URLhaus Database

You are currently viewing the URLhaus database entry for http://valetking.myap.co.za/wp-admin/wYu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307943
URL: http://valetking.myap.co.za/wp-admin/wYu/
URL Status:Offline
Host: valetking.myap.co.za
Date added:2020-02-04 11:25:08 UTC
Last online:2020-02-28 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-04 11:26:07 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:24 days, 1 hours, 53 minutes Bad (down since 2020-02-28 13:19:52 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06invoice 70_3786605.docdoc 54a7a25b8d4e6b975f11053d4ab18016171b86457df03b01c945dc245a813ea3Virustotal results 22.95% Heodo
2020-02-06Inv_7526_5435313.docdoc c137f96ad20933f15cbd33dd13a59de4aa1b0e84ba2d9ffeca8835eb21d271e8n/a Heodo
2020-02-06INVOICE-CRXN442_4668757.docdoc 12368c93f93b5feac92d01c7f620337dcbaab18dc50b27dfe2a50ebae513d355n/a 
2020-02-06Inv-DAKI2613_051864.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06invoice_KML316_5119513.docdoc a5fc11e008c844121e447116ba31e7430ab4bc38350cfd1b6bd52fd322c059f0Virustotal results 32.79% 
2020-02-06Invoice-ZLII3_82868026.docdoc 90250acf44f763164182f91d1d9e734ea442e491965e1c3883ed40fea09f0d2fVirustotal results 32.79% Heodo
2020-02-06invoice-BK3404_2876520.docdoc f64c7b18189347af96b402b6f3cb3294d4dbbc7cad63748805727ac4d2a83997Virustotal results 32.79% Heodo
2020-02-06INVOICE-J001_060321323.docdoc 7eac21ec4810b17ae186a7cb7619660833006d22ffdd25ffa44769a9474a13b9Virustotal results 31.15% Heodo
2020-02-05invoice_TDDC990_267171813.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05invoice-OFKL6642_7097683.docdoc 4c81ae4043b5ebb941a22c4511a4757a6a0ca5a842660b5c1ea31c57955800c5Virustotal results 26.23% Heodo
2020-02-05invoice EMXI4_98357145.docdoc 6d5225b0982f192c99503ae1e58b74554f78452462dc9d2574aa266355967658Virustotal results 26.23% Heodo
2020-02-05INVOICE_JIW67_80481577.docdoc a2de78a3a39c2c5d3d3c617de7f83a6ee2ba59eeb411de1095a208d4b21ecffen/a Heodo
2020-02-05invoice_Z760_27924148.docdoc ef8c19d2f4c9eb90e54283dae9139015ff46f2bc701fcc49ad0b760ee816654fVirustotal results 26.23% Heodo
2020-02-05invoice-FXI8_2466975.docdoc 80ff1f7758139fb61d82afe12894afc778068701ba7fc6acc78f1e05b8e6d90bVirustotal results 26.23% Heodo
2020-02-05Inv_1_8832592.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05INVOICE-YVJ654_9622003.docdoc 553bb18cdd7ff56366cb6f9509373cc5c6e58e24d1056bafe7e9bde95f6817d7Virustotal results 26.67% Heodo
2020-02-05Inv 8822_779322329.docdoc 3d86715a18dc19cdf1364d58ff7deee2c387cde502de5b43166a7c0d98b2a24an/a Heodo
2020-02-05invoice IZI670_191536.docdoc dc0402b2e8b444ac6695dd0686b697822b5c339fb556f63aaf4cb4dce9354572Virustotal results 27.12% Heodo
2020-02-05INVOICE-W237_291901519.docdoc 6e4f1e55d03c7f87e1640ee1dba3bbbf7f3d01655098885ef1db6e84a5947292Virustotal results 27.12% Heodo
2020-02-05Invoice-Q2_7187364.docdoc 6e6b6b51d4a9dd7f74e82c53490f95ead4a4d2a9a4adb06f1cbd991bc2b225a7Virustotal results 33.33% Heodo
2020-02-05invoice P1487_05890243.docdoc d753eaf7b22aea01dd44dfba5b9fc26ebb5677f4a713b4afa69d8c34efe836f0Virustotal results 33.33% Heodo
2020-02-05invoice_43_501535.docdoc 471942cfd9aa93923bc0f054e64201217913ae24a3e192919207202918c628fcVirustotal results 32.26% Heodo
2020-02-05INVOICE-VMEY9186_35748831.docdoc 50ed2de7492f944d8a34c9d454c3757a58d26078f91dd5de90ac595eb6279dc7Virustotal results 42.86% Heodo
2020-02-05INVOICE_ANR38_63166311.docdoc 25d98e7b0341be2da85f8fbbe279863673a1b0744c9773c8f6bcaa0c0666c935Virustotal results 34.92% Heodo
2020-02-05Inv VOQ2907_89573688.docdoc fe95a5f68fe689f22c1ba6e479febd867fbb29760f0063700ad27d7d8b482d67Virustotal results 34.92% Heodo
2020-02-04Invoice_T208_363044339.docdoc c01faf044c1df797bde7ae50e931236add55e532401115f33435ad6802eeb184Virustotal results 33.87% Heodo
2020-02-04invoice-5004_072940.docdoc 0b2ca06ad6086c411fe61f2b5a791d8fa9336d920a8c39214db4c4b05e69a3acn/a Heodo
2020-02-04invoice-XWT457_33806912.docdoc 41aea47e36728ef17f91fb0ed0239001ef742699f4e187e54d4e107680725a5eVirustotal results 34.43% Heodo
2020-02-04INVOICE Y9_075253.docdoc 9cf373c9a2dc126d14647d1c4f9bd6a554335f4f00f76b6ad0ce24dff7d1c054Virustotal results 33.87% Heodo
2020-02-04INVOICE-K0_193731949.docdoc cf00a0e13bdc326ecf08bd0238ee35c3600642133c7f84f69b0434aa63bfa291Virustotal results 33.33% Heodo
2020-02-04Invoice-3_132318.docdoc b4c3990e73035881f982534ee5ccc3a30f80b58c625e28b6f68067c223589fc1Virustotal results 31.75% Heodo
2020-02-04Invoice-NT08_058313666.docdoc 40c57139f9fe475f5e06542c48aac3476cd943f3530f73ef44a60db380bf9e04Virustotal results 38.10% Heodo
2020-02-04invoice-VRD907_565162.docdoc cf761039f6144534194bd9b3c7b79c189a433742c439a379d11e351c6b46263bn/a Heodo
2020-02-04INVOICE ZND1_145815106.docdoc 1173cf1516a39c758a543aa77e5efb97ae7c0405e4d4921939f774fe9a48be41Virustotal results 38.71% Heodo
2020-02-04invoice-HIX5911_35040827.docdoc b38620f90ec6f200c3c194fb6ec3444c55f50151f4a47cd6ff0eba0bc12a03can/a Heodo
2020-02-04invoice-RJH6_417354881.docdoc c6f67345d51de31d968f542885d815a518e46ae16c2629694893cceceb18ff3cn/a Heodo
2020-02-04invoice-T4_413352872.docdoc 8e2050e086086c77b6f00187036ab0673a1e954b77835c411ce08c5769cca78cVirustotal results 35.48% Heodo
2020-02-04Inv-185_705199871.docdoc f243a8a66b3734ae705e62579b6520ebd361bf4f5b5b51462032c3c2261f8841Virustotal results 35.48% Heodo