URLhaus Database

You are currently viewing the URLhaus database entry for http://behaviouralworkshop.com/msuvpkl/694NGFUVO-7/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1971380
URL: http://behaviouralworkshop.com/msuvpkl/694NGFUVO-7/?i=1
URL Status:Offline
Host: behaviouralworkshop.com
Date added:2022-01-12 17:54:05 UTC
Last online:2022-03-23 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2022-01-12 17:55:08 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:2 months, 9 days, 16 hours, 10 minutes Bad (down since 2022-03-23 10:05:35 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-13O_448.xlsmxlsm e2053410b37647f1f7e190f99174fbe37bf5833edbc9801319f4443e1478eb7cVirustotal results 30.65% Heodo
2022-01-1348804010.xlsmxlsm 55831e6466e727c6dc0efc619eefaf7ff2a89d4ccb2f770e34aa49cd4a9894b9n/a Heodo
2022-01-13TXB_27.xlsmxlsm dc8adc8e13d3e5a64f2d69f2163da90a19cd80594bf4db6b8d17c381312d28b6Virustotal results 30.00% Heodo
2022-01-13UZPW07558.xlsmxlsm 22a61ad6c9715296ffe0d288650cadff57697c93c047bb60ee8feb45820cac07Virustotal results 32.79% 
2022-01-13OD_6090.xlsmxlsm 304e17c2ef41373d5b2ded923de19336a227658abf49881fe446df0cfcfac00bVirustotal results 30.65% 
2022-01-1373317_4197408.xlsmxlsm f2c2b34b3d0b8b5e85cfecf0bb20d225e589c18841538e9283f91302bb27bde3n/a Heodo
2022-01-13YA_67.xlsmxlsm 132b4dea20861342b68e5c2485ade61c87962f5b17c8c73c2235a75110fd2104n/a Heodo
2022-01-130386320-102.xlsmxlsm febd9978510715acb1f4bb87d04412fb1e3e6e2720329590b6b146de515d2d85n/a 
2022-01-13nw_68.xlsmxlsm f1d5904d51c4f979acbd63d484b167b8cfe3b6476c70a47a80f22399c27253b6n/a Heodo
2022-01-1336220179305.xlsmxlsm 97a28f39e64f29aa43aaaea8797e145ccc300757164905ee08775c079f7f68acn/a Heodo
2022-01-13W-400.xlsmxlsm 6452605acbfd7439e825e954124dd53046c5f148daad80558e64ccf1887a2ccfn/a 
2022-01-1320400_34.xlsmxlsm b19bc21f8451f79c07538d17976a4e7881e2046722f28008cf12c70034478b8en/a Heodo
2022-01-138063_96231225.xlsmxlsm 650bbdbc87791034d76982f257174ba4504b95273cc4b6f2abaa4e361cb190e7Virustotal results 30.16% Heodo
2022-01-135729701.xlsmxlsm 772971a6b4223ed654648f6e79e34133c55e788e60337e0ac7c29b53592adf17n/a Heodo
2022-01-13NDK_75475.xlsmxlsm ec54edb8fa77d810e6deba4e6105fe4fa06c193915fbe03ddad082f3e24da369n/a Heodo
2022-01-13565820277.xlsmxlsm eb9fbf10b29d11bb18b47f49d8ba8ff07ffe92024f4daeee6d420c96bba7e8fdVirustotal results 26.98% Heodo
2022-01-13U-06.xlsmxlsm 48d8ba8e0832a4ee318f4fb4653345ed1d8e48e2bd90b55648e18d541e534d92n/a Heodo
2022-01-13xvL719055.xlsmxlsm a64b918b227ae002b52f8ca07c1e57fbf11e0f6a0c5a06abbf79e2b209bce48bVirustotal results 22.22% Heodo
2022-01-13909921XESZPR_984.xlsmxlsm 13f975538e7e72ac755218c6a35604d36e0278e74fed8e2270476b89268a7f2cVirustotal results 23.33% Heodo
2022-01-132774-693.xlsmxlsm 9e443aedd2833d67bb9b858bd14abc6a235186f865e05497ac39ab8cd0185156n/a Heodo
2022-01-13MIH672106.xlsmxlsm d32a60905cbcf3b82765d7291ede8777aa420c096699a8f848d3417e53158346n/a Heodo
2022-01-12C_6966.xlsmxlsm 57dd75934f8e97adf3ea865291bb9766cae096c65aa55bcf8df2ff2325779fa1Virustotal results 14.75% Heodo
2022-01-127529-010.xlsmxlsm 7a42c12bcce014e382336c9ed46aa93e6f6c6573b7fec7e5d3ef6dedf721383aVirustotal results 17.46%Heodo
2022-01-129875538-103120.xlsmxlsm c57fd2c02c895b4ae7bfd0dccf3721e4c979b931c8f1215e168678ce2c11b641n/aHeodo
2022-01-12063513630_63016200.xlsmxlsm 513bc7378d724e7a7c4cfb48291919fdfa001bb5e07b6cf06fc33c19055e057aVirustotal results 17.74% Heodo