URLhaus Database

You are currently viewing the URLhaus database entry for https://customairdancers.novosigns.com/cgi-bin/ME_33439501/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1968390
URL: https://customairdancers.novosigns.com/cgi-bin/ME_33439501/?i=1
URL Status:Offline
Host: customairdancers.novosigns.com
Date added:2022-01-11 20:36:05 UTC
Last online:2022-01-12 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 20:37:09 UTC to abuse{at}acenet-inc[dot]net)
Takedown time:8 hours, 6 minutes Good (down since 2022-01-12 04:43:11 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-123587312_96949.xlsmxlsm 663ca3b8545e4e02572b5d348a1f77c7ef30d1810e8adbe25dd699b2cfb1792fn/a Heodo
2022-01-129564319_55471.xlsmxlsm b34e6de4f7fc9427651923dbdfab0c34ff83e99f9d44a4bfea838e1b4e59907fn/a Heodo
2022-01-128998-3000845.xlsmxlsm b5e8f3567a440978a4203bb8ad88886ed6d4c9c2ca4a599897d7227c56368bd2Virustotal results 9.68% Heodo
2022-01-12R_083.xlsmxlsm d193efb518a026a5507a4bb6bc168c2f7922c39ce1bb8fd5553512152cc2b88dn/a Heodo
2022-01-11COQ57.xlsmxlsm d3e6a6a97ad6e4f79e73386e88cddd5b958d0f8745c551837dd366b929671704Virustotal results 10.17% Heodo
2022-01-11622_4561.xlsmxlsm e06e1cc33f42f59f86b44d17359234628540e287dc10a39ac66ae21449abd380Virustotal results 9.68%Heodo
2022-01-11P_153.xlsmxlsm d232986e906c448669c346c5edefc1d51b9224b6d53afd360e4768f9861eafadVirustotal results 9.68% Heodo
2022-01-11kpynnxo46344.xlsmxlsm dd14be16e01e5fe53b7cf8199af830a979dbbbc33593606f3b25d7ea3b32697cn/a Heodo
2022-01-11r_932913.xlsmxlsm b8662d7aff6b2489b65fd6ddc022a5a87c6adb0e1ed1f0286ccd80c0bc11471fVirustotal results 9.68% Heodo
2022-01-11dWnD-6815998.xlsmxlsm 8ad61be673c186c9cdfb6c6c8d750fbcf80f920d4905742c0ed9d67833026ed7n/a Heodo
2022-01-11T_771470.xlsmxlsm 69fdc8b909b3d9e8de4ffafb89dff475c99a4e3ac57eda41c014cea8ee8ddcb6Virustotal results 9.68% Heodo
2022-01-1179389_43.xlsmxlsm 8e6f2f4a5b3f21565eb5ebddea133dff53d5904357950842890bc5bbda52ed2fn/a Heodo
2022-01-11177_4119.xlsmxlsm e8aafc15bf0669df883db0e64e8f43f3682a856e74e19e95d9aa6b44aed98ea4Virustotal results 10.17%Heodo
2022-01-1105285SVZKZWRX7556.xlsmxlsm 54ea8278be35064a8017aefe7f5c1f1497983d965e89621a056edb730b109bdcn/a