URLhaus Database

You are currently viewing the URLhaus database entry for http://onafrica.tech/xh4z1v5/fTiDET-64055800/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1975244
URL: http://onafrica.tech/xh4z1v5/fTiDET-64055800/?i=1
URL Status:Offline
Host: onafrica.tech
Date added:2022-01-13 23:37:05 UTC
Last online:2022-01-16 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2022-01-13 23:38:07 UTC to abuse{at}a2hosting[dot]com)
Takedown time:2 days, 0 hours, 58 minutes Poor (down since 2022-01-16 00:37:00 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-14DOJVU_69951.xlsmxlsm 4021910c4fd276115da6d82a9097ceb404e3fc4e90bdf5e6fce31b4adb945d13Virustotal results 36.07% Heodo
2022-01-14qc794.xlsmxlsm c7f2afe51337a22d7458aad225f6c867436b3c51c0897ddd6815294d8731353aVirustotal results 37.70% Heodo
2022-01-14PH0515.xlsmxlsm 2c1629903649cbcf3b885c468c648e7b9caad9bce1bad13edf832b78d8e98d96n/aHeodo
2022-01-14245097079402.xlsmxlsm d2569a5701a8fc23468530b950ed661832ef6d909e2a1a921da07a879135f612n/a Heodo
2022-01-14JWD-512.xlsmxlsm cf04f9d9d12315b27f3fc16c12ca6860a84b391e604598b91b704eaabcca52d7Virustotal results 33.87% Heodo
2022-01-147931718055.xlsmxlsm 46b8a68b043ea9ede033a603ef771e24c4e2255070731c00b909c41607b2bdf3Virustotal results 34.92% Heodo
2022-01-14bud_237537.xlsmxlsm 1f9d9fca72abbfae3dc8f70790c4d8ee3916adc5c68ab73c3d2cdd1fa38198b4n/a Heodo
2022-01-1429723-78.xlsmxlsm a51724da5a2c220ccb551df3d43ba4004b8231ff7848bc4058daf8477c56f75en/a Heodo
2022-01-14EE-56354.xlsmxlsm 2819520aee64e6800af25eca5fa2aa0bc926fc6dd13200b425c0a686d95db027n/a Heodo
2022-01-14GTKA_02.xlsmxlsm 013f28c036fa5af595b6c61d98cb6dc88cb8045194ef50facb59d481041c23cdn/a Heodo
2022-01-14VVSRM_684410.xlsmxlsm 21279987ba4135e6afcbc5527f9c26b7d4e3aec26aa1e1863d2e144edd7f7730n/a Heodo
2022-01-14FHOtf-135.xlsmxlsm d88d83fc565c556b4332a98efdf1c1eb765b0526e632d40c50f8f0bc75d30857n/a Heodo
2022-01-14vhbhe74769.xlsmxlsm a5a72434f5357b664856b5ce941ab93a74e2a5e9765cd65139c74b8d0c6c999cVirustotal results 33.87% Heodo
2022-01-14RNLD-11.xlsmxlsm 87a33eb014251fbd3e80d9dce2bf789e0c1b579d59554f4efbdd3f6d78a6e57fn/a Heodo
2022-01-1483441435211.xlsmxlsm 8e5f2412f3d12b279e75f2237ca109db4bcf1196f89e12bf331a48f4b7850668n/a Heodo
2022-01-146416EHCHCFOOQV3191.xlsmxlsm c822efa6c4fed299c0bd7794b8f9a4e193703f2d22f78a795dbebc4748dbd4b1n/a 
2022-01-14gezJR_93720.xlsmxlsm 01e7bf755c02b2a01e54ba0c464ce80a6e64a404a541e9fd46ac00fd1d3b22f2Virustotal results 34.48% Heodo
2022-01-14ON69351665.xlsmxlsm 4fca1c54e08fdaa16e2a0697f33e798e9dcacde746cc035fe595bdbf1822b2f1n/a Heodo
2022-01-14BTlQ_255922173.xlsmxlsm c95f568471e97a600183f2a71c62c8c16c86552989bf03e2e1b9104282700689n/a Heodo
2022-01-14Q_098.xlsmxlsm ed0448141caba757e10c045d97e8593777ba7c60b8871b5871622b2b80ad1519n/a Heodo
2022-01-147726488WKL_7352.xlsmxlsm 0d689f583f780d0dbd3e9197bac7b961ad20c2a5d4e0df322ec0308f43eac999n/a Heodo
2022-01-14122874338128.xlsmxlsm f79292fd55509a135e97ccf4fed6dd3d4a3f363a0c0023c63bf44699a74a5767n/a Heodo
2022-01-14OY985.xlsmxlsm 76e281e4666c4a90938595d81796364bfc4521ba33fddeecae09aa8fdb0c3b93n/a 
2022-01-1470249_02.xlsmxlsm 91b698296f9258f576362d0b0eb4449692d940a43cc0a15da04204736ee3d17cn/a Heodo
2022-01-14Umxj01458.xlsmxlsm 69c12e112b530ad17135d9bfde2781898ee661501702c81ba5c27903d439623bn/a Heodo
2022-01-14AW29529139.xlsmxlsm ab5d8bf5fc5242d31fac07794a032f75a097559e76c27991d42d0afa48519db5n/a Heodo
2022-01-1439ZMDJJMDXBP706608.xlsmxlsm 63d6ae5feb2ece25c4de9930b6779f1222d705097f3c6d16c06147699adef880n/a Heodo
2022-01-14217510FBHYUKZTXC_56697194.xlsmxlsm 3e23d05ec9aa086013200c2df62ea349686f0b76b06f16992f3af4cdb0735bb4n/a Heodo
2022-01-1495157813367365.xlsmxlsm 74fe2ba2dea625d4f828ab4aa5527c83b29ae09a9a4f1c74980b998cf84f06c1Virustotal results 36.67% Heodo
2022-01-1494VCJTHHFOK-51759.xlsmxlsm 25ffc4f1a9abeb750423f929d563d90c09121eee81a928f86f02f8e4421f5c7bn/a Heodo
2022-01-1477_040052.xlsmxlsm 9770e911e79143121d645e9e5c84b8472e49263dd3ebe7f615b4051784d2ade9n/a Heodo
2022-01-14P_777.xlsmxlsm a972c47050ae7cf97f0c52155e8ab1462d5a9606eaf7140f1ee56f1e8a45dbb8n/a Heodo
2022-01-14526454_267.xlsmxlsm d75b9fb536fb81677c1647eb63af1579bc3f2e7d21a22325d4d17059d3a851ddn/a Heodo
2022-01-14bbbdmgm3153220.xlsmxlsm 21765812bfbbb2dd7f212135f049e46468f8e4918a096a20ffb4f4048f77a49en/a Heodo
2022-01-1449009-34362.xlsmxlsm 8241a915f1a80d0c6898233cdfef1c73d4e00a2b17c41b4bf84984d9b4234f46n/a Heodo
2022-01-147576-4456.xlsmxlsm 5cc2efe07bce9271f507e31985055a3f5a845b6269dcb80cc44de065b1f093cdVirustotal results 34.92% 
2022-01-1423-048193719.xlsmxlsm 1c8efbc70bde55f70789960968bfdb1a261eab6bc372e1f6859aee00261a7f82n/a 
2022-01-14GKP_90317.xlsmxlsm 7ae8d061dd1dd74a37ac33eced5d361e376cc4b919bdfd82338595f8e17d1e46n/a Heodo
2022-01-14jhhzj_50.xlsmxlsm e96a3f5577ef1f2045def7dac6923247f9ea4baf84301b8425761d362301bd83Virustotal results 35.48% Heodo
2022-01-148486_46.xlsmxlsm 77c84a4f67f70d068261158ddf09d5e98292a7d86397fb95dec8f0092a67d25fn/a Heodo
2022-01-1497469062.xlsmxlsm 679a703b419763bfb1ec0a81bcfbb679e4db76684a957e2942c64f8446d0a1adn/a Heodo
2022-01-1430108209_2222351.xlsmxlsm 0e9ecd9a72922bccbcb8e10f539cb80caf27d6e4a3d3fee85db032623821a4aen/a Heodo
2022-01-148695021_2792.xlsmxlsm 4ae00681a3df217ac3d3dc4f3e7b9a154540d3047f51504700e9f6d937e6a29dn/a Heodo
2022-01-1499027645_928377.xlsmxlsm 2bddcf7091fe815708701ec5e688ab154d2d422c7bb736a50dec1ad373b77d8cn/a Heodo
2022-01-14Y113.xlsmxlsm 2e1bb3122c60fb3a905e69cc01ba10588cf13ce9c563048fb404b14ed1f3d7d4Virustotal results 30.16% Heodo
2022-01-14539514937.xlsmxlsm efe6738d4ba36185f68784a158eaafecfa97f2a854ae278b8d193f6edc65ed2fVirustotal results 31.15% 
2022-01-14msille-1660882.xlsmxlsm 8930ee76733f7d47386802541a1c011bacf01d3a97b98801b53dc4906502f824Virustotal results 32.26% Heodo
2022-01-14YL-8.xlsmxlsm 6f172f29fad74cb96e7bfa67cff818457f78054d98f4fe83a8147104da2b7a17n/a Heodo
2022-01-14378617189_9340144.xlsmxlsm d2248407231158d69f414895bb9f2abc24b31d39c156c0f46e25a49fc0f6942bVirustotal results 28.57% Heodo
2022-01-142751-7276977.xlsmxlsm a45f772b66ff40e7de3bb7541d5563fc62563fb2aa9ab6b9343e4ab859593c7en/a 
2022-01-14I-5186985.xlsmxlsm 93797babbd39191ec7414750b549df061089d4b224c2465baa56820ed3583b66n/a Heodo
2022-01-14E_273650.xlsmxlsm 0766c61d5d861dd6db71ee8f535e5f405f9d7ae80dfc5c83938e000d2b4ba58an/a Heodo
2022-01-14CDA_4862454.xlsmxlsm d8fd315efba4dd6e72aaf30eb91ac6bbdc046717708c740158751ebf6a9e18d4n/a Heodo
2022-01-1499_23.xlsmxlsm 38b84fcdf7e7ed1a95a221a66ebb59bf63847b414da3370144e103a23b9a577an/a Heodo
2022-01-14LrDdI-2094.xlsmxlsm bd84338df7f1e8eae032de81e2839eb85a6f05c8e7f3afb88bade961419a9d49n/a 
2022-01-149669_0576099.xlsmxlsm ff585f534b9fcb8f660da3a92bdf92629e9d66cc31aceff6d3cf69be3aa2da60Virustotal results 29.03% 
2022-01-1440-58744.xlsmxlsm be9b720458252f06a6688c838079c24730523961b9242c3a0c76ef5c4c1ac949Virustotal results 26.98% Heodo
2022-01-14zXB_67649.xlsmxlsm ec237a7588cb70688e3f57edf9ec59126b234f51b996b68000604002a379dc5dVirustotal results 27.87%Heodo
2022-01-14VU_0628.xlsmxlsm 59ae2ce51e3e9e2d3e412dcf23488aa002acb72d34656606872d00bb4ab0eca3n/a 
2022-01-1464164_5825.xlsmxlsm 878245ca533c239b7066ce1bb483d8cd42a8d5887954c3e4db00b5a52d46f354n/a 
2022-01-1497354_7410.xlsmxlsm 3b63ba5e81eedd06656eca70b56b6d9490b598df1646dd83dacefe8cd52d6a77Virustotal results 23.81%Heodo
2022-01-14DYK_0747.xlsmxlsm cb0d9916b6be6d3b9d52d057b5b8aa3b223284abe331467dea72eca27165a618n/a Heodo
2022-01-14R_4819977.xlsmxlsm 0e2db8bad325d450826ee98740532c44b36d70a95f31178c85a50f4e8ee9c8b0n/a Heodo
2022-01-143967914JBKJHH_9220375.xlsmxlsm d7e424ccc4f316f9abbabc2a3b0bc47b61daf071111fed745056ffc823c541c1n/a Heodo
2022-01-14q239.xlsmxlsm 77f9047608db228251671697e703de19448819776d18446a1c5cbae840087e02Virustotal results 25.81% 
2022-01-14971037516_44.xlsmxlsm a0a8993ac49af8c9a67d95350e800f6adfbc38b6bfc5a7c213eca23b0b9e5857Virustotal results 25.45% 
2022-01-14304335639-7429974.xlsmxlsm 736d7dd8f6451b13696e026b82b6c6821497e1dcd096917e9c29c67209989d43n/a Heodo
2022-01-14hQxV81312.xlsmxlsm db24f279d1e6ca28783d945c325f1a530ba117171035e72ca275e3bbc0d8bfd2n/a Heodo
2022-01-14812.xlsmxlsm c319f68747fd435aca46ca88df79a412e6e2e3fd14935007ded0525bd0666416n/a Heodo
2022-01-1488568238739293.xlsmxlsm 675e9b8ca552efccc34ac7a2f9fff8ef872d7a5cf5790aca00d33baebff47a87Virustotal results 24.19% 
2022-01-14563372RPYBBQJUQ_8646400.xlsmxlsm 81bb7a133cc21a5f209bb293819b5157ff69fb246fd652a40caea0a5d98d90c3n/a Heodo
2022-01-13ZES_710245.xlsmxlsm 7266de84fe056156bcbd7e4c2f334c2a15e63599edbb0734bf0684a3a0c2e284n/a Heodo
2022-01-13pgfB-756.xlsmxlsm 41c387caad91677f20b6feddc3ce80cf855fad1ae7fbf716f5d1aabc68eedce9n/a