URLhaus Database

You are currently viewing the URLhaus database entry for http://npktechs.com/b/JRYOT-35/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1967731
URL: http://npktechs.com/b/JRYOT-35/?i=1
URL Status:Offline
Host: npktechs.com
Date added:2022-01-11 16:35:11 UTC
Last online:2022-01-11 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 16:36:10 UTC to abuse{at}hetzner[dot]com)
Takedown time:1 hour, 25 minutes Good (down since 2022-01-11 18:01:49 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-11918386-38.xlsmxlsm bb42c503ef90a3b580fe241d3935057273211a16974921ce0999f778cfe35f7en/aHeodo
2022-01-11N_571474.xlsmxlsm 6913af2de9271a92bd9c7c9afe4923a08f237459d7e1e03d171e96fa291e39een/a Heodo
2022-01-11OVW_135733.xlsmxlsm 79d5dd947b7300d32ff8facaa4720be444a2f7af9062654df5693bb426c9f3abn/a Heodo
2022-01-116037837-50327764.xlsmxlsm ea33d4681caae745548bdf42e52ffe5e63cedfb04acb9ec0aa32ac90d4f091c0n/a Heodo
2022-01-11RLPCZ5470.xlsmxlsm 314beb338f0644b4900ecc03c9ae919a0cb841f556fa61e02d205c281c278206n/a Heodo