URLhaus Database

You are currently viewing the URLhaus database entry for https://haball.pk/wp-includes/J5U10vgPh33u3Nqmr56/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123198
URL: https://haball.pk/wp-includes/J5U10vgPh33u3Nqmr56/?i=1
URL Status:Offline
Host: haball.pk
Date added:2022-03-30 20:10:05 UTC
Last online:2022-04-06 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-04-06 10:21:06 UTC to abuse{at}networktransit[dot]net)
Takedown time:6 days, 21 hours, 3 minutes Bad (down since 2022-04-06 17:14:43 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31MLF-897377295.xlsmxlsm 65320942312ee91e071ae3e59670ffc7c8f0f691fcf70cfebdf8bf25631a9e21n/a Heodo
2022-03-31WK-321224098.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51Virustotal results 41.94% Heodo
2022-03-31NU-639557206.xlsmxlsm 30deb7a7086f74317285271a2e26e40dc43b461a1a77c77480ea742b02cbe51fVirustotal results 38.10% Heodo
2022-03-31FR-263330056332051.xlsmxlsm 265f4ce97b8c4a17c8f27359496edc3f97e2e6926a267fba16797dd5c6e3a70bVirustotal results 45.16% Heodo
2022-03-31YM-350921728.xlsmxlsm 52f73166b6afefeb75e3e2459eb3b8a48e0c9309f83620f4fdbcfcbedaff3f66n/a Heodo
2022-03-31MAP-449504169327501.xlsmxlsm 70c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080Virustotal results 43.55% Heodo
2022-03-31IP-1097517.xlsmxlsm 08e924859a3a3f17c099cca75fbb3cfd7f8cd726fa2e89fb47ff02f9687143baVirustotal results 38.10% Heodo
2022-03-30WF-301825794200361.xlsmxlsm 9a0b2121a81929d3ea98a8b4b0e20693192eabb5c4081e2ac411fe4ed06f9f7bn/a Heodo
2022-03-30WJY-8774638.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30DEX-6737575322.xlsmxlsm a9850d81856c9d96fc75ccfe0a62c2142422d5feb66ad218a0b057a52bc4c554n/a Heodo
2022-03-30BQ-369273548331.xlsxls 34c12fb797211966f38e1025e683ec8ecc00b70e39d5f463213f7b09eea896c4Virustotal results 28.33%SilentBuilder
2022-03-302279997222721.xlsxls 7324fd5254825996acb024055b8f85c89b19897ef327543836bad401b074d0b6n/a SilentBuilder