URLhaus Database

You are currently viewing the URLhaus database entry for https://demo.nhabe360.com/3/oacaiw_680152/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1974876
URL: https://demo.nhabe360.com/3/oacaiw_680152/?i=1
URL Status:Offline
Host: demo.nhabe360.com
Date added:2022-01-13 20:46:05 UTC
Last online:2022-06-20 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2022-01-13 20:47:09 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:5 months, 7 days, 16 hours, 55 minutes Bad (down since 2022-06-20 13:43:08 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-14DQYXE_889110784.xlsmxlsm 88309150746b21b8bf021aead74ef1695d5008b340897b2a84f0a254ddfcc7f8Virustotal results 26.98% Heodo
2022-01-14vqgyt80143.xlsmxlsm 28d2e274a082c7de870cd52bde0f9bb929bcb9331d7ce9e85f5c9bb6948a59dbn/a 
2022-01-14ZQJ-1.xlsmxlsm 3dd7791745ef386d30fdac27e392533cbf154de6881440bf6bae3b947c775402n/a Heodo
2022-01-147681396PKOXIKCQ509437.xlsmxlsm 4eab3977f88e6444a99925c2a5769e6b720e8a6ba4ee8cc8235e23a33a1e6658n/a 
2022-01-1423864585-32044416.xlsmxlsm 948bece3441056d04af338e263063315d45921d28cf536276011fab5b2127a00n/a Heodo
2022-01-13XOTN97069.xlsmxlsm 731ec98a6308e19709812083b3dfba8b079aa48f36b486f2f06d7170de5d1541Virustotal results 22.58% Heodo
2022-01-1341121_8419280.xlsmxlsm e15f4ab1af0935e26f54b19c1221a5dd41698713dfa44c327a206ffd708f3ceen/a Heodo
2022-01-13008823_729.xlsmxlsm 7e9d46cddda81be61354089d761d2fd16244b505d6aed655e1fc0a44203cb37bn/a Heodo
2022-01-13X493289.xlsmxlsm 17f3a4a5b8ba1daf0deed46f749b2df4846ff01f6abab21597fa0791667f9387n/a 
2022-01-130816_99.xlsmxlsm cfcf60f2a598ac8e1abc547928fb7b32fa3b58afb00c098f3b6b34b77d0ffbb9n/a Heodo
2022-01-132556670ZUHCJYSN-843580.xlsmxlsm 581fc75adefc48a9698d1bc72dce3048ee18acc2a34ef3af5c72a1f83c1761b0Virustotal results 22.58% Heodo
2022-01-137917249771402.xlsmxlsm 88876b87c1e34620663cc95177326339d7853e695ff37d35a180f61d76d019ben/a 
2022-01-13OKPMC_6948.xlsmxlsm 80f732153350e276a2b676506c38904e02387501bbd7946340ee90858bcc5f79Virustotal results 22.58% Heodo
2022-01-13x-4.xlsmxlsm 00c4657fa8734227eb769bbed474082f1140185ab579073204135735b2c32f9cn/a