URLhaus Database

You are currently viewing the URLhaus database entry for http://meisa.com.co/assets/LLC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422909
URL: http://meisa.com.co/assets/LLC/
URL Status:Offline
Host: meisa.com.co
Date added:2020-07-31 16:18:05 UTC
Last online:2020-08-03 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-31 16:20:03 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:3 days, 2 hours, 28 minutes Bad (down since 2020-08-03 18:48:14 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-01S_PO_08012020EX.docdoc 4bd4448e06404510ab9d35c4f13fca11bfb149a3063e4778493a5fbe17fbd561Virustotal results 46.67%Heodo
2020-08-01P_4277454931151.docdoc 57b1f06463b069ec5b42e62b3dc64ba9b67ce7f179ce9ac5f08c1cd5bc846281Virustotal results 55.00% Heodo
2020-08-01AJZ_MDU_080120_MVY_080120.docdoc 6f043b03996404ae97104ef7baa132eccad7e1f0716fab5798f50d326d64bca9Virustotal results 55.93% Heodo
2020-08-01DOC_BBAOW3NUK946NNUX.docdoc b4bb1c002968b4e90f8455bcac3039b72735ab12cb9966abad99ed6fc66ff0adVirustotal results 57.63% Heodo
2020-08-01FILE_RJC_080120_WIQ_080120.docdoc 7b6a76a3a932265f067c2751c8bd6647327d0ec5bd95563dc3dc38d797a1469eVirustotal results 54.10%Heodo
2020-08-01DOC_PO_08012020EX.docdoc f5671015ad6746cf334bbde3f8310dc831719a74e5432d619f8843e20be44dd0Virustotal results 52.54%Heodo
2020-07-31V_CRRIAGVMB55GV237.docdoc a935b15d7011b3aa5d16b6a78fff2d5053d4336c4784ba84672aeaca1474de38Virustotal results 47.54% Heodo
2020-07-31RI8KJ589YXR3.docdoc 6e57ee227a3844d09aa4ed4a64cf69ec819367f00f8df9bdac7f6e09ffc551aaVirustotal results 48.33% Heodo
2020-07-31DOC_041522778082893.docdoc d3811967649cb2540eaa540cb627ace1afbfd14e0321a81f08ebc6b23d4cb7d3Virustotal results 47.54%Heodo
2020-07-31Q_POJ_080120_NPV_080120.docdoc 7a5911301b1b83e475a1f9d388add6ea34617263f712fc80e34c160f16cfbda4Virustotal results 47.54%Heodo
2020-07-31FILE_18183473535077572.docdoc 41fe7adf7807de60a91dea01796332752f93281e218123f39fa550d31aa15d13n/aHeodo
2020-07-31REP_TW5WLL93HWDLB1.docdoc 33091d857d11e214a1b20764d0cc24a6a1abd2378b9b4e26884874ff24dc2a00n/aHeodo
2020-07-31G_Z6M3O3S26P0.docdoc ad5d63edee98350ce19edb0c144dd79079865cf72f2e092b91678a77835f10c8n/a Heodo
2020-07-31PB_PO_08012020EX.docdoc 1e4b706d611f935dd5aaac2b97e921c9c1df152d9dcf98127840b7c0e60348eeVirustotal results 47.54% Heodo
2020-07-3146514442.docdoc 9a6dd9769534f2d8e5f6089180b437cd38fc654a5f68e09ecede0c636411e590Virustotal results 47.54% Heodo
2020-07-31DOC_CY3933384653SK.docdoc 7ba9d770d237bd49b68182d551c5f73e2f7c00bbcaa22bf9c1107ca4dfd2038bVirustotal results 48.33% Heodo
2020-07-31REP_59315516.docdoc ef664c354f361e0467d36c08c3bb3563f1408bd30c865fc1efd73237b7a26e6cn/a Heodo
2020-07-31DOC_LZK_070120_ZSX_073120.docdoc 4f8d2a942c244360b6b8c311d59352dad83f77899cc7d4094efd99c2e324af8fVirustotal results 49.15% Heodo
2020-07-31REP_XAH79AGQ.docdoc 2c36894f83778d33eaa330676eb166407af8264aa40f395d4086727fb194d1bbVirustotal results 46.67%Heodo
2020-07-31DOC_R2AEM3LBZ7WGXYZF.docdoc 1fb47e6f82f631e677d6380ad07189b514c6783860b7a0785ad02f10f4622820n/a Heodo