URLhaus Database

You are currently viewing the URLhaus database entry for http://ekinerja.megadata.co/wp-content/j2dp-feq-14/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428151
URL: http://ekinerja.megadata.co/wp-content/j2dp-feq-14/
URL Status:Offline
Host: ekinerja.megadata.co
Date added:2020-08-10 08:59:08 UTC
Last online:2020-08-10 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-10 09:00:03 UTC to abuse{at}cyberdata[dot]co[dot]id)
Takedown time:6 hours, 48 minutes Good (down since 2020-08-10 15:48:22 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-10Invoice 3171 7614233.docdoc ed081b9b0a350734ab4ceaac42cdee79d84da0ba4c9c5382993097e87d45a684Virustotal results 40.68% Heodo
2020-08-10invoice XNAL9 851484.docdoc 148e5b96354bb6bac513da844eb4b80372d70c7470911397f3285951081fc9b0Virustotal results 40.00% Heodo
2020-08-10INVOICE GCJO6 246534.docdoc 1685e268d62bdef6a53269862bb3726b833dac9e099fbcc882f9631629c0940bVirustotal results 41.67% Heodo
2020-08-10invoice 0637 396129687.docdoc 180a51fa45aefced7c4143c63a1bf026a398a8859c45c2de83e2589f0950393dVirustotal results 37.10% Heodo
2020-08-10invoice-21-632975838.docdoc c10c7069f668e89c9cc6a3ab2bdff06d7f6330e242012734cc3c2b7aa7a5df28Virustotal results 33.33% Heodo
2020-08-10invoice-YYH86-935035552.docdoc a9cbdf54fbc3fee8999fc438c81ed2dcfdb55656fccb1a67114b942e8eb8d306Virustotal results 35.00% Heodo
2020-08-10Inv-D9237-85590962.docdoc 4401bc2ba3095fe07b9b04c2639476e7d9ec25978d039437a48ee55cc099614aVirustotal results 28.33% Heodo
2020-08-10INVOICE-KJ0423-164395.docdoc d7641f03622e05f6323263f38c4fd70ec5b9194253a644859fe64748f6d81369Virustotal results 27.87% Heodo
2020-08-10Invoice-18-33092608.docdoc d0d97c09c0b513ac5f69066285cde071b5e0635c39cdd0048b3ed74fc0a0852dn/a Heodo
2020-08-10Invoice_P2_360781.docdoc 2ea8266f2dd9d4c82e29049618e932d8f29c45e72510de81ae28a5b624932b69Virustotal results 24.59% Heodo
2020-08-10invoice-40-129928.docdoc 51c87735884d63e648c30042618b06e0b06960e9e58dc19c95dee1da38a7c0c2Virustotal results 24.59% Heodo
2020-08-10Invoice-G963-2739271.docdoc f0218ef1c7f0104728a8f4893af346731cde2cbd9e00b373a731e8055e16f7a8Virustotal results 24.59% Heodo
2020-08-10Invoice-NE578-391193.docdoc 992a276be39fa5bb52f8159e39ddd8e5750a7ef3e2d051e9918c2202a3e6ea2dVirustotal results 24.59% Heodo
2020-08-10invoice-RRUT95-06610187.docdoc 6e637bbd18e433b5ef026dcd1028c6fbdf43e3cf11040f6a24e1496b696cd3caVirustotal results 24.19% Heodo
2020-08-10Inv_EBQ5_104288.docdoc d3533129ecd020824e13981ef730b04ddf68e11d9d332ae5101174c6b7f1f5e1Virustotal results 25.00% Heodo
2020-08-10InvDZS51670354011.docdoc 2a2a4e8fa56599f52cab485cb5ff8c064e3680295db76e7e11d25489250334b1Virustotal results 25.00% Heodo
2020-08-10INVOICE-UE2089-960312634.docdoc 299a4a4f08f41ab8a2fd28745ba178a978b720bf7a3a97daca2f48b434fa6a3eVirustotal results 23.33% Heodo
2020-08-10INVOICE B5946 775260132.docdoc 64b4da39bea431864929d11d2a2a11520d165ebaa2d69dc9e6577e6324700d63n/a Heodo