URLhaus Database

You are currently viewing the URLhaus database entry for http://ozvita.club/wp-includes/kpmlgj_715340/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1974295
URL: http://ozvita.club/wp-includes/kpmlgj_715340/?i=1
URL Status:Offline
Host: ozvita.club
Date added:2022-01-13 16:16:05 UTC
Last online:2023-06-22 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-22 05:12:06 UTC to network{at}abuse[dot]team)
Takedown time:1 year, 10 month, 17 days, 12 hours, 6 minutes Bad (down since 2023-11-22 04:23:24 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-14wnexh-990.xlsmxlsm 689555499fd2dff9a85acca987cf63ecb004150fb9428e7336b11a90eed8a4a6Virustotal results 33.33% 
2022-01-14LX087192118.xlsmxlsm a0eacf656900552c56c986b37f31393346ec3d6cf406724b775a6ca9e166502bn/a Heodo
2022-01-1435481291-209.xlsmxlsm 30998e271a430bad7397afef57404301030b49c3fc434ace1db143a0ee8252e1n/a Heodo
2022-01-14059772376_1256.xlsmxlsm 3e23d05ec9aa086013200c2df62ea349686f0b76b06f16992f3af4cdb0735bb4n/a Heodo
2022-01-14KQ_008640721.xlsmxlsm 773b1e197f1518363d69da936e0f8967af8d77decd75ce63ca091f3b1a6635ecn/a Heodo
2022-01-146459_5290312.xlsmxlsm 25ffc4f1a9abeb750423f929d563d90c09121eee81a928f86f02f8e4421f5c7bn/a Heodo
2022-01-14T_2653.xlsmxlsm 1205cb62fc6aa2332681d1cd2f1f626c67c13a8fd8bb2814ad1f0c474f72cf46n/a 
2022-01-1455_48421842.xlsmxlsm a972c47050ae7cf97f0c52155e8ab1462d5a9606eaf7140f1ee56f1e8a45dbb8n/a Heodo
2022-01-145866635871603.xlsmxlsm 1d5a664f5ee71027f50ea0456755bd1285f2d04b4bbfbdb59389b49e9aa3f06dn/a 
2022-01-148276_3.xlsmxlsm 1f33cccbde25d58a817b0b6355084b8d0694bb104019808808694c2e6bbe2fbbn/a Heodo
2022-01-14fec_668890.xlsmxlsm 8241a915f1a80d0c6898233cdfef1c73d4e00a2b17c41b4bf84984d9b4234f46n/a Heodo
2022-01-14xgy962954.xlsmxlsm 014ff5c82b7c1bdb0b30b6c7148eba05ceb93243f3a0611ff6ee6be8d29009a3n/a Heodo
2022-01-140886_19079370.xlsmxlsm 33907752a95eb439381ffe72885f212ed6dc3f71fb2a3a352478b5fd83ab3eden/a Heodo
2022-01-14ewlx28493699.xlsmxlsm 1c8efbc70bde55f70789960968bfdb1a261eab6bc372e1f6859aee00261a7f82n/a 
2022-01-1482151-779146603.xlsmxlsm 2a6e2750b860bc0613cffb355aee98ee8fa3930d2f1387ccbc9a5d022f22b14fVirustotal results 34.92% Heodo
2022-01-1499737_3487202.xlsmxlsm dd6f67bc6417791f565e1ddd1c550b3888a6673f3bc8d689ba259d955f373430n/a 
2022-01-14O2532178.xlsmxlsm 684179a59ccb9a4240a2cb91d8dcc96b15c6aa79eb8a928080a253684d3c2b2cn/a Heodo
2022-01-1442553_01.xlsmxlsm f36635fc524dee008c90bd6556c998119d281be4995e4a5fd140a69fbbfea36dn/aHeodo
2022-01-14geTj-04469005.xlsmxlsm 127c23bfe45f05520e25aa2ee365653314949ad5bf52a5961e3b97b42ee942a4n/aHeodo
2022-01-14XBME-0389319.xlsmxlsm 4ae00681a3df217ac3d3dc4f3e7b9a154540d3047f51504700e9f6d937e6a29dn/a Heodo
2022-01-14022103704_3460.xlsmxlsm 59086ed504ab67e10241f8d1fca57b0453dc224ce6e26ad4a20dc5ebafc7ab1an/a Heodo
2022-01-1494303102217630.xlsmxlsm 5f371bba772204823b8a090dd95b8561926c57c6555fcfbad90d2ab65718ff71n/a Heodo
2022-01-14118087760_2286622.xlsmxlsm 4388bfb3d3bd1ca9b1fc3350e1a4b12fa5eb80e25003b4cf503e7613279e4aceVirustotal results 30.16% Heodo
2022-01-140778ZKZNO-934003.xlsmxlsm 2a27ce2154d11dc966ffa667153ed128ea0b55eafd8cdd00ec37a4068ea6f5ebn/a
2022-01-140258730-29769215.xlsmxlsm c9feccd9b996b892cfe1cfa32f74f502708b32467b55c9a63aaf41601afc9c60n/a Heodo
2022-01-14go_37597177.xlsmxlsm 2cb32cce5af951f826a1a62921237a45f2734472193d1e7ef2285c566b44dc3bn/a Heodo
2022-01-143710_64.xlsmxlsm 033b712fd7d4d23cef910bf6ad4440c6e7c3d79f483b9d79ee72db130881a05bn/a 
2022-01-14TKS-17926233.xlsmxlsm 93797babbd39191ec7414750b549df061089d4b224c2465baa56820ed3583b66n/a Heodo
2022-01-1413219_618.xlsmxlsm fdb92c93fc55216d88ecb346e4b600385fb8cc3ee2aa598cef3cad99b3f59fb3n/a Heodo
2022-01-14X-742.xlsmxlsm a89097e556d8e582deba3d9f6c471d585cd8ea41cf7e40480f967985ed90e60dn/a 
2022-01-14066678.xlsmxlsm 046d5f85d492903e52b9161d9454a1b6a18f3980482650fff9a9b2ba7086c1c0n/a Heodo
2022-01-1421466619236.xlsmxlsm 992922c0dd74c7f68096c93f4df4d4fb642f1503e40b7b20eef156edebe70839n/aHeodo
2022-01-14DDB_0610512.xlsmxlsm 0f8d62c5f619b683052114b161c3e501f259484f9764cd3cceb95b92ba693bden/a 
2022-01-14845-08936.xlsmxlsm 19da7acace7648f617cc949600d423f00148861c9f82b7eaf35c2487033bd905n/a 
2022-01-1435689093899607.xlsmxlsm 30dfa07c13e151844f5a9f78152c5d608e0366c112205ddafe7c0b6c563e1637n/a Heodo
2022-01-14c-08214697.xlsmxlsm 847253949bd47c472e5b7069cc2796f991b745d88707a73b376c386ddf992063n/a 
2022-01-149537005211.xlsmxlsm a49399789b01cd98a86c1e039af45a87a2c9ec07d14956bb189152912239bc4cn/a 
2022-01-14OFZ-241.xlsmxlsm b6c55ef012f46dfd98a649f91717f625896cef17f6c0370e87e591455869bf07n/a Heodo
2022-01-14P-98215902.xlsmxlsm 450c4c636faac74ffc97bf931aec060b6fa4e3a1ad9e886c26eff92f991019bcn/a Heodo
2022-01-14O_26245.xlsmxlsm 0e2db8bad325d450826ee98740532c44b36d70a95f31178c85a50f4e8ee9c8b0n/a Heodo
2022-01-14RVXKV_50838295.xlsmxlsm 3f01a59cd2c4cf701b22464a7fd495b33a2ffd5f2c631ed6bbf0e2766cf73d88n/a 
2022-01-14395_54164.xlsmxlsm 77f9047608db228251671697e703de19448819776d18446a1c5cbae840087e02Virustotal results 25.81% 
2022-01-14AZ_551.xlsmxlsm 5388d17d28ba671fbe8a27779a4ff0a97c15a00c1a91e946824b81b38c6d8e90n/a Heodo
2022-01-1489883264329.xlsmxlsm 620279fcd1238b22b28ff6e4d98f577b33d7dcfe09e7729f6ffd76070cec42e8n/a Heodo
2022-01-14073002_948.xlsmxlsm 7aa44c0791b35f633ef18c39ea504a2ff2b50ab64ed914a7827846f28fff5decn/a Heodo
2022-01-14PDC_093477.xlsmxlsm 6de1b20d93771763cb7ad66c40ee46a585ce85885919aad6e3b2a4fd9e342e08n/a Heodo
2022-01-14903FQPU-48524234.xlsmxlsm 9914b76a0ba3fb9da5a56e91338779ce902665c925d401d929aadf7974293d79n/a Heodo
2022-01-14WW_17304.xlsmxlsm 700465c4be1e671b009e46928a0479f311b16f05004d4e24755bb22c405781f1n/a Heodo
2022-01-13859791105355.xlsmxlsm 731ec98a6308e19709812083b3dfba8b079aa48f36b486f2f06d7170de5d1541n/a Heodo
2022-01-13qgczn_8849977.xlsmxlsm 88422e6f6a8baaf355add1168faec3c2cf520438933d982dcff40a31f2468a09n/a 
2022-01-13576BMSVQRQQT-8386.xlsmxlsm 7e9d46cddda81be61354089d761d2fd16244b505d6aed655e1fc0a44203cb37bVirustotal results 24.19% Heodo
2022-01-1358614633691.xlsmxlsm 17f3a4a5b8ba1daf0deed46f749b2df4846ff01f6abab21597fa0791667f9387n/a 
2022-01-1302677-731.xlsmxlsm bade694a72c3d8e5887ae4e1f1554aa85add86c8748b60af2e53e4241570d8f7n/a 
2022-01-135074287.xlsmxlsm 6e346a952b92ea8d7ecde685f07f01806f0d66530eb588748cfdf35aa4467797n/a 
2022-01-1330686401073469158.xlsmxlsm 929400abfc42d038419315b35d0fd68f85270fee48b20985276ff79651f09264n/a Heodo
2022-01-1335268QEKCPI_9518780.xlsmxlsm ecf91431dd232099783efaccf118d076e4116f577bd121646ecfdb2e66cef7efn/a Heodo
2022-01-13T_036641.xlsmxlsm 48c3c2d26bd19b1dc2eb3c36a851b00ef5cd2db217ae6bd0d89cc11c8a1a8513Virustotal results 27.59% 
2022-01-1343ELUQPF8.xlsmxlsm e894314815096ab9fbaa2b7f084fbe70f1de47caf8d5f282e012a8095831da67n/a 
2022-01-13vdxfgs_7847.xlsmxlsm 0282a5f27aea18bebe2c3a6406c3145994755a9f37ec1e941ea0dcc1f6978550Virustotal results 33.33% Heodo
2022-01-137917092998844.xlsmxlsm accddc7c06e08cf3517f7277a5c299c85176cd7821220fcbc6681c3dfba5be01Virustotal results 30.16% Heodo
2022-01-13C_769458.xlsmxlsm a58fa75e6f2b26544b017856c6e1c56cb39d7769f3854c1cebdebdc0bcdbee9eVirustotal results 30.65% Heodo
2022-01-139201519_1112732.xlsmxlsm a139884d68aacbe19a1b68501de5392ef5ba05cc3eb5a5b2ed0c347db44af4can/a 
2022-01-13JZ_79760156.xlsmxlsm 84367a10ef0a1067456f443303350ecc02e59f1a99aea05fd6c748000092a797n/a 
2022-01-13GH_852.xlsmxlsm d652c467b10eb9cec0d36d73accbe00a2d4704678683e8ab611e8de487e34cf2n/a 
2022-01-1315790-7945991.xlsmxlsm e8582d91a7c35b946a184125231a598380cf9c149e2e754acad290a1e129ad03n/a 
2022-01-13G441107.xlsmxlsm da2a461e20d4c87bd5324dad79a728e4223d6b8b70ec892fce58fdec3ca86af6n/a Heodo
2022-01-13UPW-962754.xlsmxlsm 22a61ad6c9715296ffe0d288650cadff57697c93c047bb60ee8feb45820cac07Virustotal results 32.79% 
2022-01-13POVX_9047858.xlsmxlsm 02c231df7918633f4f17172591cdcc703ff87c55aba48942d561e09e91cbf96dn/a Heodo
2022-01-1316043838BOHCGOWCET_2401.xlsmxlsm eda2e0f86dc8a29ae0f9c8b2e7a0905b0f57b9195b807e87f72e8595c31d9b64n/a