URLhaus Database

You are currently viewing the URLhaus database entry for https://megabyte-xtnegocios.com/ys3v1clw/Yin8itky5MZ3RLARSVO2b/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1986189
URL: https://megabyte-xtnegocios.com/ys3v1clw/Yin8itky5MZ3RLARSVO2b/?i=1
URL Status:Offline
Host: megabyte-xtnegocios.com
Date added:2022-01-18 11:35:05 UTC
Last online:2022-01-18 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-18 11:36:27 UTC to abuse{at}cloudflare[dot]com)
Takedown time:3 hours, 12 minutes Good (down since 2022-01-18 14:48:50 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-18628180163434.xlsxls b9810a3ef7017dc112cfcc5135ce71644e58ec3b5dbd596f2110d2dfb339502en/a Heodo
2022-01-18717951820957880991.xlsxls 4b5e1f6a6cc6ea2d649a5e3cc210effc33b1804e7a4931d4b0696af2ff98db29n/a Heodo
2022-01-181073534212.xlsxls 7f8c95e3849529c50f1972686ebd92fbc0223cbd1df540b3f68ed40894ecaaf9n/a Heodo
2022-01-1800689441566.xlsxls 8808bca9d3fe1c1b081455e20513352831ddfbe9b65a42171b8754c2d8931e97n/a Heodo
2022-01-187095578938396.xlsxls 895e52ebe7c38eec3e599f404e671b1821baab608ba0050d1883f77fc229cc69n/a Heodo
2022-01-18446774933246160.xlsxls e5f7c1f04f9057742b40ff1383040d2326c9cb981cdeb9ccebec4c9467fdece2n/a Heodo
2022-01-185501539904254752580.xlsxls 101b1f39ef9ce95753101c8136cc17b7f2c9cddcfc535b86b5db4170d1557036Virustotal results 32.76% Heodo
2022-01-1844644754271.xlsxls 94214a74bb0158fd575aef28c69f335fd6c001fc1d1e015437e278387ef5470dn/a SilentBuilder
2022-01-18541135037605232.xlsxls ae53d5b866d7e49a50c7620025cf11206801dc9d981011954214750e10867083n/a SilentBuilder
2022-01-180698586519018086.xlsxls cef1611e425ccba10f308525ec2de771c18c7aac31a584676ad804905bacebddn/aHeodo
2022-01-183478155345858532.xlsxls 21750a942c925484d6e4e5fa44b8e8d795dcda94557066150d3f6a03e567d98eVirustotal results 18.87%Heodo
2022-01-1801077467611702016930.xlsxls a58631457908cd701a6f63570e99aff8a1eaf4e7b164d087ee2b195681ededfen/a Heodo
2022-01-1831927699224462.xlsxls 14584a4907e1d5ffe9c5af416ba27019f14c9e19cc678b988b940a8f644e5f76n/a Heodo
2022-01-18860419830708866630.xlsxls ec6598c3ce18e5a26c6455730f05ad506f69950eb70e28f35b212b60cf071f6cVirustotal results 25.00%SilentBuilder