URLhaus Database

You are currently viewing the URLhaus database entry for http://megasalepoint.com/wp-content/esp/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:698362
URL: http://megasalepoint.com/wp-content/esp/
URL Status:Offline
Host: megasalepoint.com
Date added:2020-10-15 19:25:05 UTC
Last online:2020-10-16 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 19:26:03 UTC to abuse{at}contabo[dot]de)
Takedown time:15 hours, 13 minutes Good (down since 2020-10-16 10:39:03 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-16NSM_100120_OUI_101620.docdoc aa3af1b21af839268143b000b0e8f4a431079b94f69c8025f31315e8ceac2b47Virustotal results 31.15%Heodo
2020-10-16VIB_1859873104.docdoc 13dd027c7d676424966985f919f6af29ceaa868e93910717ac651e65201aaa08Virustotal results 32.26%Heodo
2020-10-16PO_10162020EX.docdoc c4e5490b2508ceaa3f196549d3c7d2865225ebbd56af97bc4a753542204c6641Virustotal results 32.26%Heodo
2020-10-16INV_PO_10162020EX.docdoc 1682a6f58a0d8fe8135a5c7fad215ef799e173618d1292fc89e2ea3fc99f7ed4Virustotal results 32.26%Heodo
2020-10-16IIF_100120_TZH_101620.docdoc 44b5ac3a1688e978f2ab497cb9a2b77b9a4a27edb617212e27b63035becfb148Virustotal results 50.00%Heodo
2020-10-1661550984.docdoc 92d36d8404107035e4524734547170d1517c9ffff23480556c718f4c7c89d3d1Virustotal results 50.00%Heodo
2020-10-16PO_10162020EX.docdoc 147b9616588be0def766828cbdc415348543d772fbf13e9a7fbe0b37b0ebf3fdn/aHeodo
2020-10-16INV_PO_10162020EX.docdoc f677579d45117ccb457830413b6ee450bfe97425e2b31f2b582368410b0b78e9Virustotal results 50.00%Heodo
2020-10-16INV_WC3534728804FM.docdoc 2d9023a6f86851ac7ecb86a93a0c083b17f481474a2b8182c64a69cbda7fb2e2Virustotal results 50.00%Heodo
2020-10-16INV_5FIK7ODQM.docdoc c1a5fabe5d3cfa0cfe41476eed0e59b226db234ae57ea097b50adac70d5d9f98Virustotal results 46.77%Heodo
2020-10-16REP_707438928480587.docdoc 2955467d39aee8efaa08f284298b86e105ff6b8855c674bb41e38ca21d2c6bfeVirustotal results 46.77%Heodo
2020-10-16OFX_100120_NCX_101620.docdoc 766e921c13edd4367d95fd44b3070b9d4bbee1886ba2e298fc91f030e5e034acVirustotal results 52.46%Heodo
2020-10-16BAL_XWN_100120_IDW_101620.docdoc 9ff3fa5bcfc5a9b21abf19a4f8f3c406f0874fd93f8508c58e42529f672a6d23Virustotal results 48.39%Heodo
2020-10-16Z_PO_10162020EX.docdoc 677cb2fc5d7a4e66220d66445d3a7fa7129fefcfad236744a558140e65d7264cVirustotal results 48.33%Heodo
2020-10-16201946362623566518.docdoc 63409e6742b521d02cfb6f833ee7484c6db70237e48675a06c28cc7c9920bfe5Virustotal results 50.00%Heodo
2020-10-160CK6MWHM564.docdoc dc7ade8fcae56fa5c268c86c9602ade9af26324733a73c86e60274a9f5b8e864Virustotal results 48.39%Heodo
2020-10-15REP_87E9S5D.docdoc 70652370e67cef224785a44a3bb57d19f00a8b000714cf7117ed9dec27b3c920Virustotal results 50.00%Heodo
2020-10-15FILE_QGR_100120_HPJ_101620.docdoc 2889aa2818bb6b697ece0258b29a039f5f46f85444792ecad4d3667806bb5610Virustotal results 50.00%Heodo
2020-10-15FILE_US8601855380DQ.docdoc 39c25de18abaccdff5bdbe5fb490b60e00e8b38d1c30556115d11f468d4b6a76Virustotal results 48.39%Heodo
2020-10-15REP_XV9910052979OH.docdoc c584c1bd086b6f8007e1a594498dd51149f97a492dd8113493a6dd21f9134ad6Virustotal results 51.61%Heodo
2020-10-15FILE_HNN_100120_RRO_101620.docdoc d88cc631f25d888116c3b78ddf00181cc391af4dde6f53be7dab166efdfe71e1n/aHeodo
2020-10-15FILE_G8E0C4G3764JIAEB.docdoc 598b4cf3fc5b97854ae8b54625407b4e6b7f05d8ad96b446baaf0855b754074cVirustotal results 46.77%Heodo
2020-10-15O_PO_10162020EX.docdoc 9e6ccb86ca25351f22a9960687787487cd93476f21e943368886f63c03167222n/aHeodo
2020-10-15REP_07901247.docdoc 966af50d9ffd82cdc2a4fa693620dfe90172ef15047cc10d3b35fcd47ae47c4fVirustotal results 46.77%Heodo
2020-10-15DOC_KFN6UFEX.docdoc b9bb517022d0b2c98532d6239bd55d7a33911467a4ca1d6c8d69736530a6157an/aHeodo
2020-10-15INV_02605843.docdoc 52cc4044252ebba622acceb8374c67dac01416c08fc26a5a1e366be2d6a475aeVirustotal results 47.54%Heodo
2020-10-15JV_PO_10152020EX.docdoc 200fd063fbce58987452058b68b6f0d32d9fd51afddd74f6ed466124627fc51bVirustotal results 46.77%Heodo
2020-10-15BAL_SYQ_100120_EXN_101520.docdoc a44bec73fa5d84c99c152a133907faff21cecbabd17faba199a628c8259be229Virustotal results 45.00%Heodo