URLhaus Database

You are currently viewing the URLhaus database entry for https://skcyber.xyz/usvz/Qgi6SZdFQx6IqhJXMvrYptk/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1987189
URL: https://skcyber.xyz/usvz/Qgi6SZdFQx6IqhJXMvrYptk/?i=1
URL Status:Offline
Host: skcyber.xyz
Date added:2022-01-18 18:58:08 UTC
Last online:2022-01-21 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-18 18:59:09 UTC to abuse{at}cloudflare[dot]com)
Takedown time:3 days, 0 hours, 38 minutes Bad (down since 2022-01-21 19:37:28 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1943812417260001943.xlsxls ae57b4a117312a993a66c2ec3d0f5f7d3d59ad1eae97708ac82eaef859f732e2n/a Heodo
2022-01-195727646126520248722.xlsxls 54c4606892b1fede80e10591041b980262e6a780b2017de3ce6779d96d862a44Virustotal results 20.34%SilentBuilder
2022-01-19650316079865.xlsxls c425b918e6144021b603d7713891f953c90f3fe0b724c2fd15767e577edb7ba0n/a Heodo
2022-01-1913934514451481.xlsxls ed228873fb44f8cc68edada7c0687dfda287a3ae45fb0c0cb6cf8a58bb2487fcVirustotal results 18.64% Heodo
2022-01-199090916733758252.xlsxls 6d56c4a60ec2d451673ce2ce76e1fd89e23fa89a05c872736d78e15020cabe71Virustotal results 20.34% Heodo
2022-01-1921055648850.xlsxls d26f4a2809e92686fcb04d7e6662638fb1da0e2e7d7dd7057ef7931d1c36f4d3n/aHeodo
2022-01-1928752772072.xlsxls f8746c0e7d492357a8f30e424870c4fce49699d165260610a62360668541035an/aHeodo
2022-01-19782632795191057403.xlsxls 2973cc99c73795a2e3a00ef11ea792c3800f933fc073fe670d2907261f6c965cVirustotal results 18.64% Heodo
2022-01-19404844355990.xlsxls 14817a3b02e6cb0a22fd6b251c612d2f21ba516c03224741e3ddc24755c424deVirustotal results 17.24%Heodo
2022-01-194800973148.xlsxls 536fe29b4002bc97dbdb4f89a409168dd8f4166ef7a9d857252fd6e82be07950Virustotal results 17.31% Heodo
2022-01-1990134244350884.xlsxls b9c54b000f35aba6a914ba40e2eccbaf4ff2193a5f5f657e47173a4d11659728n/a Heodo
2022-01-19073785274986738.xlsxls 7bcc81bd2ed657103d32c3786d4ed067a429f084675d83b1a7b4517c48680820n/aHeodo
2022-01-1931705541970986573864.xlsxls b8e79d6d4ce2e23e9b126c3397150be331952bae520caad6039e7dfd048c83f3n/a Heodo
2022-01-19352765724197755910.xlsxls 06f81a0439de4a88bddf3371586a0d0594bfb213bb35e9b00f300d012e4e2691n/a Heodo
2022-01-1922788892341109484.xlsxls 9395907b748740960ac38d3ba4faeb6248b7953da69f834daff192bb2ff1fff6n/aHeodo
2022-01-197133367256.xlsxls 08326159f288918480978f4ca2d0a705037a18c23e58f779f9bb3bd9fdde6d75n/a SilentBuilder
2022-01-19886180392519835.xlsxls e65457b2422f5bf91f36b2f1a6d12469325b7b580d3d07262777b764230414f0n/a Heodo
2022-01-190052983282402960786.xlsxls 45436614d9baa751a6da8b87c9736389801dd8daab1a8f82d73aa96f644da316n/a Heodo
2022-01-1976306822567.xlsxls 4cd7a9573d00e7cf41a66b48f93031073ed5751a546dd851d52e805248aa3972n/aHeodo
2022-01-1929801070223.xlsxls 3340c74a1202b3e5f9516584a312c057b828436c35a06bbd7c3d0916e9a85289Virustotal results 18.64% Heodo
2022-01-1983689851620556.xlsxls 5b4c4e8767ddfa4938976a941711a1019fcd0f5a903d8a87e3f2bf316db2403en/a Heodo
2022-01-1942145534360.xlsxls 76faa078d1f1713f316cf3d152958b0db77d8e9255dd084d902b460fb3ea97cbn/aHeodo
2022-01-192968820550.xlsxls c48a780e4664704fea5ddb053288a405a134644cd21cf1b2a21050df56d28d94n/a Heodo
2022-01-193077379651952.xlsxls a1d4e9c497ec94e9c1182741b7096c47396c0057014747c17e618e82538eae72n/aHeodo
2022-01-1806685815376986.xlsxls 95141c557c2da97c647844e7c27133e0f8ba49907e167088ad774ed57e950294n/aSilentBuilder
2022-01-18475283294002890654.xlsxls a98a6b8d7f497c5ad84c185e896e92fb586634573f1fe358124f1c94e8fd3832n/a Heodo
2022-01-189501972343.xlsxls e1727c3aaa854ddf777f23d7783fa1a77d690ca625cfa0e70fa04bc42110728en/aHeodo
2022-01-1820762987697184.xlsxls 78556887acaa53925e57fcbc94e349fe95d1bace58bbb11d1c1b31869a1cf473n/a Heodo
2022-01-1890569986820367347737.xlsxls 8b706cc22fcb8aa3c6b477e0b9f7d605ff4d388f0488edd975457e663d7b1619n/a Heodo
2022-01-18389970965725.xlsxls 65e5fe051c4c5946140e3c7e3c25d2e9d06de1c8b6874baed4f8b470f5336663n/a Heodo
2022-01-1847690452719009140138.xlsxls 0d50ffd3103edd65a1f5c3e63bd2eb0a62762d9803760a0d652b1cc3c2b8ed2fn/a Heodo
2022-01-18601079031613.xlsxls c574b36b0e6bed4b835f678fd2eb93d1e6d918bece963a09ce037111a74dc78fn/a Heodo
2022-01-18893373525643652.xlsxls d604a9cdcad6118bf0ac1b221ff136cb18aba927259f9545e79572b995d03406n/a Heodo
2022-01-18859185316213168.xlsxls 70ef89d31d042c8ecf674744c98b367d068cb668b2f5b4ea1ebb025e9034a280n/a Heodo