URLhaus Database

You are currently viewing the URLhaus database entry for http://medyamaxafrica.info/wp-admin/NyICjM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422444
URL: http://medyamaxafrica.info/wp-admin/NyICjM/
URL Status:Offline
Host: medyamaxafrica.info
Date added:2020-07-30 22:41:08 UTC
Last online:2020-07-31 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002838851 created on 2020-07-30 22:42:06 UTC)
Takedown time:20 hours, 43 minutes Good (down since 2020-07-31 19:25:20 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31invoice 4053 259335336.docdoc 25c12d4806108d86841e67f79d958093ac0ee1b28322cbeaae2e7527322b66f5Virustotal results 46.77%Heodo
2020-07-31Inv-Q1473-7711196.docdoc 958410d0bb67c7d367734d2485d41525305b9b547c7382bbc8a615da1c93cf30Virustotal results 46.77%Heodo
2020-07-31invoice7914408157.docdoc d4c0573790c2e02c30dc3ef6e219a26840751e18de0537fb023782af9db88116Virustotal results 47.54% Heodo
2020-07-31INVOICE 18 8371560.docdoc 015ea078c5fd0a7e7358750b113536aa28746f179954e4c37e6185b99888c39dVirustotal results 46.77% Heodo
2020-07-31Inv WNMM8 5393766.docdoc 8d668df833984a5c527237ca2ab0cafd0d9358925912ce0c64cfb8fb749d09f8Virustotal results 47.54% Heodo
2020-07-31invoiceAO1285556697.docdoc 7215486425975ce0aa1c7e3e980b1c70b6bde41a872a7b946a2445fd733a3701Virustotal results 46.67% Heodo
2020-07-31invoiceAO1285556697.docdoc 7215486425975ce0aa1c7e3e980b1c70b6bde41a872a7b946a2445fd733a3701Virustotal results 46.67% Heodo
2020-07-31Inv-H533-157543.docdoc 955df219d60bd853070b3b3202dffdc5458ac8fed8c076c8c8076baf06348236Virustotal results 46.67% Heodo
2020-07-31INVOICE_N3783_179168003.docdoc 991fefb51ab6ff987891d3156610be49073ac26a760411d94ff209425c7af854Virustotal results 47.54% Heodo
2020-07-31invoice-EMY0-953397.docdoc 329ee2c468d88dcf1fbfeecc4f4cd304e2f5bab2e86ac85a7577f4e02f0f7067Virustotal results 48.28% Heodo
2020-07-31Inv_7743_02401221.docdoc 1bbf1c280e0399776065e6c00e7ccc32e3dd3657069cf5d5f27ccda9a1e53d69Virustotal results 46.77% Heodo
2020-07-31INVOICE_58_12834808.docdoc 8d4a6bbe8331ba2970792f5e37e044765e5a0c7df74b1e26d8e0af16b6390bd9n/a Heodo
2020-07-31Invoice-I111-513445804.docdoc 74ea191fd9dd8739f62ffc1cb8d3ba2aad0b198006c5e8aab604e362798cdd45Virustotal results 45.00% Heodo
2020-07-31Invoice-ZMUG86-2813427.docdoc c1750c95a8c4d6fa3ace82fdd29e4da91bc8ae1612124941dec4b06310e9a00dVirustotal results 45.76% Heodo
2020-07-31Inv 4531 1168230.docdoc 1e78d834b4871e8021b0bdbff55c32e9a28bbb0f6901965f9c2bfe6c2ee9eae7Virustotal results 45.76% Heodo
2020-07-31Inv-0-469118753.docdoc 26a1feed3df8164358b5997371f3ccad341b539859c7ed75914f15c59df315ddVirustotal results 44.07% Heodo
2020-07-31InvoiceQJ26{:REGEX:.docdoc 3d8ef147ca84e9943fdc850171e2de9c05b0db3472cd05901e4f109e7fbe07f1Virustotal results 50.85%Heodo
2020-07-31INVOICEQ4649_543713.docdoc 24faef0a3c46f8fdf60a5fff6f323ebd01a0365dde63a55a242ecfa0455183baVirustotal results 50.82% Heodo
2020-07-31Inv-1684 76646047.docdoc 98736475243073034ab4507eda664966af3cc2025cc4f026364550e1fb270661Virustotal results 50.85% Heodo
2020-07-31INVOICEDO040-100048.docdoc 5399417505ae67bdc2253943f273fe2b69fcdb71294530cbfe0cbe731a251b48Virustotal results 50.00% Heodo
2020-07-31invoice-KX1154 35314295.docdoc c8586306addfc533e0c3ee2c72a3a19e28d38b0e41207d72632708e52ee965abn/a Heodo
2020-07-31Inv-KZ7697_344287.docdoc eae169c0ec808dcf097bfd419bae07e5c001b1157d781d90b037250ea07fd4bcVirustotal results 50.85% Heodo
2020-07-31Invoice-QJ89 699049145.docdoc b6ffa6767e3b7c53645dc329280108bc5145c28514aad30f28d9b628bb3bed9dn/a Heodo
2020-07-31INVOICE-0962 72399973.docdoc 48c0326e786deae1ebf50df4773916c79325d15261708cccbc89d2421c639729Virustotal results 51.72% Heodo
2020-07-31Invoice QWLW5{:REGEX:.docdoc dcfb38249b589a264dd4ce2c25853335f1399685fcd68d68c337f308d110a793Virustotal results 50.00% Heodo
2020-07-31Invoice 809-803386.docdoc cee085d16cb1dec28ff7ef5bd5399111ba8a5e26623b17902866e886144c228fVirustotal results 50.85% Heodo
2020-07-31invoice-PQP4 004854554.docdoc 468c03e5514c45db80f93d359506f99bcdc95812e5e37680b531dd2fd1cba7f2n/a Heodo
2020-07-31Inv_YLNX1345{:REGEX:.docdoc 2a378624ddc963eca6688d3c25bec4bc7637de2153e1f23f594622a03f6e600dVirustotal results 50.00% Heodo
2020-07-31Invoice_RHTB590_58658666.docdoc 2789d1d3eea1e5dcb760faf9bbf395f267ec901bc7c52a67ae60133050897609Virustotal results 50.00% Heodo
2020-07-30Inv 455-133648.docdoc 2e24bcec136a5b896e730820974bfa9162575d275b2ee669ece097f7b195e4f7n/aHeodo
2020-07-30InvWXCP12-9117387.docdoc f2e5dfabe9cc22bc5f4995c900e073bcf2219dd18413aa69a7d1148fb6257585Virustotal results 50.82% Heodo
2020-07-30Invoice A4415 979200143.docdoc 881c5ef2385626accbec7572c0b5c5b5cdff760f61e1bb044546983d6c3fbdc4Virustotal results 50.00% Heodo
2020-07-30Invoice_5-3819731.docdoc baef0f6a498331d648f442e8851509d8e91245685e215ae6beb917e8d4a9980cVirustotal results 52.54% Heodo
2020-07-30InvXTYI1552{:REGEX:.docdoc 011f53f91ed6b3d4113cfe1b87fe6f289d409a87187216f7b8520cb638a16b20Virustotal results 51.67% Heodo