2020-02-04File.docmdocx 8850bfdd37da2c746074f307dfcda1b492a3d639d6a48a9d56dc084fec7c536dn/a