URLhaus Database

You are currently viewing the URLhaus database entry for http://poilbartalivetv.xyz/wp-content/BUGZ504/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1974720
URL: http://poilbartalivetv.xyz/wp-content/BUGZ504/?i=1
URL Status:Offline
Host: poilbartalivetv.xyz
Date added:2022-01-13 19:27:19 UTC
Last online:2022-01-17 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2022-01-17 08:19:06 UTC to abuse{at}cogentco[dot]com)
Takedown time:3 days, 17 hours, 17 minutes Bad (down since 2022-01-17 12:45:26 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-14eta_734.xlsmxlsm 21961b0d16c7d2561ef0c3d8a055eee86e90688f4a6fbe27c7f64c61096d0aecn/a Heodo
2022-01-14RM_12895344.xlsmxlsm 891fb03e7a6757fa9641ac54134071ebda5f54c377cc9105a996d366f66628a6n/a 
2022-01-14954829BYESFEFLKX-65028463.xlsmxlsm 8ac60a4dd90aa35456bca26f504442bf3464e6931317017199138907cf34f7bdn/a 
2022-01-14M_087115373.xlsmxlsm 45d0ff33414f7e28bd4bf48ec71ad16080126ebdf84d54e9c5b90ac9510eb5c7n/a Heodo
2022-01-14GG7050120.xlsmxlsm 41170eea358fd62c2b91fcc29d05724b8536d8691c295a7c7f16d12104946f97n/a Heodo
2022-01-14YU_726044.xlsmxlsm 514cea821d5d4c28b8a3a56cde53d806dc7ef8637ff6f5cec8ee936c75f16c07n/a 
2022-01-146064236_686.xlsmxlsm ea5179148ac7b6d4de608eb71ad65c3ba410acb6a3d3f8e28186c61c94d29c0cn/a 
2022-01-14yKLD2.xlsmxlsm 754727f1351a9c17908d09e7425e5643319d698c7d35b450155d1750fc243a5an/a Heodo
2022-01-1426488_9260.xlsmxlsm 0e99e67675ab5402fbf03f532b3a517e7190fe2fc668fa2e8e85cef8dc68bd05n/a Heodo
2022-01-14209195_397028841.xlsmxlsm af9dce730d67705a0ac57abc612dfe0539383a38c746f3f8755aef310e1d3334n/a Heodo
2022-01-14318LBPDVYMHGK_4179182.xlsmxlsm 8a1759da5cf30cda277162bcabe0a579ee44c76e90293cad589f0d6f1e36310bn/a 
2022-01-1485137613RNFEF_146617.xlsmxlsm ab5d8bf5fc5242d31fac07794a032f75a097559e76c27991d42d0afa48519db5n/a Heodo
2022-01-14Q_81790.xlsmxlsm 689555499fd2dff9a85acca987cf63ecb004150fb9428e7336b11a90eed8a4a6Virustotal results 33.33% 
2022-01-14Q04879024.xlsmxlsm 63d6ae5feb2ece25c4de9930b6779f1222d705097f3c6d16c06147699adef880n/a Heodo
2022-01-14RIPE52.xlsmxlsm dac736a5562b2a96cece573228b50c17f369d3912fef2b92dc5ea40d5c427034n/a Heodo
2022-01-14EVEK-5554481.xlsmxlsm 01e14e3c803705655e2068d80e77f2e2103118f38fa43791e069273b46c8cc0dVirustotal results 34.43% Heodo
2022-01-148624954_6.xlsmxlsm 91937b58d9ec22774d2b500998864b2929fca1cfe5ded24b2db292ed81b6471dVirustotal results 31.75% Heodo
2022-01-14FQS677951280.xlsmxlsm 6d309b2f00848aad2b4bb6ebe146e8bdc4dddb271c9ce170a5946cef29ccbe41n/a Heodo
2022-01-14AL125.xlsmxlsm a972c47050ae7cf97f0c52155e8ab1462d5a9606eaf7140f1ee56f1e8a45dbb8n/a Heodo
2022-01-14ryavwa-49295.xlsmxlsm d75b9fb536fb81677c1647eb63af1579bc3f2e7d21a22325d4d17059d3a851ddn/a Heodo
2022-01-14wobyz_69.xlsmxlsm 1f33cccbde25d58a817b0b6355084b8d0694bb104019808808694c2e6bbe2fbbVirustotal results 36.07% Heodo
2022-01-14LNHPX0562.xlsmxlsm 8241a915f1a80d0c6898233cdfef1c73d4e00a2b17c41b4bf84984d9b4234f46Virustotal results 30.51% Heodo
2022-01-144907PFKWKQYK169.xlsmxlsm e1f0eb778a09fec529aa7aff9d665828b18007c8e52d62565a552f606c04442fn/a Heodo
2022-01-14301969-5.xlsmxlsm e666db29cafcd8ca53bf39e302e59b22b962a623ce08bea482188b4b198b059eVirustotal results 33.33% 
2022-01-1465_37.xlsmxlsm 1c8efbc70bde55f70789960968bfdb1a261eab6bc372e1f6859aee00261a7f82n/a 
2022-01-149045267YMJ-4266424.xlsmxlsm 7ae8d061dd1dd74a37ac33eced5d361e376cc4b919bdfd82338595f8e17d1e46Virustotal results 33.87% Heodo
2022-01-1432293837-792351.xlsmxlsm e96a3f5577ef1f2045def7dac6923247f9ea4baf84301b8425761d362301bd83Virustotal results 35.48% Heodo
2022-01-1493502FDUHJW_08.xlsmxlsm 141cd6be868c4fa899a6d5f3f2f0ea22d94887abe2e2a3246efb2908d25031ban/a Heodo
2022-01-14PFTZ_508678.xlsmxlsm 9cd906e8e1ade72180999a159418a5afbfe2cebb2cbcabf9e53352b1101e8e99n/a 
2022-01-1481169899494075.xlsmxlsm 0e9ecd9a72922bccbcb8e10f539cb80caf27d6e4a3d3fee85db032623821a4aen/a Heodo
2022-01-149471_3094.xlsmxlsm 4ae00681a3df217ac3d3dc4f3e7b9a154540d3047f51504700e9f6d937e6a29dn/a Heodo
2022-01-1458134250078589.xlsmxlsm e528e3738d4b8284c74b4e98c0cd720a9656a76170631018efa083afe6775b20n/a 
2022-01-14798-0.xlsmxlsm 3e81aeff6c3de374e2eccaf42502eb484fd572d9cfd1b165fb2d05169913a6e5n/a Heodo
2022-01-14400377-11225208.xlsmxlsm efe6738d4ba36185f68784a158eaafecfa97f2a854ae278b8d193f6edc65ed2fVirustotal results 31.15% 
2022-01-14MW-1056909.xlsmxlsm 8930ee76733f7d47386802541a1c011bacf01d3a97b98801b53dc4906502f824Virustotal results 32.26% Heodo
2022-01-14fe8002.xlsmxlsm 31880b7b69938b12824c65ef7240304c054a61f2c4e62b7f596cafbad8b63eben/a Heodo
2022-01-144389_12065131.xlsmxlsm 42c5bb56d6d7939abf3f29c32648b0239c79d8362d5b7634e96c8387b4376831Virustotal results 28.57% Heodo
2022-01-142747_477704200.xlsmxlsm 033b712fd7d4d23cef910bf6ad4440c6e7c3d79f483b9d79ee72db130881a05bn/a 
2022-01-14y_27.xlsmxlsm 93797babbd39191ec7414750b549df061089d4b224c2465baa56820ed3583b66n/a Heodo
2022-01-14NVCTM_64209.xlsmxlsm 722d4a00f62f11f3e669d18aa37360f9fc04792b7d8b9c150c4adfd9f9e10e92n/a Heodo
2022-01-1494LURGVSNFJI-63960247.xlsmxlsm d8fd315efba4dd6e72aaf30eb91ac6bbdc046717708c740158751ebf6a9e18d4n/a Heodo
2022-01-1436948196027462203.xlsmxlsm 38b84fcdf7e7ed1a95a221a66ebb59bf63847b414da3370144e103a23b9a577an/a Heodo
2022-01-1422234_78.xlsmxlsm 992922c0dd74c7f68096c93f4df4d4fb642f1503e40b7b20eef156edebe70839n/aHeodo
2022-01-14T_73225.xlsmxlsm ff585f534b9fcb8f660da3a92bdf92629e9d66cc31aceff6d3cf69be3aa2da60Virustotal results 26.98% 
2022-01-14B_6369.xlsmxlsm c38669a80f2dce6bbc2dbfc67e98ecead22379ea9733a7e496c8cc6896d61d11n/a Heodo
2022-01-14U-5210.xlsmxlsm 28d1e4658a5855c9dd40f51712aa35a428f2a49c8ae9c5c29232226e521b4a86n/a Heodo
2022-01-14E_39798.xlsmxlsm 59ae2ce51e3e9e2d3e412dcf23488aa002acb72d34656606872d00bb4ab0eca3Virustotal results 26.98% 
2022-01-146079247_18814.xlsmxlsm 878245ca533c239b7066ce1bb483d8cd42a8d5887954c3e4db00b5a52d46f354Virustotal results 26.98% 
2022-01-14166EQIWI-368.xlsmxlsm 296171d1b92b175041ee3829e60a6880b93861ef09614e912d112777fc2fe13aVirustotal results 26.98% Heodo
2022-01-14ptzff722.xlsmxlsm cb0d9916b6be6d3b9d52d057b5b8aa3b223284abe331467dea72eca27165a618Virustotal results 26.98% Heodo
2022-01-144970472_2256.xlsmxlsm 0e2db8bad325d450826ee98740532c44b36d70a95f31178c85a50f4e8ee9c8b0n/a Heodo
2022-01-14306531700_4120.xlsmxlsm d7e424ccc4f316f9abbabc2a3b0bc47b61daf071111fed745056ffc823c541c1n/a Heodo
2022-01-1470089_79667.xlsmxlsm 77f9047608db228251671697e703de19448819776d18446a1c5cbae840087e02Virustotal results 25.81% 
2022-01-14VOK_6743872.xlsmxlsm b258f9290e51fbb164e311ba5ed55dc99113582e4f849be35be5efcd3a6784a7Virustotal results 27.87% Heodo
2022-01-14FYTV_160593.xlsmxlsm a1a5295caf727bb6210b32ba53371db4451b4355c8bf0b420b09dc8e1182fad5Virustotal results 26.98% Heodo
2022-01-145549_4275.xlsmxlsm 9c8a39e1e2d7547aebadc4f37b84543d9e48faca443b9acd76cdf46d65459acdn/a 
2022-01-142269756SVQEKBLA-376642.xlsmxlsm 3dd7791745ef386d30fdac27e392533cbf154de6881440bf6bae3b947c775402Virustotal results 24.19% Heodo
2022-01-14mOBqP-8.xlsmxlsm 948bece3441056d04af338e263063315d45921d28cf536276011fab5b2127a00n/a Heodo
2022-01-13sqpcv-068523.xlsmxlsm fbaad03de2f185ae958c7192e2215fb6678792763d4872c4d3081d8980edc463n/a Heodo
2022-01-13rjvjmf361446041.xlsmxlsm 88422e6f6a8baaf355add1168faec3c2cf520438933d982dcff40a31f2468a09n/a 
2022-01-13640475474.xlsmxlsm 88d07eac813b81a446e976b9d46feb95a86d3e4d0cdfb6e604d42bba8757db02n/aHeodo
2022-01-13z_7511899.xlsmxlsm 792a7b8e75aa51f90c66ee711faf429dfe3220b038cc3725ee935083fcb60e0fVirustotal results 22.95% Heodo
2022-01-13DRZAV8744.xlsmxlsm bade694a72c3d8e5887ae4e1f1554aa85add86c8748b60af2e53e4241570d8f7n/a 
2022-01-13DZ_50.xlsmxlsm 6e346a952b92ea8d7ecde685f07f01806f0d66530eb588748cfdf35aa4467797Virustotal results 22.58% 
2022-01-13XNYD_3549.xlsmxlsm 8956b950352fe247497f8aa4a0738a1fd22c1e32a643a1e98ecc416229fa29f4n/a Heodo
2022-01-13BY-23.xlsmxlsm f1ec4f871b40968083790f9f1e19eaf6c17301f20743055e00b6382b3d5b2f55n/a Heodo
2022-01-13LVQS_72.xlsmxlsm f82aed370591fd8b536179975bac82d0c6c17f97b74d1dcf5c235fbfb66dad72n/a 
2022-01-13LPSRp7853.xlsmxlsm e894314815096ab9fbaa2b7f084fbe70f1de47caf8d5f282e012a8095831da67n/a 
2022-01-13263CZLUCVYRV-188475.xlsmxlsm 0282a5f27aea18bebe2c3a6406c3145994755a9f37ec1e941ea0dcc1f6978550Virustotal results 33.33% Heodo
2022-01-13C-8083011.xlsmxlsm 8b8691c729c4aae4cda2049c3fcbf3153562829da68bfd3121e61dc3f9bf2cfbn/a Heodo
2022-01-132011015_0305.xlsmxlsm 4d1068c5631ba69917214793509ea1cfb56708ec210f961c053edab3d1b610f0n/a Heodo