URLhaus Database

You are currently viewing the URLhaus database entry for http://cld.platsandgo.com/assets/c2538/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1968373
URL: http://cld.platsandgo.com/assets/c2538/?i=1
URL Status:Offline
Host: cld.platsandgo.com
Date added:2022-01-11 20:30:05 UTC
Last online:2022-01-12 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 20:31:08 UTC to abuse{at}ovh[dot]net)
Takedown time:10 hours, 43 minutes Good (down since 2022-01-12 07:14:34 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12CFJMC351284.xlsmxlsm 4b2ced5ad04b4256bef5bee0fb95867913b271eabac843923fc16220f924b332n/a Heodo
2022-01-12KT_52846156.xlsmxlsm db88756a23fe6c0998ddbf1864efe7e4a28073dca342fa7712775388ac757529Virustotal results 14.29% Heodo
2022-01-12legi_673740.xlsmxlsm 78692618c12acca00b6da84e155086145c3d8140bf9bbfa308510e77da32c4d7n/a Heodo
2022-01-12734395_1642378.xlsmxlsm ee114d49a4192550bd7b5094c73f545ad17e8e0514684f8124f3b13f204bc061n/a Heodo
2022-01-12408599793_50400.xlsmxlsm a49d524f974becd9753ec5781b8d2ea4788fd2826e762a18a8e737cf579b3eedn/a Heodo
2022-01-12BZTOM_85068791.xlsmxlsm 95761ae4efbb60ee498b7d56d6c84e48753a21ab59a655f5439b47167baf6ea2Virustotal results 10.17%Heodo
2022-01-12623274303-858383.xlsmxlsm 8232bffcdf155d94e02d6bf3de90b25764ddf81e8d0071b283d866debed7e5a3Virustotal results 12.70% Heodo
2022-01-12SYA-024.xlsmxlsm 1c873e22b4b174756cf0b84c5fd5af1b12515761507c3723ff77a95572ef0823Virustotal results 12.70% Heodo
2022-01-121693255494.xlsmxlsm 2d954283067945efe19a87dfbb59f88f2bb4eb034fe285fce5448bf092faa730Virustotal results 9.68% Heodo
2022-01-1246560-9512864.xlsmxlsm b1fdd5d25639259cc813c570979343d8e297a624df7f477788cc0c0622f2a671n/aHeodo
2022-01-12FX_5073.xlsmxlsm ef5bb2b9bf9fc8c4f7d325cddd5202c205f256d0d59689570a2b332203c23314n/a Heodo
2022-01-12436152_4355.xlsmxlsm f84556b6185aa546506bdc7eddba5d3b4cc4a44f32366edcd3755baa19c73f2dVirustotal results 9.68% Heodo
2022-01-12qELG_781.xlsmxlsm b467daf3c66e48745f7c878e38cffc2bd0a1d0c9409e7a7be13e5c76a285d542n/a Heodo
2022-01-12CY_563.xlsmxlsm f28bbe346a1043a08f1cdc244ca35bb345e7a7dd491c22e9197cfc449e5a59b4n/a Heodo
2022-01-12771263JWN536.xlsmxlsm 3c650d7a8587b1e9fd3720682611258f730d5762a31eec35e66269191f376295n/a Heodo
2022-01-12273338618902156.xlsmxlsm 697ea1260245ebb08b7387e6d6f4eddd9f9d37d4849abb996244b79526827a11n/aHeodo
2022-01-11HLYG-59692821.xlsmxlsm 2bcd5baa2d280f6afd51a5beb204c382fce0fa58f20ff76076d27cb2323e8ac6Virustotal results 9.68% Heodo
2022-01-1123JJGA57250441.xlsmxlsm 427080f3d4da3ec0746fc297c0a922b5212a53ae04504f5efd17ff4f9208c662Virustotal results 10.17% Heodo
2022-01-11Y8351.xlsmxlsm d232986e906c448669c346c5edefc1d51b9224b6d53afd360e4768f9861eafadn/a Heodo
2022-01-11o665109.xlsmxlsm aa920a2c74b8982c5dd77f97f0dd2d6c7fd69f047983447d6ae43cdf1573b07dVirustotal results 9.84% Heodo
2022-01-11314RZFBNLCWH_3.xlsmxlsm 8a9101b7343bf1a4608ae17b84bd290c1e40f510ec792e9c5d3cc5ace4ca5490Virustotal results 9.68% Heodo
2022-01-1128137_362.xlsmxlsm 8ad61be673c186c9cdfb6c6c8d750fbcf80f920d4905742c0ed9d67833026ed7Virustotal results 9.68% Heodo
2022-01-11736759-83134.xlsmxlsm 71da6e57fe5adfa0b06f8ba9525e6db95e7c25246179fa8563561d24e79e6c65Virustotal results 9.68% Heodo
2022-01-11339630_984134.xlsmxlsm 929fd76e8373d3c14a1fa542d4222dba73cb21f0c5cdaa0c8b7acea0a53d8f0bVirustotal results 10.00% Heodo
2022-01-11OGWE-04802846.xlsmxlsm c9e970aa711be04a18931e15dbeb8bc9e24beeaa6d8e95ec64d11c3c9d0eeff6n/a Heodo
2022-01-11r-1664855.xlsmxlsm 54ea8278be35064a8017aefe7f5c1f1497983d965e89621a056edb730b109bdcn/a