URLhaus Database

You are currently viewing the URLhaus database entry for https://graniteprint.co.uk/derivedness/rjptc_24531/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1975390
URL: https://graniteprint.co.uk/derivedness/rjptc_24531/?i=1
URL Status:Offline
Host: graniteprint.co.uk
Date added:2022-01-14 00:49:04 UTC
Last online:2022-01-18 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-14 00:50:08 UTC to abuse{at}fastly[dot]com)
Takedown time:4 days, 19 hours, 44 minutes Bad (down since 2022-01-18 20:34:15 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-15325759122991.xlsmxlsm 1f2fb274efe18ae6707db44fd5e92e99c9da494530658002e2443435536ad260Virustotal results 35.48% Heodo
2022-01-15MRMMK-06674.xlsmxlsm c58ec0360d977c3351cf691b6f778bff30e6392de98f919995bbfa8b77712bdbVirustotal results 34.92% Heodo
2022-01-14u1.xlsmxlsm 2c1629903649cbcf3b885c468c648e7b9caad9bce1bad13edf832b78d8e98d96n/aHeodo
2022-01-14SPB_2405359.xlsmxlsm 906b4cdc24cc6fdb0b681efca20e463defabc36d49ecf5e082c3dd4b68ada68aVirustotal results 37.10% Heodo
2022-01-14066365_05076314.xlsmxlsm 62b760a1bce4550241c1287ef18a547bafb9d2ea5ac31d67e61e2625321ac359n/a Heodo
2022-01-1455966377012.xlsmxlsm e4789d37fc052b9ccb7af72cfe30d0c26d4567dc3c55f9c1436db541d1e09e12n/a Heodo
2022-01-14UT_3537.xlsmxlsm c95f568471e97a600183f2a71c62c8c16c86552989bf03e2e1b9104282700689n/a Heodo
2022-01-147093804-470409.xlsmxlsm 518ada94017758d7fc52e229e1470a4b5285da78a90d748232462647e910104cVirustotal results 34.92% 
2022-01-14GG_6625.xlsmxlsm fb51ebfd72054de8cbd7f74a05ce8d3cce650a9224c21504077cce9e86ae6fd1n/a Heodo
2022-01-1463753093_16.xlsmxlsm c51b53b80e46faa2609fc03aa38720a82a939a25e4999abdd30b94a915ddc24cVirustotal results 32.20% Heodo
2022-01-14uwwkifs_6030.xlsmxlsm 60373a2b7942416a3047d1724d055f1383105920170390683cf2e74aea7d632dn/a 
2022-01-14MUv_6243.xlsmxlsm ca10d23a4990ebac124b1dda44768d00c6592d955ed3ed5814954a99c9f8f5d8n/a Heodo
2022-01-14FIE9285991.xlsmxlsm 684179a59ccb9a4240a2cb91d8dcc96b15c6aa79eb8a928080a253684d3c2b2cn/a Heodo
2022-01-14347_68.xlsmxlsm 240d9c912338f39fde436264a56a9b48ded82608f23ae5f4a8f732110c2b30a2Virustotal results 33.87% Heodo
2022-01-14SM-2.xlsmxlsm 4388bfb3d3bd1ca9b1fc3350e1a4b12fa5eb80e25003b4cf503e7613279e4aceVirustotal results 30.16% Heodo
2022-01-1481645882072539.xlsmxlsm 31880b7b69938b12824c65ef7240304c054a61f2c4e62b7f596cafbad8b63eben/a Heodo
2022-01-147734_054341212.xlsmxlsm 93797babbd39191ec7414750b549df061089d4b224c2465baa56820ed3583b66Virustotal results 29.51% Heodo
2022-01-14XZPUH-5014.xlsmxlsm a89097e556d8e582deba3d9f6c471d585cd8ea41cf7e40480f967985ed90e60dVirustotal results 31.75% 
2022-01-14AD68228.xlsmxlsm 19da7acace7648f617cc949600d423f00148861c9f82b7eaf35c2487033bd905Virustotal results 26.98% 
2022-01-1452201756686.xlsmxlsm a49399789b01cd98a86c1e039af45a87a2c9ec07d14956bb189152912239bc4cVirustotal results 27.42% 
2022-01-147848630050.xlsmxlsm 0e2db8bad325d450826ee98740532c44b36d70a95f31178c85a50f4e8ee9c8b0n/a Heodo
2022-01-14VLTZ74678483.xlsmxlsm 5388d17d28ba671fbe8a27779a4ff0a97c15a00c1a91e946824b81b38c6d8e90Virustotal results 25.40% Heodo
2022-01-1490051331DBCRLKDR-62.xlsmxlsm 6865b7a1dc0601641ca16e96af174f9dfceb18c137e19db1801def5dccb3b79cn/a