URLhaus Database

You are currently viewing the URLhaus database entry for http://rjmtel.com/cgi-bin/821571656/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1969685
URL: http://rjmtel.com/cgi-bin/821571656/?i=1
URL Status:Offline
Host: rjmtel.com
Date added:2022-01-12 04:39:04 UTC
Last online:2022-01-12 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-12 04:40:15 UTC to abuse{at}aware-soft[dot]com)
Takedown time:4 hours, 51 minutes Good (down since 2022-01-12 09:31:36 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12993075258_68277.xlsmxlsm f9692b1b14f84c19013c44d18cbce9002b36fae19825c152563aa55cd4507402n/a Heodo
2022-01-12379358_825535.xlsmxlsm e9e6415510b97e8b3a7d452eb091b19866b9ec229fe934b5d8a726d0b010593en/a Heodo
2022-01-12O2768686.xlsmxlsm 6913af2de9271a92bd9c7c9afe4923a08f237459d7e1e03d171e96fa291e39eeVirustotal results 9.68% Heodo
2022-01-12914556_990.xlsmxlsm 1432dfaf66fc92262751cc8a85c31df66552687538effa62d8df537136495e1cVirustotal results 14.29% Heodo
2022-01-124775_58924781.xlsmxlsm f6eb92eefd23279c500288c9ad0001b53d55cb734bc2406315af250547aeeacdn/a Heodo
2022-01-12667-8808.xlsmxlsm fd430afe622e1d99902b0a4c1bba73111af6e5193852959c880ce5471a5e6181n/a Heodo
2022-01-1225768_8347490.xlsmxlsm 4b2ced5ad04b4256bef5bee0fb95867913b271eabac843923fc16220f924b332Virustotal results 14.29% Heodo
2022-01-12ws_7886799.xlsmxlsm db88756a23fe6c0998ddbf1864efe7e4a28073dca342fa7712775388ac757529Virustotal results 14.29% Heodo
2022-01-12269053902-6960.xlsmxlsm 78692618c12acca00b6da84e155086145c3d8140bf9bbfa308510e77da32c4d7n/a Heodo
2022-01-120779918_900882.xlsmxlsm 4bdfc4d2f6481a25fe90516f5ec9235465fb26cb61e9099697c9c99002c9fd3cn/a Heodo
2022-01-121269054-720254.xlsmxlsm 1703b3ed61314b55df26556fb39593560397c5da3dd952dba8f721744e14e1afn/a Heodo
2022-01-12821571656.xlsmxlsm e4bebb2f41877a97053567aa24786042517b6086b8adddef55939fad19cd0b71n/a Heodo