URLhaus Database

URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as HeliBot.

Database Entry


Signature:HeliBot
Firstseen:2024-11-07 15:23:08 UTC
Lastseen:2025-12-04 06:11:13 UTC
Unique Payloads:29
URLs:29

Payload


The table below shows all payloads that have been identified as HeliBot.

Firstseen (UTC)SHA256File TypeFile sizeVT
2025-12-04 06:11:136ece2b3ca3002b6ed255647b9ce906b5fc54d297aa7bf2e34cc992e28b3ab2c1104'712n/a
2025-12-04 06:10:128c463c115b145a7825dbb5ba74b1288a8bdf401a7f88765d7ba053ea74bf008c144'778n/a
2025-12-04 06:10:1244873dc0fc06e0cae727f357cdf61d79b92f08d01506a5e5a9802c85ac771034106'529n/a
2025-12-04 06:10:12f82716a75a974c80272d7beb11a9fd2b8a6ad48116936f4499888f14e44fdaa791'819n/a
2025-12-04 06:10:1237ae5202f43966cec314666a2c750ba2c823a1a251ac29168874cad31df48a2d104'824n/a
2025-12-04 06:10:12ff23c876a53c366630b5acbf2d2b1d9afc4910c77528fd46b3c65baa346cf2a885'241n/a
2025-12-04 06:02:14eee8970fbf689f85e7b65f83d80a7966bf3a1a5fa6bde3f6d2d92eb4e1b64dcc2'248n/a
2025-09-14 12:05:105368bff56c657179b4fe196d01b2fee7c99e8e632462f23c53ef3c03867562a32'109n/a
2025-09-14 12:05:09fb21b1f4574a375639617cc47af121229e375c251bcc70b0358afaa1d1c66e49106'529n/a
2025-02-21 17:27:075636d0bf0c441aa5cd05e6c855e58ded740ca95aa673290f7530b04568cf71bb106'529Virustotal results 40 / 63 (63.49)
2025-02-21 17:27:0726923b7d86e00f9605881a4de838be5c61fa3146b02975d02d40c24a9d6650f8131'184Virustotal results 36 / 62 (58.06)
2025-02-21 17:27:0636f721844bcf9cf63109dda76d5e3d9e6b7655cc9b80ceefa21061e46a0fc1a4144'778Virustotal results 41 / 64 (64.06)
2025-02-21 12:12:055636d0bf0c441aa5cd05e6c855e58ded740ca95aa673290f7530b04568cf71bb106'529n/a
2025-02-21 12:12:0426923b7d86e00f9605881a4de838be5c61fa3146b02975d02d40c24a9d6650f8131'184n/a
2025-02-21 12:12:0436f721844bcf9cf63109dda76d5e3d9e6b7655cc9b80ceefa21061e46a0fc1a4144'778n/a
2024-12-02 18:36:09c4dd765d224cb5d36c9c8feeef3c27e478a6fa45f183a92f44bfc762ca33e261104'824n/a
2024-12-02 18:36:08b010e0e865ea5453b73c624b130f680e1b3d4814ba0bbdcb9f787428f53e5485144'778n/a
2024-12-02 18:36:082c033ed3f0aa2c1ba8bd858c600b25820c320bf360ac5d5a862857100acf853e104'712n/a
2024-12-02 18:36:080fa8f7eaddf75c73dfc4594ce5367118ab45216b64123b604cf0edcfa6d6918b106'529n/a
2024-12-02 18:36:075daac57b6c28be7de0281f4e9884b97da2662e85728e929fd23a6137d76134a180'455n/a
2024-11-07 15:23:10eaaff494428a4ee3807dadc5af695696d026b48a573747bb8330e713cc165148106'529Virustotal results 41 / 64 (64.06)
2024-11-07 15:23:10de522e7699a5c60df09dda05ccfe8c28237788694e1803309a8e7492618083b0124'582Virustotal results 37 / 64 (57.81)
2024-11-07 15:23:0984852b64426f64738de2d655db376e5a66e69147e25335a40581af539b17e96e91'351Virustotal results 34 / 63 (53.97)
2024-11-07 15:23:099ef46206b7c6dc478fc7ea5b0be08cb8fc590e8b3b2da1eb18a2a730379eb04e124'582Virustotal results 36 / 64 (56.25)
2024-11-07 15:23:08385de9ee66959aebe08cb5c41c87c4e5971552c885daa89632d87b90935b3ddf105'152Virustotal results 35 / 64 (54.69)
2024-11-07 15:23:0810c33328219a107f88de1e64b41308e5fa42814d87aef1f2f6297bf805dcbdfd144'778Virustotal results 42 / 64 (65.62)
2024-11-07 15:23:08e4624d16da8ddf7be1741bc56bc57c5de457c9e30fc2282978b5ee081fe7d96c106'529Virustotal results 40 / 64 (62.50)
2024-11-07 15:23:082d98b9dbc4d75a63381d0b6e484b0a9a180318df53c040bd23cf3f66e9e8790982'666Virustotal results 37 / 64 (57.81)
2024-11-07 15:23:083f8646f69335748da3d0167c2726078ac6a2bce2141ffbb1e43e3eb2d599d704106'925Virustotal results 37 / 64 (57.81)

Number of entries displayed: 29 (max: 1'000)