URLhaus Database

You are currently viewing the URLhaus database entry for http://buildotech.com/hijy/658850587-9/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1968315
URL: http://buildotech.com/hijy/658850587-9/?i=1
URL Status:Offline
Host: buildotech.com
Date added:2022-01-11 20:18:05 UTC
Last online:2022-01-20 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 20:19:08 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:8 days, 8 hours, 39 minutes Bad (down since 2022-01-20 04:59:04 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-125505AHSIAJGM_7251.xlsmxlsm 57dd75934f8e97adf3ea865291bb9766cae096c65aa55bcf8df2ff2325779fa1Virustotal results 17.46% Heodo
2022-01-1283347994507.xlsmxlsm 0c16a75494c71ad39149e21f629585890f62b87f82f421aa9796f55a45911f82n/a Heodo
2022-01-12GF-954052.xlsmxlsm 4ba298f5eb285e1caf8eec898984ac6cd199b8311648d62aaece404c80edf321Virustotal results 16.39%Heodo
2022-01-12207_6023560.xlsmxlsm 6511bf0cd0a150e9e4530b6b27ec3c9227b0e6ff38eafd6f6045f71ded06bc03Virustotal results 17.46%Heodo
2022-01-126137733-5855093.xlsmxlsm 5af2a325f143af92ffc1ad4c45442f8ebcce5937fcb00a77ff3b51c1effdebbdVirustotal results 17.74% Heodo
2022-01-12LA688.xlsmxlsm 27d6855c830f8df3fde9a9f56e1cf9c88ad097a4cb45b4983f63e70a7c0517d0Virustotal results 13.79%Heodo
2022-01-125120_7933.xlsmxlsm aa0e7e06ef6a8326e0d55630872406ec5a56ab4677760157c5b8cf9c7bc49623n/aHeodo
2022-01-1230511271-70841545.xlsmxlsm ce390c83df0a362de9c0a4704f3a7a22d52e5e536a46f3d64618812f24e7ad27n/a Heodo
2022-01-12136998864307.xlsmxlsm 79daeb5bf882947dee2541dcc653db008700b0f5b528335398d1ee9d934e3e7aVirustotal results 17.46% Heodo
2022-01-1245-636254.xlsmxlsm ff0dd0d6c82eabd6f0c69da4f366755d7e300e845e1eb68342107fa69d83b53en/aHeodo
2022-01-1273320_019.xlsmxlsm c5b975c17c0bb735289b89373ddf4a74f1c092098730f47ee94905c37d05df03Virustotal results 17.46%Heodo
2022-01-1240025034_634.xlsmxlsm ba7c1dc54af2f71c4737c1122c4092af41db3769d6f6883cfcc27636f9f133b0n/aHeodo
2022-01-12725544159556.xlsmxlsm 53812bd0525b37568f64e10ba86d759bf65fa1e511dd43b4c7e8d458229d305dn/a Heodo
2022-01-12xe03876559.xlsmxlsm ea3e85162646a07f1e9328a85f012d22517bf42b58e0eb11987d8fc701357292n/a 
2022-01-1278GAKGVEOXBK_57548.xlsmxlsm 6de523cf03d5a8cb34cc06b2f41ccd57f611201fcf36696d9f9c601bae54cd40Virustotal results 15.87% Heodo
2022-01-12oH_311903.xlsmxlsm fe9b66e9750d5a9622c8cdf80c0fe282396305c32affe31e612bb8a69485ea80Virustotal results 8.33% Heodo
2022-01-12y-5206874.xlsmxlsm 92713b457c90861b16201ffa88fe2c16b77c58265d9a4c249d683fe899fe4af1n/aHeodo
2022-01-12wzirfm-81329648.xlsmxlsm 99704dcf815cd49262652add049aa8b90b0549e6c769adce9de208f71bf5d7cdn/a Heodo
2022-01-12V86.xlsmxlsm b34ba405eae43784dea2e89cee8c5fee71bc8de8ad674d58d7d6bdacd2ac52a1n/a 
2022-01-1267995604.xlsmxlsm d2bcf2bda4b017286f8f68c4a613bc34f230670d136e5140fce43194dda7c86en/a Heodo
2022-01-1270QDPXPSYGT6200.xlsmxlsm 17f03ce4ff3120ccad3cb69b71f73257b385061b7fde11370a98257caa36b273n/a Heodo
2022-01-1269963_25.xlsmxlsm 1e50449562b25ca05c87fd4ec8d1166d89f8043a941b27fdb07f30dcc231b5d4n/a Heodo
2022-01-12495801.xlsmxlsm 2290d005f9baba04f5ee48f1545bb6cbc2db9d5bada9763698233eb8a95c033bn/a 
2022-01-12862378817-2251523.xlsmxlsm 8d17e6affc048db2010e1a8ea21fe99e522aca0e88cd8a930ffbdee911309c46n/a Heodo
2022-01-12984055JERMFW_427.xlsmxlsm f3c5183187bec6e03d69db279fdacf6ef6da9f243b263c82fff3a206ae4879a3n/a Heodo
2022-01-12YOFGE-1788.xlsmxlsm 3ef2b8a6070172d50448713db5b705ec1884d4b5e67e984d8a84d1a1329ebaebVirustotal results 14.29% Heodo
2022-01-1275093-378.xlsmxlsm 7d1dc178571039c34f2a0d908107ce3b24f74fe93ca9843928d81ee09ae213ebVirustotal results 14.52% Heodo
2022-01-12T_886811036.xlsmxlsm 7b23d6a5346b658b23fc0605fb5fdbea6bad8cb3846ee1b076479ff6e560a289n/a Heodo
2022-01-121720-854340.xlsmxlsm ee097abcfc352c62688eec061aed96275fb4862a3fb1d2b450fdbc07234bd5b4Virustotal results 9.68% Heodo
2022-01-12t_909977469.xlsmxlsm cb1f89046f7898f583d7ce5bf765b81582f9cf646847397863824fe4267a8badVirustotal results 14.52% Heodo
2022-01-12VLM_41.xlsmxlsm dd4bb165098876eece296f603bcaad2abaf3a306255559022fbe195553139c96n/a Heodo
2022-01-12J_73705.xlsmxlsm 7ee5d7c6d793d39fefbad3dd41511f94fe3b893e6c4080916fe6a00d6b41e3f5n/aHeodo
2022-01-1247181928GPVZBHUMZ_3988.xlsmxlsm ae07a783e2db5694e8dc897f18d6303fb09914626708dec41aec7a4f43d1f74bn/a Heodo
2022-01-1213076319_594641.xlsmxlsm 31f54e459b699cc0a4f9c9cf15481019ede90771c2921cd1424361acd40044e3Virustotal results 14.29% Heodo
2022-01-12E_334.xlsmxlsm 775e8ead32426df8843052b194bb6347952c58b1e93c88fcd4b5332c9cb72a41n/a Heodo
2022-01-120354089-8065886.xlsmxlsm 6cb3272ca6160c0e01f7084ecda308e0d4599b5107c80b3cdbf497268a05b540Virustotal results 12.70% Heodo
2022-01-1264904_51891242.xlsmxlsm 532169af0239d3f90afefe58a433bda8070dd51a49fe6bf22ab3a8e365c5d58bn/a Heodo
2022-01-12197195115_0.xlsmxlsm 94fc2ad122ed454bc9372a45f62f10e8f65f77f51f5acc8f871f72454aa449fdVirustotal results 10.00% Heodo
2022-01-12nH_113.xlsmxlsm 263dc5247e15db142100c5f3868fbb16eb2d25b2ce86ebaf407be909a39e6406n/a Heodo
2022-01-12252877082169.xlsmxlsm f3d1334b346c1bab22c541a6fb05cb2f0bcbfe8ba5a055d111b1c05505d5baffVirustotal results 13.33% Heodo
2022-01-12q60369535.xlsmxlsm c17c14f8440fdefa29879068c2918c34171f4ca6b3276ac83e9d70fd7b2164ccn/aHeodo
2022-01-1242768_807383.xlsmxlsm c42c6b271090675b57d6970aa659e468606dac00d39875f1dd85f57a9f203654n/a Heodo
2022-01-12lti-203470.xlsmxlsm d22b1ed4ea99f7ad304a62fa6fa6755831c212f00508bd84b500904f99a1f766Virustotal results 10.17% Heodo
2022-01-12290360201959.xlsmxlsm eadb80966605b87f9a5633aeef55213108e6a1309ef209ad23c7e63759452c66n/a Heodo
2022-01-12417272_1608875.xlsmxlsm b94a04d3a5f75fb0370e59e96488c49848647fd60e1b9ef2a9e898ff5b53f6can/aHeodo
2022-01-1214823235453.xlsmxlsm c95bf0dd160b7a12ab600aee9220e652b1b1cc3b006f264c324a0c0a9d5aa257n/a Heodo
2022-01-127565157_30745.xlsmxlsm b5e8f3567a440978a4203bb8ad88886ed6d4c9c2ca4a599897d7227c56368bd2Virustotal results 9.68% Heodo
2022-01-1100507_4.xlsmxlsm f20a142423cea7ec0369d225894d4cf71f4c31d425bf0215de2b6277a5354192n/a Heodo
2022-01-11808780-235980.xlsmxlsm 427080f3d4da3ec0746fc297c0a922b5212a53ae04504f5efd17ff4f9208c662n/a Heodo
2022-01-110905299_871944.xlsmxlsm 6ec9e504112744f9f07ce60fb9315cdcd427d27a16c248fbe9746477bfc851afn/a Heodo
2022-01-11b44967.xlsmxlsm aa920a2c74b8982c5dd77f97f0dd2d6c7fd69f047983447d6ae43cdf1573b07dVirustotal results 9.84% Heodo
2022-01-11CI-69.xlsmxlsm b8662d7aff6b2489b65fd6ddc022a5a87c6adb0e1ed1f0286ccd80c0bc11471fVirustotal results 9.68% Heodo
2022-01-11obkfujo_729157.xlsmxlsm 130eb4a6e7be06428ac24a7bddafcefed7d23415f7d822a6c55d0cac55cfb6f9Virustotal results 9.68% Heodo
2022-01-11IW62.xlsmxlsm 69fdc8b909b3d9e8de4ffafb89dff475c99a4e3ac57eda41c014cea8ee8ddcb6Virustotal results 9.68% Heodo
2022-01-11poxcfx-5420.xlsmxlsm c4bc03a927a72a21be0b15c8c55124264c456a940a325d8071f5cbcb7032f1c8n/a Heodo
2022-01-11835_817859.xlsmxlsm c2cb81db208398e070c47e7d03e76709142dec85ddaa985883536283a0acbb14Virustotal results 9.84%Heodo
2022-01-11CRZIS_9950091.xlsmxlsm 79a935edd516953713a4d4565e5dfcbbb08f17b9633f31d84e0e042a5de4c178n/a Heodo