URLhaus Database

You are currently viewing the URLhaus database entry for http://nav-a.com/wordpress/YTQW_30130452/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1968513
URL: http://nav-a.com/wordpress/YTQW_30130452/?i=1
URL Status:Offline
Host: nav-a.com
Date added:2022-01-11 21:19:06 UTC
Last online:2022-01-12 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 21:20:10 UTC to abuse{at}gmo[dot]jp)
Takedown time:8 hours, 15 minutes Good (down since 2022-01-12 05:35:48 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12UE73353.xlsmxlsm c95bf0dd160b7a12ab600aee9220e652b1b1cc3b006f264c324a0c0a9d5aa257Virustotal results 9.68% Heodo
2022-01-1203508659191049.xlsmxlsm b34e6de4f7fc9427651923dbdfab0c34ff83e99f9d44a4bfea838e1b4e59907fn/a Heodo
2022-01-12698766173-99724888.xlsmxlsm 978af74bf15d2a91d89790b36c10deb099346510e755e8915883f43401b3fe10n/a Heodo
2022-01-12JKTR_8070950.xlsmxlsm f20a142423cea7ec0369d225894d4cf71f4c31d425bf0215de2b6277a5354192n/a Heodo
2022-01-110959365IYDXI54203.xlsmxlsm d3e6a6a97ad6e4f79e73386e88cddd5b958d0f8745c551837dd366b929671704n/a Heodo
2022-01-11jSSwXj1985176.xlsmxlsm e06e1cc33f42f59f86b44d17359234628540e287dc10a39ac66ae21449abd380n/aHeodo
2022-01-113724492_87253433.xlsmxlsm 6ec9e504112744f9f07ce60fb9315cdcd427d27a16c248fbe9746477bfc851afn/a Heodo
2022-01-11NZ_983.xlsmxlsm dd14be16e01e5fe53b7cf8199af830a979dbbbc33593606f3b25d7ea3b32697cVirustotal results 9.84% Heodo
2022-01-11mtyjA-3541.xlsmxlsm 410781f7086d808183f2b361ef8c56f8cfc53a1448d8182434183d00d73403edVirustotal results 9.68% Heodo
2022-01-112608350-76746737.xlsmxlsm 71da6e57fe5adfa0b06f8ba9525e6db95e7c25246179fa8563561d24e79e6c65Virustotal results 9.68% Heodo
2022-01-11TUX159664320.xlsmxlsm 69fdc8b909b3d9e8de4ffafb89dff475c99a4e3ac57eda41c014cea8ee8ddcb6n/a Heodo