URLhaus Database

You are currently viewing the URLhaus database entry for http://mgavisa.com/wp-includes/esp/wy0qEFjnaeygH3j944ZH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:585577
URL: http://mgavisa.com/wp-includes/esp/wy0qEFjnaeygH3j944ZH/
URL Status:Offline
Host: mgavisa.com
Date added:2020-09-21 11:46:03 UTC
Last online:2020-09-23 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 11:48:35 UTC to abuse{at}hetzner[dot]com)
Takedown time:1 day, 20 hours, 1 minutes Poor (down since 2020-09-23 07:50:22 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-23doc_925.docdoc d077391f811e9aa25621f5140c96860cdda3b56bceaf5245e4d4cbc6a961e6efVirustotal results 30.00%Heodo
2020-09-23INF QWV7483.docdoc d29db979a44af6a91074afd2c68cd3c1f353bc4f4a30a953916795ecb3813e61Virustotal results 30.00%Heodo
2020-09-23Mes_R976.docdoc ead5e12d378c9099bd007886c313ffb492b6d6579557cc4cc9288566b7739663n/aHeodo
2020-09-23Dat-VO83884.docdoc 4f09397b6219cc33b6d317121c35865043663d6bead47a855a9d33820f8f49fbVirustotal results 29.03%Heodo
2020-09-23Arc_72217.docdoc 2476d30165bd880c46ae9c11a0a7dd1c90560cc39805f1255fe7c888fffb5f72n/aHeodo
2020-09-23INF 20200923 492.docdoc 799375bc17349fabb727d209dce766f0f790222a89a95d7783de4428c113320eVirustotal results 29.03%Heodo
2020-09-23File-2020_09_23-PF834.docdoc 027663162c00f241d945da03d397e35d882cdccce8e0e487e463501b6d2dd503n/aHeodo
2020-09-23Rep_20200923_845723.docdoc a1b5ef92ceaa6be33f3950c95ae60066fd936f9757ed3213b26f31ad04659cf4n/aHeodo
2020-09-23DAT-20200923-ANP141.docdoc 66fb0ff0bc019411aae249302066f28d3d4a17f14d79cb2d743b4b3f86cd2e0dVirustotal results 30.00%Heodo
2020-09-23Untitled_2020_09_23_231770.docdoc ffeeb0722e07550459e556ff30cc8718de924313f5eb93821a1ed9dec87e5df7Virustotal results 29.03%Heodo
2020-09-23Dat-20200923-87413.docdoc ca4c7b4c1ea9e7145ff335a29663652adfbb0ebb877a560a33b1d60ae678da95Virustotal results 29.51%Heodo
2020-09-23INF CK06444.docdoc 352b0eaafd07102686fb7e59059288bd6f527e4190c6700cc5dd1e6f267bda16Virustotal results 29.03%Heodo
2020-09-23FILE-YP293905.docdoc 23aff50ac3389334abb3560b23550c5849e7d2837d24dab1b1874048977ff19fVirustotal results 30.00%Heodo
2020-09-23arc 2020_09_23 SD11111.docdoc 9c67d232abc4ea64aac36180f8259c7a5a52ae4ccf35ac7d5b9e6f350f5ee00bVirustotal results 29.03%Heodo
2020-09-23Doc_808.docdoc 835f71195c622e6d5dee5f8d307078c0efd97045a75c08947600350fb2da5a5aVirustotal results 27.42%Heodo
2020-09-23arc 2020_09_23 YWM7879.docdoc 97d2b08197301a0059c2de0cbd059211231382fd31f2435fb72eea7eed55031bVirustotal results 27.87%Heodo
2020-09-23Attachment_20200923_AQH058.docdoc f2e74e9f4eff803c24130a1d601bf039e1c14eb872c3aa0f026982512146ffc2Virustotal results 27.87%Heodo
2020-09-23doc 20200923.docdoc 24902fba74d4a7285bcf27a18267f05e104acd3dbb083de1c50f854e491b2378n/aHeodo
2020-09-23DAT_2020_09_23_3318.docdoc 3b12b9e3c5bb951db8bd86ba2ed902362a034487b029eb22199b2a7c28264480Virustotal results 27.42%Heodo
2020-09-23Attachments.docdoc 3d1707b3867ae69cbfe18261cef10deb79add9d180448d455e6736499be9c3c6Virustotal results 27.42%Heodo
2020-09-23File-QN41626.docdoc 14fb3459b2830d93d3158893cf9d19a967236429dab7740d73d83999d23d380dVirustotal results 27.42%Heodo
2020-09-22list-2020_09_23-NJ0938.docdoc a132f8367518b36376bd03160587713674ff98805021fed3d6e3ff58c045a97dVirustotal results 25.81%Heodo
2020-09-22Attachment-7797.docdoc ddce72ee2a6c8276c490d00f3c5334dddbfef7dd01107ba9b47b8620b5f04f87n/aHeodo
2020-09-22mes AV93751.docdoc 63fe6f0cc7e175202080598dbeed5c1f7beef33c935620ab3b2d0665c7e3a311Virustotal results 30.65%Heodo
2020-09-22rep.docdoc e3187dbe7923459b3ea645a3d68b357927471e14d70aa4e542327ad4ef540637Virustotal results 32.79%Heodo
2020-09-22inf_MYA0440.docdoc 95f26a244aca835b474bdf449493ab967a0b39f10683f8df2254f678a595b989Virustotal results 30.00%Heodo
2020-09-22UNTITLED-804.docdoc ed8d8e2b3ecf9f7c9623777392dfc8655b5c3db9800977815afe28fd2a380a8fVirustotal results 29.03%Heodo
2020-09-22MES 20200922 3690405.docdoc 6f0e03df41433654a653fde3c2dd49f9839e5c7f59ab54dd3ad0526d2670f4d7n/aHeodo
2020-09-22mes_2020_09_22_JRK0008.docdoc f7d2c758c06cd5e2ee4d6e2df8ef0dde049145434e8cb1ed6d667aa35d5c5877Virustotal results 29.03%Heodo
2020-09-22list_CDB9633.docdoc e13fcb0d33f6ee3f84684fa5658bb952f5d4a04bf0b0f391629541708f516ef1Virustotal results 29.03%Heodo
2020-09-2206390GJ-K214013.docdoc 3c8a083cba6f42eeca7d197da85d0ab24ee5e9e03de7d32eb976903c4bf4a604Virustotal results 27.87%Heodo
2020-09-2262769214-PGJ0347.docdoc af186c14e8d9749cce94d6ca5d2f4c8d66e9d06962f8ce370b0efcea3b7897f7Virustotal results 29.03%Heodo
2020-09-22Mes-UK2258.docdoc f70acfaf7932e07a6befae363c753f68bfbd78961bda44459f6051aeda261c90Virustotal results 29.51%Heodo
2020-09-22File-20200922-SKR477.docdoc 807f0fb8f94f16a66f2cba86e04982b3c8cce542eb80678040264f2a5f3ea051Virustotal results 29.03%Heodo
2020-09-2296954-20200922-D379.docdoc 3d3e7a36ee6daa96f0746464ac4059212f6edf7c2d5e73e9b3ad85667293ea4fVirustotal results 46.77%Heodo
2020-09-22LIST 20200922.docdoc 8acf0b37d385a10275fd3a0bc004262403e9760f7a88e529e5a51ccc176f26e3Virustotal results 46.77%Heodo
2020-09-22ARC-425536.docdoc fee44ec3b333796685007e96f4c1478fc810a6a4549ed0d18c4e26fb91e508f0Virustotal results 46.77%Heodo
2020-09-22Doc_2020_09_22_ZG0851.docdoc c4699bc83e2c480aa53af341f4b67b5dfb27cb5d28fb09a7619b55689b686ae3Virustotal results 45.90%Heodo
2020-09-22rep 2020_09_22 8778.docdoc 2c9c3cbda0aa694b7f8075132ef84de6c06632e7959d6356634acb932ef4d9b4Virustotal results 45.16%Heodo
2020-09-22Doc-HH761.docdoc c02f344560f245e4228f6f218c205578449c7da6d58290a4e59fe7a1fc87a1c4Virustotal results 45.16%Heodo
2020-09-22Untitled_Y8259.docdoc d319ca8bb25ffbd71b92f69f73f46e20618ff475a6e7b60c7413ff6f676ee424n/aHeodo
2020-09-22dat_20200922_JZQ886.docdoc afa0a61bd99aee69ed4e9507affec82529f4e9a2de5a1aafab8bea4a44af7b0bVirustotal results 38.71%Heodo
2020-09-22REP-B705627.docdoc 1f6ed2ece5d580a01e3e3afbf88bebc1ecd74f37e6fd2b256ecb855d82941667n/aHeodo
2020-09-22doc 2020_09_22 067.docdoc 86f5a840e37520ee3de241a48fb38347df2babd2b311ee264bad91bb349dd475Virustotal results 37.10%Heodo
2020-09-22List 20200922 2361.docdoc d4ebc64e8b514d0421a035ef5ead0893ee01889332cf393385f2a460b0b6807eVirustotal results 37.10%Heodo
2020-09-22Attachments-U10359.docdoc 21522233d51172d1c9e3dd7ac515ae5cfaa2233c12d418866d392063e32088beVirustotal results 33.87%Heodo
2020-09-22FILE 2020_09_22 ZN8867.docdoc ec0011702614cd33aa57769c23abfa9106382cc9b99ec9a1f9bb57204cd157d9Virustotal results 32.20%Heodo
2020-09-22Untitled_2020_09_22_Q118932.docdoc 52de3e5c1757f2f963ae355ff3194a0d0dc123cf3ffff1a3ccc0374f8ba73502n/aHeodo
2020-09-22Attachments_2020_09_22_10287.docdoc 869d585ea34405afd2c82aa0d5ac39d4328b70429259c4358c2bcb81fe5f0b96Virustotal results 28.33%Heodo
2020-09-22INF RB616.docdoc 71662eb323a9a4af953568b9ee749cabc486bbd0e17d2b0cf2d52ff88cf6bbafVirustotal results 25.81%Heodo
2020-09-22INF_ZNP8940.docdoc 8d0bfa85c33d7f8725fb13809780b7a2ca9bf9ccdad1780e4e4a55bc670948a7Virustotal results 22.95%Heodo
2020-09-22REP_2020_09_22_5814471.docdoc ef28e3219caccf8576b7f4eb7146b9fc62fa24e5e962b80f11c01df5a146e758Virustotal results 23.33%Heodo
2020-09-22REP_20200922.docdoc 7bfde47fcd28e6a17aaa935131ac5e119a454718666722331ef2836df8efc82dVirustotal results 23.73%Heodo
2020-09-21REP 20200921 302.docdoc f515aa20198574ad28264b78c6e2e4387697c8d8854080321942c2036133eb53n/a Heodo
2020-09-21List-2020_09_21-F794126.docdoc 0f3dcf665c7ea9ad31fbcaa324e8f714b5611ca2d55c539279fe724acbf61cfdn/aHeodo
2020-09-21REP 2020_09_21.docdoc 868ba9aad8eb6aafcd6a7f0478da47b3053f110fa35aa2e1e49d9bc8c0888b1an/aHeodo
2020-09-21list 2020_09_21 D07932.docdoc 7324fb63ab2862f03f39836b95eac796f953ca27fe0fd545bb8b8fb8c99e3a36n/aHeodo
2020-09-21Inf_2020_09_21_0350.docdoc d514c46c30e752ee22291f4cfce174467d0b7c6ee1506f12d854a4090fb65ef0n/aHeodo
2020-09-2106854_2020_09_21_N9359.docdoc 3a05776c14b74dde1308f9a7a7098c4c6fbc065004db3227330937bc0a1eeaa1n/aHeodo
2020-09-21doc-20200921-IWV698.docdoc 5b553de983ac2fa97b6d41a6bc545e330a7e725deb81c7d4ebb0e795becacd4en/aHeodo
2020-09-21dat.docdoc 3a3066eb5fc603c6bd26e82784e4692ad45e2ceb005e34ef397224cb38b9800fn/aHeodo