URLhaus Database

You are currently viewing the URLhaus database entry for http://swmoz.demo9lec.co.za/dgcothq/3629720WVWLU_6/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1967916
URL: http://swmoz.demo9lec.co.za/dgcothq/3629720WVWLU_6/?i=1
URL Status:Offline
Host: swmoz.demo9lec.co.za
Date added:2022-01-11 17:48:06 UTC
Last online:2022-01-20 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 17:49:06 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:8 days, 16 hours, 47 minutes Bad (down since 2022-01-20 10:36:26 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12711120408_8785428.xlsmxlsm 697ea1260245ebb08b7387e6d6f4eddd9f9d37d4849abb996244b79526827a11n/aHeodo
2022-01-116448_5506071.xlsmxlsm c82f282fe8e4c3583e5e4d834ae90565ff0b3fb958513688b442153cc57c82fbn/a Heodo
2022-01-11cxah936534724.xlsmxlsm 1df00c09db9bfcf4e493dacdef73f2b732cd06ae4b931bd356516667a44c47e2n/a Heodo
2022-01-11L-567.xlsmxlsm 57bb4eb8428998738c8860427c1c1de98d681120512901d8174f8fc2edd545f9n/a Heodo
2022-01-1196841000_5426002.xlsmxlsm eadf1f43941284bcf91014295d0353b4d71e409b16b8f8991dbdf11ba404bf2an/a Heodo
2022-01-110004_70.xlsmxlsm 8a9101b7343bf1a4608ae17b84bd290c1e40f510ec792e9c5d3cc5ace4ca5490Virustotal results 9.68% Heodo
2022-01-11C_49200092.xlsmxlsm 20be5590c08561d3a5be97621400daf8528533950a589089a00a259da40668d8Virustotal results 9.68% Heodo
2022-01-11uizvq7.xlsmxlsm 69fdc8b909b3d9e8de4ffafb89dff475c99a4e3ac57eda41c014cea8ee8ddcb6Virustotal results 9.68% Heodo
2022-01-11vdbWK_0383791.xlsmxlsm c4bc03a927a72a21be0b15c8c55124264c456a940a325d8071f5cbcb7032f1c8n/a Heodo
2022-01-11y_744.xlsmxlsm 6c410c1ef971638f6cb6b26c9c1613bd8cb7c3bb10ea63146e40405c80cca38aVirustotal results 9.68% Heodo
2022-01-1187491.xlsmxlsm be28d13f222be634d640dd982c04039f80c9ada5efc2eb126adca4c9a3595d6dn/a Heodo
2022-01-1183006YHFSHLIR-450596.xlsmxlsm 9a67c9f6fd753a0ebb03e8eff1557ea4fdb517b473c8be64c1d4f6a94da900c5Virustotal results 9.68% Heodo
2022-01-1127535-4.xlsmxlsm 051d5f4c4102ef6ac6b09bb70a215e4d78b98be24d8a20d7cf483e656d34109cVirustotal results 10.00% Heodo
2022-01-1155286.xlsmxlsm 95761ae4efbb60ee498b7d56d6c84e48753a21ab59a655f5439b47167baf6ea2n/aHeodo
2022-01-11JQON60.xlsmxlsm c7361097a3fd04904faaab145a9e15e79e0a3f772aa9f0e374e8ecb7e2bca145Virustotal results 10.17% Heodo
2022-01-11556952970.xlsmxlsm 9130d8068b2ef10c7127ddbc23715591e0bd026c0ce94a36c26d92b99ee8e524n/aHeodo
2022-01-11XOJDT1130082.xlsmxlsm 60a2fe4a87a42aef09d57e41fa80f438983821928336d78cd14ce1042e638b6bVirustotal results 9.68% Heodo
2022-01-11ADEY-93405.xlsmxlsm 2c337e62c2e3a1a3f742a2c7977a24bec7e8458e31a0cde9ce590cc53ff5a819n/a Heodo
2022-01-111160_3.xlsmxlsm 94fc2ad122ed454bc9372a45f62f10e8f65f77f51f5acc8f871f72454aa449fdn/a Heodo