URLhaus Database

You are currently viewing the URLhaus database entry for http://stratexec.co.za/training/mahz3mkicx/97pr1577695146697asjxht6y5ka2cpodqrl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435271
URL: http://stratexec.co.za/training/mahz3mkicx/97pr1577695146697asjxht6y5ka2cpodqrl/
URL Status:Offline
Host: stratexec.co.za
Date added:2020-08-17 23:48:19 UTC
Last online:2021-04-28 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-17 23:50:04 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:8 months, 13 days, 12 hours, 14 minutes Bad (down since 2021-04-28 12:04:24 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19149945282398.docdoc 03c177e560713d7bea35f5f09a80811e163ffd703f9df3f38610095666693630Virustotal results 31.67%Heodo
2020-08-19DOC_Z7CWF6QFICCK2V.docdoc dec85f1ead815b5c109e7a7e9793a63849fc89f591a2e29a5c266b91280bcf08Virustotal results 23.33%Heodo
2020-08-19BAL_YQM_080120_VTM_081920.docdoc 8d3b2fdc25288364fd65d1dd62308aadc287a87a4dd553b72a6937c088715771n/aHeodo
2020-08-1980599381522496727456.docdoc f0a8ac44de88e568c8758ef8d4c1fc77b88d80a19045c8b48676c7f7714cb615Virustotal results 23.33%Heodo
2020-08-19PO_08192020EX.docdoc 293921527da71236ef9e13d2b761e81efe85607ab084b379dd797bc3b6a31218Virustotal results 16.67%Heodo
2020-08-19FILE_2AGNSJR.docdoc e10fd6b719ccb741ff632f1141214caa698376417f9615419d85d200cff1bf6fVirustotal results 16.67%Heodo
2020-08-19G_04776458.docdoc 3780d20be48fb349faf9fb0fc17e1eb9f3a3060e3d57af2bbd7e20d6b0b4223dVirustotal results 18.33%Heodo
2020-08-19INV_GFL2Q8JOPOT.docdoc f72a18b5e7cf69423c431ec5aa068b8ff80aaef4050ccb7a64b2e509a231f8c7Virustotal results 45.00%Heodo
2020-08-18Z_309479769984371321.docdoc db2013508bc3e41f1f93da8cc42b9edcae448ab5eefe05b364e1ce01247dd763n/aHeodo
2020-08-18YZC_080120_ZGD_081920.docdoc 6132d38c562ce3fd2f815bb85f961fe7be3153f058d6b86f366c69a51f65bbf8Virustotal results 42.37%Heodo
2020-08-18FILE_11576041.docdoc fe26e82cbd2b5d6687f5b9793748e9e53f958a4c71decf035c8630a50cc24fe7Virustotal results 40.00%Heodo
2020-08-18RM_25743191.docdoc 460a8e4f639b96c10e0094ce3aceeb1f60278284a1d7b27e3b16fd4b76744636Virustotal results 40.98%Heodo
2020-08-18BAL_MDARX53IKR.docdoc 8f113aa3e0e0c6b2e83af971e3675874b5ba848bdb4ddf0be0cf15d8df0a03d3Virustotal results 38.33%Heodo
2020-08-18BAL_22370679.docdoc a86930bc30ff0b73aa01cbdc19cf0503ba59a676f992f7623d399e1d54e13a56Virustotal results 26.67%Heodo
2020-08-18BAL_478782872190675604840707.docdoc 0017bd312dca6a55a4c8573e1bb88ad991b85da2a1546ba713ccd52f2554132aVirustotal results 23.73%Heodo
2020-08-18N_UFR_080120_BCG_081820.docdoc d021a79aebe130ed1440dfc99908def9a8947d245ad9f8c9dec7a339adc06135Virustotal results 22.95%Heodo
2020-08-186209613412887913070.docdoc 92674d8d935ca49cbe4489ad9f6b55bb98697e74750d26bc138edd3c70f214b4Virustotal results 20.00%Heodo
2020-08-18INV_PO_08182020EX.docdoc 3d046766ec30e113966502a639a2055522806959804ab8ccc127a7690caa5456Virustotal results 21.67%Heodo
2020-08-18QP_07736680.docdoc 32e48dcbf4e76c4b36965f707ceeb7d30e379c45840a425af07b91ea27932c06Virustotal results 21.67%Heodo
2020-08-18B_AJGA4M3.docdoc 7976a8188a5d793cdbb85eae76d2bf5dcd550789634815969fd953edefd06been/aHeodo
2020-08-18FILE_PSA_080120_NQB_081820.docdoc 8265ec213eaa6d222c57d0befde6281f1e53f7cbbc3e23df4b0b151921316accVirustotal results 45.00%Heodo
2020-08-18JKM_PO_08182020EX.docdoc 5fd9d575a13678e66d43f02aa919121a34f26ff8ef42fd2b43a475f1e96a0188Virustotal results 40.98%Heodo
2020-08-18JCE_080120_CMI_081820.docdoc a9f2dfb969ec4a5c09edfdcf49a041eed112c8ef64c36610131b1ef17118292an/aHeodo
2020-08-17REP_GFA_080120_LOC_081820.docdoc dff1df7c560a8a24caa14cf006d941b7c3d80648923fc99f691cf668706dd683n/a Heodo
2020-08-17BAL_JX7663811820MF.docdoc 8db1361f62d2104158b5d7ce624e355ff63fa255281de2a93eed9e0a2c523432Virustotal results 43.86%Heodo