URLhaus Database

You are currently viewing the URLhaus database entry for http://naabayafoundation.com/wp-includes/4lzYQ8vuzHCvlyubrBJAy2vrWYHR3MaiP1vfw56IY5mvUVjiZxx3lV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:940284
URL: http://naabayafoundation.com/wp-includes/4lzYQ8vuzHCvlyubrBJAy2vrWYHR3MaiP1vfw56IY5mvUVjiZxx3lV/
URL Status:Offline
Host: naabayafoundation.com
Date added:2020-12-23 03:49:46 UTC
Last online:2020-12-23 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-23 05:10:03 UTC to noc{at}psychz[dot]net)
Takedown time:14 hours, 26 minutes Good (down since 2020-12-23 19:36:35 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-236O06RMZ23EY.docdoc 768f3c029cc79ae21d7c732487da93f0e8c7d19a83737f9ce7e107e3adc9054cVirustotal results 43.55%Heodo
2020-12-23DREMHNLD.docdoc bce89cd09be85ac647d834fb41cec14c3f695ddd559477288bd3853accb78258n/aHeodo
2020-12-23EQ8D02NQOKL9.docdoc 0339f21444ef1ad35fc320d6879ea93b08d3aea53e25aaf3c5b841a2cdad855cn/aHeodo
2020-12-23O0IU7LF1S2P.docdoc 97c84b3491b00cb32b26ac143d29922be55d22afa87aa8e8b05006b50c34cf78n/aHeodo
2020-12-23OU6J5V.docdoc 94d804683ab1c9195ece193461e872d75b4835c2ee0fc73886dcca02a89463edn/aHeodo
2020-12-236X8I88EHA1CP5.docdoc 395efc9f98f81ccdcbfe6f9bffdd0e0ea5a2611e4542e43f1241c649713bf46dn/aHeodo
2020-12-23D56CBLXA9VDVZV.docdoc 036504550e6290a5bd9b8c67b1e7c22de77c5034c8b51865ebe1c1f8d4d339b0n/aHeodo
2020-12-23JIC5AVD3S4H6.docdoc a7b7abb4d144045e42bf5e55e294d5b67850d11ccaac312734570ccca072851fVirustotal results 26.98%Heodo
2020-12-23OQO80S.docdoc e9df17a69800a02dc5484a6fc60d1e9f19f7059ed8f0ef9c7847beecc39968a3Virustotal results 26.98%Heodo
2020-12-231T2J93O9QIOH.docdoc cb4f991bd4228ec60ab6af1bab6193e68f4fadf3a30b226e7ee9cdfe893113a0Virustotal results 23.81%Heodo
2020-12-23W33LNQF.docdoc 49f4475b4c4b63927d612bfcfc707d4a25237813c727333fbcb42fec441757dcn/aHeodo
2020-12-23VAJ0SEFKEXIB45.docdoc 8e6a0c5576e309e8d8bc23d6103bc9d355ac27c354d69992c7fe8650d39e10b2Virustotal results 22.95%Heodo
2020-12-231QIQBC.docdoc d03bdc5b9f72efd01d6cb79bfb3a1a2abb46914234af6d3439f4879a1af9d35bn/aHeodo
2020-12-23LR56FY.docdoc f989bb90fd752549af52988b47a9cf55638f97c26ea723457efd21cdab409da5n/aHeodo
2020-12-23E7TWZ7B1LYDTDH54.docdoc 318cf158cf886f17e7e947feaaf989f25e514c91bec35e9dcca2a4f2ef4baa95Virustotal results 22.22%Heodo
2020-12-23NZEO650N15.docdoc a8a5d52ccfe6f7bcc1ef7c99087ec90083ea7e3851e760b0653bd4189d54bc9en/aHeodo
2020-12-23EFIJ5VZFG36EKIP.docdoc 383bbcf6e40f5db6ccf0a07f33eb55614c381daaae647ebf0ed8db148d4ab7fbVirustotal results 20.97%Heodo
2020-12-23NDSD8S7AJCF2PX8.docdoc f0a4ee510f94aaef257225740c62c4a65b2da3ced23ca6b1513b9fbe11fd3cd8n/aHeodo
2020-12-23JIBNNLCNM3OQD.docdoc 60029fa95c17ba479a9ed424abc3a3f684111997424360741b67de478d0bcd4dn/aHeodo
2020-12-23Y57TIS8XQT.docdoc 1b1cb32d2f4a43f7bd1699dd46b55f8deed32e31065c9f13c69f2610b96d41c6n/aHeodo
2020-12-23XE6IGEWEUTFF76.docdoc a59e3318597fa65b37e597175045690d391ef038c7e58869d71ba50ab499cc64n/aHeodo
2020-12-230MTYSH2QC.docdoc 64df2f4241becefb0876d62be5908b4d62620e2aeb97828cb2819d952d106f11Virustotal results 28.57%Heodo