URLhaus Database

You are currently viewing the URLhaus database entry for https://sales2b.io/Fox-C/rBoNLURu77UVu6Rww/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1913559
URL: https://sales2b.io/Fox-C/rBoNLURu77UVu6Rww/
URL Status:Offline
Host: sales2b.io
Date added:2021-12-23 09:01:09 UTC
Last online:2021-12-24 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-12-23 09:03:41 UTC to abuse{at}hetzner[dot]com)
Takedown time:18 hours, 23 minutes Good (down since 2021-12-24 03:26:44 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-24H445320811482225.xlsxls b83acb50575b7d5099bbf5f0fd6489e8f4280c87b4ec18c27193a9d22b19c82dVirustotal results 20.00%SilentBuilder
2021-12-24G56035617016066.xlsxls e816b8af8419f2ff9402737cf33c8a97c8c9f1ea64bdc49898c5e3879b49278dn/a Heodo
2021-12-24K592116312.xlsxls d7b1cb1ae00dca8fee12505663178144a9f6e73485e53b9e5bc644597514c2b7Virustotal results 26.67% SilentBuilder
2021-12-24Y80564350535065970.xlsxls 824a3f0277b943e71033fce00144f02f387109b820629795a6004b19b78504b4n/aSilentBuilder
2021-12-24D233308918360995459.xlsxls 8572129b1cac68674b83cf9bd41a81f9f3d0d2e57f89336549d93828ea8f9a83Virustotal results 20.34% SilentBuilder
2021-12-24N104522270816.xlsxls 217d7429a7e27846234640ca688f2cf4322537249276789a974d10ad3ef1bdb6Virustotal results 27.12% Heodo
2021-12-24W17428752.xlsxls b3217d89db940b89373fa4722cc741990ac78e6c640c501f263dc0281ee07903Virustotal results 26.67% Heodo
2021-12-24B63552289.xlsxls fb82843f10db494932a1319ebd8ee58ac58c0a06f3fd0ab9aa07e4c8670681a6n/a Heodo
2021-12-24I01336245203119.xlsxls 924640dbbfd1b3edcff40a76cc477f4620e22633329c8e153ad05f2bdca3bbben/a SilentBuilder
2021-12-23S0915359.xlsxls c40d34e4a36e023913b611711194fee37a9cd7a63feda45a49387e897df904e0n/aHeodo
2021-12-23E6713744.xlsxls 5bb626d65f16f3befd6929af097b9f8513a435662959c67645414a795777208aVirustotal results 16.67%SilentBuilder
2021-12-23P2252284892.xlsxls c823f747a61a893f0695d0e4976a02a5b8ebbe8c6cd9c7d1a4a93e0d850e730eVirustotal results 20.00% Heodo
2021-12-23W5854329183610850.xlsxls 42603cb53911f9ca1f24c482898ce630307c63d1b3c6106a90effeb6e98c13b6n/a SilentBuilder
2021-12-23D337005381767060008343.xlsxls be5684befe36a019ae8d6f8492eec5ce265d9695aa76e242c46c9eeb2cd76561Virustotal results 16.67%Heodo
2021-12-23E6059092825038.xlsxls 9c5d887e1325f828b492c2c96b0613655a5d5d2dbfda883a46488659ccf8dec7n/a Heodo
2021-12-23O81328417684.xlsxls fafa2ae98fe73affbbfabe314789e9076966ea64cadba074b161e9906ee20f80n/a Heodo
2021-12-23A6346827021813031109.xlsxls 5ed58ddab29c6f791015f938f0cb4adf6a6acaf01713621dda6c989d282935aen/a Heodo
2021-12-23110747707831395.xlsxls dc1641158c36eff2c4d91bbb19781d1af7344fa0f7caca62597bc783e242fa5en/a Heodo
2021-12-2380701362743.xlsxls 861cb62cead8d40f593f586755b1479dcc59e2ceafa956c149f2ebd073efadb1Virustotal results 11.86% Heodo
2021-12-23923938379740.xlsxls a5bc5901f86b006d4956ecc16e7eb5bd82236314ab68e08ffb88dcb31f43b960Virustotal results 10.17% Heodo
2021-12-23751201706.xlsxls d17e5714f2363c494e05cc3eb9d8ecd3bfa4a4d1fbdca6211639e1a3f22d625aVirustotal results 10.53% Heodo
2021-12-2313688588954.xlsxls 3d864a5abb894f87beb6922c0c3e9281328fb736fb6a8aca743622504374bc59Virustotal results 8.77% Heodo
2021-12-235334712010074.xlsxls 09a0c26818f83cd912922688f32145dc3457a678a5494ea4ff48f01efbe81179Virustotal results 10.17% SilentBuilder
2021-12-2345049148738963.xlsxls 60aba73bffd4d8285cd0fd090d2ae286e12fe0011cdceb5a260d731b58677462Virustotal results 10.17% Heodo
2021-12-234758063062106.xlsxls a481d58b9b01954ee8c6c3d44b8297c2cfcc3895f07f9beda648106cf39462c5Virustotal results 10.34% Heodo
2021-12-23018411411630336.xlsxls 88c5c9ef188378cdb6109939fe56c2f80e9f8957ef4e024909b03cf61402e9cen/a Heodo
2021-12-2335119032461.xlsxls 362bd4683c3102c2321471cf0e68baf188aa28b98790ae9a1772da66d01997f7n/a Heodo
2021-12-235406678293392006.xlsxls 89a15766c623b4dbea7629c9eb55d730025c98ce7ade1128f684f089e062e979Virustotal results 10.17% Heodo
2021-12-23124929310139906.xlsxls 1abb015e73fe7e537eb6e24b839ca986ad28652e1f65c4a5f557fd37249253f2Virustotal results 10.17% Heodo
2021-12-2388033136646.xlsxls 2a170f15029d9d55b7dad42d14f58e962f45df96879073456075ca40bcbdcb68Virustotal results 25.00% Heodo
2021-12-230199798329450073.xlsxls 832a938cfc84159a078fb16bbed0644db6e06770da8bf3e826e3b8a8711084ffn/a Heodo
2021-12-235664619526.xlsxls 90cb589e8ad98d161e345280f45e99f3713f803b6d98d81fc71b8566a0424c56n/a Heodo
2021-12-23740663604.xlsxls 42b1e2a0e213d6eee32b31260653d53bee0dda078f5fb6668453d80f9923c770Virustotal results 28.33% Heodo
2021-12-237208737886518.xlsxls 03359a1154c46ed7fa375c6d220c5f9b236f8a324657b3898d86eab19256913dn/a Heodo
2021-12-232834068439.xlsxls 96db156560d85a9601b70c1a695e9e2c1f1a7553af38397f29d6e426528663can/a Heodo
2021-12-234133084500910658.xlsxls 385a37cb84547fbdf22fba6812e0fe6cad247e5e1621ccb99d5fadd860d4b5b0n/a Heodo
2021-12-2339023949683910.xlsxls 5d1f5d444aa2f95ecc107aeda2aab52be49b64103bc947cca075ef765e8deacan/a Heodo
2021-12-234445405536578832.xlsxls a504a11a8d99739c2e8c7f3a5801b2697d2003db15d14e9b4a5ec57ae4e15a42n/a Heodo
2021-12-2394436514.xlsxls 216fa1b1519c963efbe24fd1334d0f367eee2418b8af407da62d6a1132e035d2n/a Heodo
2021-12-236347987.xlsxls 48fd4140e9773bfc0c3c2699d273e88be581c6d4933ec1966756ada7016d33e8Virustotal results 22.03% Heodo
2021-12-2369653973.xlsxls a9b99c81f5b18081bd702068ae6cbbf9ab0aca216053ea00174c7cab288eeacbn/a Heodo
2021-12-2356892394.xlsxls 081ba0d2825548ebed528cadc5c597819690cbb0a93451d15bfd71aa089f278cVirustotal results 30.00% Heodo
2021-12-232809320.xlsxls 0ad385922a01543568e212cfb1e35edf9089b10809986ef0790cebbb8cea45fan/a Heodo
2021-12-235192579333675.xlsxls ace44466c2b43f6fa09036ec9d87d50c31050728402c4a9c58e86d7ebfd1eb07n/a Heodo
2021-12-23682009352664.xlsxls 61130a5847b536ab3ea8864f5117bb92b3408849d4cc5a8ab3443f7c20872ff2n/a Heodo
2021-12-2359707184899587.xlsxls 6f83a6ead72ff0d14bb2a3d7b8eb3db5f845be37678dc1577f8aa199b4aeab22n/a Heodo
2021-12-230148445836489190.xlsxls a2930c425172e491112c3240dc1b5112a659050d0aab05594c04b30248232808n/a Heodo
2021-12-231152202495377135.xlsxls b5a8e2f5f7fe82dfbf09bbd6509f57d8b93bb81b5ab1a02e066e0cc7e7745a9dn/a Heodo
2021-12-23432926445.xlsxls 91d4f32d6a37e6013639cd5e523e6328604a95436f8d3b266480f57a97599f2cVirustotal results 27.12% Heodo
2021-12-2322168768498.xlsxls a03c451ea28bd499adaa3c394f8704439dc17fc7cdbb24d2ad2665b05d12769dn/a Heodo
2021-12-230318061.xlsxls 435a3b34c0bd974f368bce0cc95457050f3e727c580c104534377c66edfc8ec2n/a Heodo
2021-12-23808194898299184.xlsxls f9d1b2ac0446fed5d00c61bf9767fba85018d86908c3a74398d4f2c30f3d080fVirustotal results 27.12% Heodo
2021-12-236176770004.xlsxls c3382078051e880a209c31fefb1229e151594eb614b4eb6ada220d671ee7162eVirustotal results 23.73% Heodo
2021-12-2382193625525084.xlsxls fe2203b02b75563948e0147d2e17f6481116f2a58551df60416c61fcd764c37cVirustotal results 22.03% Heodo