URLhaus Database

You are currently viewing the URLhaus database entry for http://hbaa.law/wp/SM42099/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1983502
URL: http://hbaa.law/wp/SM42099/?i=1
URL Status:Offline
Host: hbaa.law
Date added:2022-01-17 11:24:04 UTC
Last online:2022-02-10 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2022-01-17 11:25:08 UTC to abuse{at}ovh[dot]net)
Takedown time:24 days, 6 hours, 44 minutes Bad (down since 2022-02-10 18:09:59 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-02XFK_701764.xlsmxlsm 5951f2e9692548b9221f83d17d2495b963300952539c88355ebb9a7357076104Virustotal results 47.62% Heodo
2022-01-17668272382.xlsmxlsm 50cbe9118f2f994c659e087e8bcc79c4335a7b77644e2e55086ae9ef303abeabn/a Heodo
2022-01-1780569_5.xlsmxlsm 0f2531f6017dbdb8385b0b2243e836b999b88b204074a6d3fb2a59a92e7c9791Virustotal results 23.81% Heodo
2022-01-17HP201.xlsmxlsm bb129e52a34554610dab76d4c4ca56c04d62af6df6db2663fe68e8367805250en/a Heodo
2022-01-17jkx_9.xlsmxlsm 8950d1ad9e167268737a0496f61a0ce8e1243b09f5f6a5fe06ee04f7b5b89e1dn/a Heodo
2022-01-1763_92.xlsmxlsm 3a8f3b99f34a569a677b366f37af5485668d556b85970cf76c6d0fb009b5b6b4n/a Heodo
2022-01-17459353XUAYFJO_0409067.xlsmxlsm 39875d1bd13a9725e4927c66b9446dfeaf91baa724b1a3ab6cffd030d63fcdb8n/a Heodo
2022-01-17IBOW_65389.xlsmxlsm 190219458719434f62500232bdaff2d64739f2794b857b90f740e4b4acc9199bn/a Heodo
2022-01-1701401792_4.xlsmxlsm 562ddc0012e73ed85326fa4e511d9d25b03fd9d6767e8dcc1b84df292dfff604n/a Heodo
2022-01-17EOEIJ-948707.xlsmxlsm 6bee685b8b324236eb8b115a9e45415d17156584fd6a5766b216655909a50f02n/a Heodo
2022-01-1758-31.xlsmxlsm 16298042b5073b61f8937b60ccb4efc10b28e4e0b2043383d0e07ff7d302ba7dn/a Heodo
2022-01-17tdtw_75995.xlsmxlsm 9fd076e3d8214023a2c4dd24dae3611c7d260f41db72dbf5eca2d37dc6cd25efVirustotal results 22.22% Heodo
2022-01-17974130-395.xlsmxlsm 509adf48f1d34c9f19758904a9ed30240a16ef34f64ea4e6ad4b28b9284c4fc5n/a Heodo
2022-01-17FTYB_672430.xlsmxlsm c2e540d9d68762dd0d6b0e5fb6b71d8f01ed205e4b041a36edf232000bbd7093n/a Heodo
2022-01-17BAQ-563.xlsmxlsm 130a3440d27d5f57af151858f121b978fc0c8e09b553ab84b9ca65a3a891187bn/a Heodo
2022-01-17xHSG-7712.xlsmxlsm 6c7d0b65c32f54ee602ebbdb96d1112f99348bc1af781977328d531431c36b24n/a Heodo
2022-01-17087657-65329.xlsmxlsm 34a1b0b5d38a036c45fa73926dedfaff07606db3a238014cc94e799c8ec6bbfen/a Heodo
2022-01-17CR_770363.xlsmxlsm fc7606f8432f0726d5994b3cc3851d1fd0fdd15a9a376d66cf8d22d885fca2can/a Heodo
2022-01-17W8272.xlsmxlsm 94da71270fde1ac82e4f19eec9b474540390cc1866f491b7eb6cedea4ae1fa6dn/a Heodo
2022-01-1712232-79376.xlsmxlsm 532f03e76c61427a70bb8770f709a22d964a7a5bcbd7fe4ee417747f14987761n/a Heodo
2022-01-17cq_569379.xlsmxlsm 25d793cd75aaef43bbc1856a93ab45be96fb42063a96ed3a5bb6332c826345fen/a Heodo
2022-01-17104306_9.xlsmxlsm fbcbe1e47f074b616977ffe5aa2c083b39be92f726319a987d016ba8941edb64n/a Heodo
2022-01-17UR8703.xlsmxlsm fee69d011e8cbfe4072a561b1b7332fc48687cc61f7277e26295843c1a3f16dan/a Heodo
2022-01-17ByiZHQ_26.xlsmxlsm a26052fa2c65c7f6dad6b24d745c9bba1a040aab34b7a72623a016fbd79189edn/a Heodo
2022-01-17zrxek_31.xlsmxlsm 8e8d1c3d3997e21e024c039b896efc13ded9351258763a0d5bb7d2fb578f87e3n/a Heodo
2022-01-17O-8109.xlsmxlsm 3cd21d1ab4cf52a40bf8e1af3d7ee588d88779d5a8a18c36a3245e413feaa465n/a Heodo
2022-01-1795101089-55073.xlsmxlsm 8d209fcf2f9009c909f1a62b0a87100c7bf3eccf9a61e853e0b1ff836bc21defn/a Heodo
2022-01-17D_05.xlsmxlsm e572dfa20efb7fe613e7c6109441e73b9627f73182a87257c82c0d91bac1c2c1n/a Heodo
2022-01-1709879-277985.xlsmxlsm baa2ed08258707eb934b19384846f3c9f8ad7c4f84c43bf18e4624a51f00d574n/a Heodo
2022-01-172491012-695.xlsmxlsm 6b06f4116937e4ac8d663228e3a0fac9a024f5cfc2356afed999f320c5ed12b6n/a Heodo
2022-01-17UQ_755031.xlsmxlsm cd10266dba86101c4ad9a523800ec7b6cf71e0be8aaf1bcdcd0645acbf6e362dn/a Heodo
2022-01-179581981311.xlsmxlsm 75a2be267f5f14510539392c72273557934123014e1c9c0cc7ece689bb5dec04n/a Heodo
2022-01-1714926.xlsmxlsm db4a998e0e404ff7a8795edb2198cca0903ec4cc2682cb2b09dcc3cdeaabcff5n/a Heodo
2022-01-1759ZVBX_6048262.xlsmxlsm d57b0cb918fe26017b8a6d794c032b45e84a94cb0313742457e81e8fba677a0fn/a Heodo
2022-01-1727AVOHIZY_404.xlsmxlsm 2449eb351e345e1aa06b6dc0acf4f2eb4ccc8961568ad46cc5f188d0b990b685n/a Heodo
2022-01-17O_8817014.xlsmxlsm c21c42734fc745a132026c1c45e006a4ce12072ba6d0fadedacfbd260c700694n/a Heodo
2022-01-178975497694.xlsmxlsm e7d07654ab4ed593855719a626ba94157b4a165dfed49672565111d4dc20c397n/a Heodo