URLhaus Database

You are currently viewing the URLhaus database entry for http://nawwarahtravel.com/wp-admin/FILE/kphlcbm0em3x/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429698
URL: http://nawwarahtravel.com/wp-admin/FILE/kphlcbm0em3x/
URL Status:Offline
Host: nawwarahtravel.com
Date added:2020-08-11 21:13:05 UTC
Last online:2020-08-13 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-11 21:14:02 UTC to abuse{at}ovh[dot]net)
Takedown time:1 day, 8 hours, 56 minutes Poor (down since 2020-08-13 06:10:21 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12ZHL_36978751.docdoc 8c7851a5daaa0c8c31576892d5cb0c864dd1bb198bacda8282d3f65e1dc1c820Virustotal results 28.33%Heodo
2020-08-12FILE_779932340359785157771.docdoc 14967b4d7ed265d47e03452c19a7c3d048828bfe37abacf2f56782e7eeeeab23n/aHeodo
2020-08-12DOC_FJP_080120_JWH_081220.docdoc ad8c8f216c595ab174ae2ccf71b9f20380e7fce15c8077b80541061a2a073d36Virustotal results 52.46%Heodo
2020-08-12REP_96009622.docdoc 05fb55b118852bdde2c76754d2d2b2700accc08481280cc2309ab985aeb86c06Virustotal results 51.72%Heodo
2020-08-12FILE_PO_08122020EX.docdoc f5e067c9ce4ac6b6dca42fbb099d867e403cc3e6590dbe9d8650b588cbb48637Virustotal results 50.82%Heodo
2020-08-11REP_34380016.docdoc 6ace76691636bdbdbb4f83630f0a2168999b38e936f308fef550869e5d893469Virustotal results 50.00%Heodo
2020-08-11DOC_7418864354804298509898.docdoc 854be831ad01f15c5a5cc2f0f253d059b2a9faaac66db5b90fe51b3daa401c57Virustotal results 50.00%Heodo
2020-08-11D_PO_08122020EX.docdoc 6ef92d63f441bea978f148ae6b93fd26d8feb4716042101e28ebacd3101f6eb1Virustotal results 51.67%Heodo
2020-08-11FILE_PO_08122020EX.docdoc 9d0bac325fa1b829f25ab0696d273be2b1eb46da5d94f3837ed30ca9c495b4c7n/aHeodo
2020-08-11REP_PO_08122020EX.docdoc 1d09b28a4d454266d52d7d2e5b9aeab2bbf43839ec33c9a7221eafae3c28c067Virustotal results 51.67%Heodo
2020-08-11HI4836674269GD.docdoc 9f2c2d82ace44bca7690c50a2ffac425afb8d0a417113c3715ec648680683975Virustotal results 50.85%Heodo
2020-08-11IK4102013117XN.docdoc 0d42809ab9b859db56beaedaa266afe18eb447d209b5f11522b39fb88deb29a1Virustotal results 52.54%Heodo