URLhaus Database

You are currently viewing the URLhaus database entry for https://haball.pk/wp-includes/J5U10vgPh33u3Nqmr56/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123187
URL: https://haball.pk/wp-includes/J5U10vgPh33u3Nqmr56/
URL Status:Offline
Host: haball.pk
Date added:2022-03-30 20:02:08 UTC
Last online:2022-04-06 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-04-06 09:38:06 UTC to abuse{at}networktransit[dot]net)
Takedown time:6 days, 21 hours, 22 minutes Bad (down since 2022-04-06 17:25:15 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31MLF-897377295.xlsmxlsm 65320942312ee91e071ae3e59670ffc7c8f0f691fcf70cfebdf8bf25631a9e21n/a Heodo
2022-03-31ZL-8970878657626.xlsmxlsm 566c3447fd5a1b7f7f0c942d484a0185bcd747d47f9c487452dcbfed1979bd52Virustotal results 33.33% Heodo
2022-03-31GIK-29451959222.xlsmxlsm 484ac30b71e02b553efb54dd38ddc6e86610a68995e280411a4b9f30c8630c77n/a Heodo
2022-03-31GJ-1152254.xlsmxlsm a43da1637de01a06d72a9d09981de5132b8bd971844704ee9fc7c5e07450a49dn/a Heodo
2022-03-31YM-350921728.xlsmxlsm 52f73166b6afefeb75e3e2459eb3b8a48e0c9309f83620f4fdbcfcbedaff3f66n/a Heodo
2022-03-31OTC-940645478487922.xlsmxlsm 0c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3n/a Heodo
2022-03-31MWK-16717020.xlsmxlsm b73f04d9f7a2ce5624249871b7f1277fcc2959bfe5abcaa33e1da19e0da9cb08Virustotal results 38.10% Heodo
2022-03-30HI-967713411807.xlsmxlsm 2909468da77be7c90d3c57fa66be2e6250afde34bd400f2c815be9bfd89be7ddn/a Heodo
2022-03-30WJY-8774638.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30BFK-653984925.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30TXP-94566805643.xlsxls 2fb5d6b4684b1f180fd682f92fc346420c16376d64b8b8ec6b0564247000dc58n/a SilentBuilder
2022-03-30n/ahtml 3cbbf9a615d5ba920d7594a8940ee11c48695f2191047be122c47067cc0ee9d7n/a