URLhaus Database

You are currently viewing the URLhaus database entry for http://havnet.net/email/N0OiATFOaFT2IZg1aO50LfjAV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122779
URL: http://havnet.net/email/N0OiATFOaFT2IZg1aO50LfjAV/
URL Status:Offline
Host: havnet.net
Date added:2022-03-30 16:06:04 UTC
Last online:2022-04-25 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 16:07:05 UTC to abuse{at}positive-internet[dot]com)
Takedown time:26 days, 1 hours, 21 minutes Bad (down since 2022-04-25 17:28:18 UTC)
Tags:emotet link epoch4 heodo link redir-doc xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01YBY-597489442356.xlsmxlsm b05ff21e7a696091a19661b1e82447f30e2dc4e663b94b03b42cdc022e393e19n/aHeodo
2022-04-01ZB-689694711284.xlsmxlsm 2ac3bf7095647237fe3a5bd46c3c7e85f0332e2bd3b8024452aad240a740c064n/a Heodo
2022-04-01JUJ-20040314049.xlsmxlsm b9a82fa6fb67d3ca785a7d8d842c76b3beecd65c9789af664049e029ce4e9a7aVirustotal results 45.16% Heodo
2022-04-01ET-22250769.xlsmxlsm f316a9b48040c007a792f5b99f7367b7d6996c7db03a377dd159a22db01e6546n/a Heodo
2022-04-01UEE-9616262279.xlsmxlsm 17745afc954df41d2b3f49d96ab76cf85baef03d4b9acbeefb44401a89f5b9bfn/a Heodo
2022-04-01TW-825432447.xlsmxlsm fa5f3e1ad7a0966fac2a2d091be90b6c0d70c79e258c9b19a2e93c47cd0c4818n/a Heodo
2022-04-01RJE-684462936572900.xlsmxlsm 81b6929fa5ca90e9e08f68e7aa10eeb6a557a65880ce71b3c4976a67f4e5aebcn/a Heodo
2022-04-01WB-65842731804.xlsmxlsm 1a8adefa7d083432f592ddc3797611b4e8076869a11177ebbdc1b5b6bc22982fn/a Heodo
2022-04-01GCK-665292078820433.xlsmxlsm 8c3a1df0298f1bddbc6946c5ab191ef80476cf4a3a8cefe7493c189035d2f0cbn/a Heodo
2022-04-01OOI-393706503028.xlsmxlsm 4fe9cdc6b35e9992d206f5a0bb6ebcb063618ed502e651ba2f5c014a2aea5776n/a Heodo
2022-04-01CU-430118525.xlsmxlsm b42ac7850efc6c39b4c7db61d4be9a131d78b545eaaa868dab373c45bff2fd72n/a Heodo
2022-04-01FJ-299060843790.xlsmxlsm a839223fec71c2dc5f6dfc6538ec0e92c40881a5c07c677fb2eadef197853c1cn/a Heodo
2022-04-01YZ-068527269574800.xlsmxlsm c201ae0ab0516a27d14400b4af28d4189bb2c6d8b589c4fadb025c26645f19bfVirustotal results 48.39% Heodo
2022-04-01EKL-88181811616558.xlsmxlsm e40bfb9b0a236fa78f9150e560fa82b899430dd6cf6da41388a30f8e09496ecen/a c8fc17ff030feb3383d8889f69abbb
2022-04-01US-0148001477.xlsmxlsm a7b2353e3cc7e51e65aae622e1a0f4c8ce1feb70c9a7e385cfbd056528c812a7n/a Heodo
2022-04-01TMS-00778464123818.xlsmxlsm ff29c4e7acfa113d826b2fcfcc5e8dea43a58a5db3ad37376750c95e58335050n/a Heodo
2022-04-01JY-8000571015.xlsmxlsm f44647dcfb785e6463e4203aaecc8f5d7dcbebf18418667ed31c226c92372383Virustotal results 43.55% Heodo
2022-04-01LF-420804847.xlsmxlsm feaefe1adc1f1f9a68bd8211b8c2f3c5e76ee4fcacf1d2ed3336a04de96fcfa2n/a Heodo
2022-04-01WJV-144862759239.xlsmxlsm 55af29e8285944f573d931d856bd099dac92ab1868000f8346d13a0bce7f1e3dn/a Heodo
2022-03-31PSV-702113826.xlsmxlsm 7093cef5fa36d3a3226ede66e633684706991f11f806fdad017d28a40684cc76n/a Heodo
2022-03-31VH-5224845723213.xlsmxlsm 525f6667c0439d7c21905eb0aec33c64c4b4ee34d0f3896f67f5140927b44d90n/a Heodo
2022-03-31ZK-1563118.xlsmxlsm 65d9f4ae7d90232314fd04917e53e9f4e2a214ec3670daad35bd2f51fe9a45d7n/a Heodo
2022-03-31UXZ-47648655185.xlsmxlsm 73a1d60faa31200f09f2567671137d6b5f9be02a97eec33fc20971d151d5c8f1n/a Heodo
2022-03-31WMK-25264759244796.xlsmxlsm a395d2ca627270c1b53481050d39c6395c778682e98aeedcb00d1f68fd1ec23fn/a Heodo
2022-03-31II-71700977846.xlsmxlsm 99bacd00ff714e00339dc64c1418b2c0c26ca69120e34bd32ba8e73d2044cd9cVirustotal results 40.00% Heodo
2022-03-31FE-024785250747008.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31ZL-156989349878.xlsmxlsm 48f3f48c930933448b555efe67aa364e098504f2273ec2a4792803cb4a21b8bdVirustotal results 40.98% Heodo
2022-03-31MF-34447482.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31CL-5751025697262.xlsmxlsm 53ef2d3a553342c46f5d3011cb07634e1f02b36dae99808e47dd459dd384e388n/a Heodo
2022-03-31HLX-616225304849.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31OZ-816609194.xlsmxlsm a099f9c9c8eff7049da288a1205f1c0ccd52a4954930cabdd7a00dafbe8bbe6dVirustotal results 38.10% Heodo
2022-03-31XH-41496658.xlsmxlsm 8ffdaa8f731fe2148ad8c7dd79ce44c3dc17eadb46af64c64a76395fd0e629acVirustotal results 40.00% Heodo
2022-03-31YBM-3413277.xlsmxlsm 484ac30b71e02b553efb54dd38ddc6e86610a68995e280411a4b9f30c8630c77n/a Heodo
2022-03-31OTT-8101242021998.xlsmxlsm 265f4ce97b8c4a17c8f27359496edc3f97e2e6926a267fba16797dd5c6e3a70bVirustotal results 40.98% Heodo
2022-03-31KL-32466393.xlsmxlsm 52939ecf287fe6bf3435960c423bf17f7ea8452f102024e9aca86cf806fdd533n/a Heodo
2022-03-31PC-11438832494449.xlsmxlsm 0c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3n/a Heodo
2022-03-31CX-8898589378587.xlsmxlsm f93f882fe4bac2b1210512c64a2985c99282b49a95a2aaa3bfcf6865d6dd0056n/a Heodo
2022-03-30EV-4300635093399.xlsmxlsm 2909468da77be7c90d3c57fa66be2e6250afde34bd400f2c815be9bfd89be7ddn/a Heodo
2022-03-30VIX-6802218980934.xlsmxlsm 533372e6130ad44ced6eae30ab3af8be4ae172cc7585719b61074bb861f2dbben/a Heodo
2022-03-30NTQ-75450429893.xlsmxlsm 168a9aa1b5fa37a354fd6ccba71dcd29cbcd503a578504c69feb38bd84a8a691Virustotal results 30.65% Heodo
2022-03-30VO-796392345113606.xlsxls 403c28ce1df56f185d0824575299bea20d7d1738e6a9688c551d039b6d1aaea2Virustotal results 28.33% Heodo
2022-03-30n/ahtml e5c0ea84f46acd46268752175da5c6a89926b5f271828d7660458a27f7d1394an/a