URLhaus Database

You are currently viewing the URLhaus database entry for https://ownchoice12.xyz/wp-includes/89216857-1980576/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1973868
URL: https://ownchoice12.xyz/wp-includes/89216857-1980576/?i=1
URL Status:Offline
Host: ownchoice12.xyz
Date added:2022-01-13 13:06:11 UTC
Last online:2022-01-13 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-13 13:07:17 UTC to abuse{at}amazonaws[dot]com)
Takedown time:4 hours, 18 minutes Good (down since 2022-01-13 17:25:58 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1385226151.xlsmxlsm 3e8ac5b89fdb8697813438a75aec6df15ad029e5c499a023f5bc7a209ff1b13bn/aHeodo
2022-01-1357390279_966677.xlsmxlsm 78dd5816d66701839612b5caf64d4337e45d516e52b5f177345f5019ce4aa907n/a Heodo
2022-01-1358392240_13016174.xlsmxlsm 115b1bbc0363cd535f4336aac31bed3fa17e2c2a4ebcb15618e55c9dfc91896bn/a Heodo
2022-01-13134724.xlsmxlsm 4f9ce5c9c9dd88a6a01a3df3299e0aa43da3bad195036c22b141f28769708334Virustotal results 27.87% 
2022-01-1363527338-35.xlsmxlsm febd9978510715acb1f4bb87d04412fb1e3e6e2720329590b6b146de515d2d85Virustotal results 31.75% 
2022-01-13612489878-777062.xlsmxlsm c87454534ee25d7d677e5bab46857f861240685ce17532b788892d370096be83Virustotal results 30.16% Heodo
2022-01-13VYDY544769.xlsmxlsm 41750a936f4e59a899e45972dd3ccf154305807c52bd7e5f5b19344e909f86ban/a Heodo
2022-01-1397581-77977.xlsmxlsm 2d009791d777c752c4fddb6e32e5d123d7ecf80145baef849436bf4879259b8en/a Heodo
2022-01-1398110_0831.xlsmxlsm 109868bbf981851bac44548c11bee90f08fd3c83e06c9b9539f568e047f45e0aVirustotal results 32.79% Heodo
2022-01-13733196-6764059.xlsmxlsm 93d3e72ebe801f6ce7a577d88f1cb395aee4124d390adf1b4d2711786623e0d6n/a Heodo
2022-01-13VK_4647.xlsmxlsm 8afb20c75c55c9430321b9e1bc404d9178c80a2f7f39f2cbb632e24cd2d4ae87n/a Heodo
2022-01-13129681784_66441794.xlsmxlsm a614f219d2ac01684232b60b059d1501b606e08d969465cdb9144286dd042c2fn/a Heodo