URLhaus Database

You are currently viewing the URLhaus database entry for http://onex.co.za/journal/LLC/MNWxStgCzpFsHTKxYxrx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:611123
URL: http://onex.co.za/journal/LLC/MNWxStgCzpFsHTKxYxrx/
URL Status:Offline
Host: onex.co.za
Date added:2020-09-25 03:10:05 UTC
Last online:2020-10-09 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-25 03:12:02 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:13 days, 20 hours, 59 minutes Bad (down since 2020-10-09 00:11:21 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-27MES-2020_09_27-990.docdoc 4893d5828613a7b157505151182a80ad894439fe4f65ebeb87fcf641880ca47aVirustotal results 58.33%Heodo
2020-09-253412670_0350.docdoc 863bbfd4a6aee7bd20295337291b74770af7e88442951513db49b33586ee71f9n/aHeodo
2020-09-25inf-5655533.docdoc 84850efb7ef99e4faee35e1f4711edc0e528daa445edfc24aec1217e3ae6f26dn/aHeodo
2020-09-25Attachments.docdoc 6119c776a665ceeae14b6c41f368a0c8fc38c84de92a8908012785d47cba3585Virustotal results 25.81%Heodo
2020-09-25rep_2020_09_25_774.docdoc 7af65b3e6ff098ff2470d97bd7516a4be13b0853251bd92c07bea314fcc3a209n/aHeodo
2020-09-256737 20200925 79968.docdoc 0ec750da300c9438bf6c4d55c0f4afa754c9db2f1e38eed1e82def35510ca4f4n/aHeodo
2020-09-25rep 2020_09_25 3788.docdoc a498490c2d2082417852e61a598fa2606f70d6a8fd7fd5f6ae72ac00b1276126n/aHeodo
2020-09-25Dat-20200925-AM5641.docdoc 0f674723c07c5218324a68f25f78d92f4f7f8e4662c3856380643e948187a4can/aHeodo
2020-09-25Untitled BDT70489.docdoc 60708ee02046481b73a1e7bc265756eb3a0e7e7d7e5f28d6a2b3a1fea9dc5f4bVirustotal results 35.48%Heodo
2020-09-25Dat-2020_09_25-OM07999.docdoc 21625230474a55191ff09f7f29eaf0cff26e1fcfc6680a91885dda9ddad6129en/aHeodo
2020-09-25Dat_250190.docdoc 1b4bdeafbb09007e953a6160fe436d4804b6edb5069a03724183c8299f6e5ac5Virustotal results 32.79%Heodo
2020-09-25FILE-37944.docdoc 219c155f7385d0d4f45a890eabdef0749ed226d07c1f2bd1e6d5166bfadeecdbVirustotal results 32.26%Heodo
2020-09-25REP-20200925-HQN750755.docdoc cfa0d3a1e1906b7d38dfb055e13882fbff4559fa7d7631be401c0bdd87f31283n/aHeodo
2020-09-25REP 2020_09_25 FMI7096.docdoc a5d07fac1fd1f74e00644c183bfe972d95582bb06c0f8a16e3a0f58cab1152e3Virustotal results 32.26%Heodo
2020-09-2540078-17199.docdoc 7e262533eeb4db4a15145f80b5cd17c54723b81f4dc194da6d449656d5d039a1Virustotal results 32.26%Heodo
2020-09-25Rep-7206.docdoc e3e75a9fd546642652ff675e41bee9686f2bd9812e6cfb36db83ff8e08c67bc8n/aHeodo
2020-09-25Doc-2020_09_25-AA52035.docdoc 6ffae1d9e9a6596659fba02a68da2b4b00a0729ee83731c6a954be690f7c7a0bn/aHeodo
2020-09-2556958B-20200925-86680.docdoc d4f8effbd6965dc96f14d41074b11b187b8173c9f20c950f26dc1dfd243f0a4an/aHeodo
2020-09-25File-2020_09_25-X367216.docdoc 3155aee94b5f26a27b523fe5df878a43d7d7ba601989219c94d61199dfa016a1n/aHeodo
2020-09-25doc 2020_09_25 5639582.docdoc a5d7e06e28beb1225f209f356fa949e12a1d78d304e5e1f90763a41cf83c7801n/aHeodo
2020-09-25Doc EK86876.docdoc 15220c43248046fa93074c3c80521f9773803510ac48a42f7de5b5c28c97eafan/aHeodo