URLhaus Database

You are currently viewing the URLhaus database entry for http://nt.welcome-to.com/b/RG2/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1990501
URL: http://nt.welcome-to.com/b/RG2/?i=1
URL Status:Offline
Host: nt.welcome-to.com
Date added:2022-01-19 22:01:10 UTC
Last online:2022-02-17 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-11 08:15:07 UTC to abuse{at}amazonaws[dot]com)
Takedown time:1 month, 25 days, 8 hours, 31 minutes Bad (down since 2022-03-16 06:34:31 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-20WK6693249.xlsmxlsm 46dadb348869cda14d38466d791ebf6c906f5ec26cc305fdca50921785f48b20Virustotal results 23.81% Heodo
2022-01-2069673_25253.xlsmxlsm 6b010b591c50b68c8101ed6ffe62e903c6501ae17d1b430a904288c1391d4482Virustotal results 24.19% Heodo
2022-01-2086613799_711186.xlsmxlsm 5eb512924e585833ee9f0111efd74c3e3ced26d8a78db2b71d87bb6c9f684791n/a Heodo
2022-01-20NNM_53649304.xlsmxlsm f3af1bae6675bb7eff796079a60c5a67ec86892f1c09053d2c25fe7d9fcee836n/a Heodo
2022-01-2070006413-4925.xlsmxlsm b1551887350e6e3d73f1d159a97f121cdb3d5b3d9f151de703c313f247958248Virustotal results 24.19% Heodo
2022-01-20619360-5.xlsmxlsm f3f1542a86bb2d668046714e3987278506d3308023b1cb398efa9573d2da7776Virustotal results 22.58% Heodo
2022-01-20hr_872407947.xlsmxlsm 1bccdaed8a9d03e7c5a5f0ecd9ca25e942077d1be538087e6451cc3030e37b8dn/a Heodo
2022-01-2069620113887772175.xlsmxlsm 7429c9e25f9d5b509f78af97a0f595fac9ce8122ad4788c17087360e06521b2fn/a Heodo
2022-01-20TVUPC_25020.xlsmxlsm f48ce531d75c5080dd92c721b92678a75a2be77b9c53d1a33d5539c695d1e614Virustotal results 23.81% Heodo
2022-01-2040768235-71806.xlsmxlsm 8ca261137fec414bb9066e12a3b88f3872e87a71d57134c1ee8331a7c0590965Virustotal results 22.58% Heodo
2022-01-20wqiucm_1.xlsmxlsm 47b55d5918804812bdc25923b93b4d42f3f5fb005f755266aba09ace6d636e20n/aHeodo
2022-01-20etxh_69976431.xlsmxlsm 54dd7b43faf6af4521533712663354a19b6793199ff1fd6b355828448b1cce66Virustotal results 27.42% Heodo
2022-01-20H_15.xlsmxlsm 7805fd902552d2c362cec5d35c3ab11be2ecd01d5932757e4f175b5f9d21ba1fVirustotal results 26.98% Heodo
2022-01-20414491816_7599.xlsmxlsm 619c3ee3590e414b2de3333ff07b4cb2df3c76fc7512468d4a6499833db70078Virustotal results 23.81% Heodo
2022-01-203416116-57129053.xlsmxlsm 88390a46879f6c9ff67152cbf22d1868e9edb89c0724e1e144a789c73f69b086Virustotal results 28.57% Heodo
2022-01-2067670_8213201.xlsmxlsm b888459d1357d67943ce5a794338519d4a543b73cf7a58339dba66c242a5973fVirustotal results 25.40% Heodo
2022-01-20s726693.xlsmxlsm 05aeb3fe4bd3f690ebe97d33014d66f3adc9e4a7517507d6df3be40dcbea26d4Virustotal results 26.98% Heodo
2022-01-20zp-66072181.xlsmxlsm bc7476f9d9148b939127a2024a1b341cec82fb398bf06667bdd3da4b1acc8bd2Virustotal results 29.03% Heodo
2022-01-20MPLWH-725119.xlsmxlsm 862b616752a3805737a27809a3d8d8fc317e9cec6e0148d0c402498ba211b7dbn/a Heodo
2022-01-203930_2266.xlsmxlsm 42eefcfe7fff0afcdc0bca565d1d1dd9cfaae1167d9d0a9ca49e0389d53ed46dn/a Heodo
2022-01-20068088-544557.xlsmxlsm 5abfcc35b24e7bfff1c0f6d09e2df83b993f9dcb0afc6226b7b9b9adb79c8a95Virustotal results 27.42% Heodo
2022-01-20C_651059504.xlsmxlsm d63cb63141af447b2bac52e24948f5d9b47036a98df5d352877f0dbb90f767dfVirustotal results 33.33% Heodo
2022-01-2062151232_0712610.xlsmxlsm cc6c720dbe0651cb2b617927ad0a5601915eeb6e7b07800617f78a9f0e8250f8Virustotal results 27.12% Heodo
2022-01-20DSO-355.xlsmxlsm 45ae174e0c5d865a0e1a2f1831df896eb8e6edd60b0505864baa9a2db811a536Virustotal results 26.98% Heodo
2022-01-202498ZVSQH-702405.xlsmxlsm 23b2b77659388fa5b454b87d59731166c71aab81f4073dcfd7cb25e0004f4ab6Virustotal results 25.40% Heodo
2022-01-2057616_04.xlsmxlsm e2d111de041c2bd5003a3be379f8c617e854516169debba317cab4168b92e38eVirustotal results 26.98% Heodo
2022-01-20049_667.xlsmxlsm 54e103034b729155182a2b22eff84ddaa16f5d3fa992d88b32d5202c1d1d2577Virustotal results 26.98% Heodo
2022-01-20WWZVN401.xlsmxlsm d3f4d5fc34a444c8ae251c04b1e12ad1371e72f9f7f5682c02e0339eb3fb6ba8Virustotal results 26.98% Heodo
2022-01-20D-54.xlsmxlsm dd2013ad0148de7b9a7877b7b27f3372c04615fb214c98f8a96d3d5dc80b03f5Virustotal results 30.65% Heodo
2022-01-209859_89150.xlsmxlsm 9761bc5de47973837988a9be7b5128db72f1817d53c224709b5b2c63848e47ddVirustotal results 26.98% Heodo
2022-01-209992211260.xlsmxlsm 39d40e8b39b2ded1846a5ac1aa2441a8bc1e11f4edf26d60f60d49862a3435bbVirustotal results 26.98% Heodo
2022-01-20ZUA2.xlsmxlsm 8866cd8ebac58f0fd038a21db8094be78be8577a1e3613be93fe9ff78388e192Virustotal results 25.40% Heodo
2022-01-207992373370.xlsmxlsm e4b4b4aeffb795fbbac1cd7bf7465c6fd98c0906401fdb3a90ecca0ce903b3c4n/aHeodo
2022-01-205884215_4094.xlsmxlsm a75d803a646fa5cfa41b0489c6de355e62319450b46d41792b4b5b3cd21a0dc3Virustotal results 29.03% Heodo
2022-01-206818791-46547.xlsmxlsm 4bd8c91634e67571e3d3ef12e97ec113895c366559309e1ed0cf9a18b196b787Virustotal results 26.98% Heodo
2022-01-20ZylNo71966824.xlsmxlsm fb18f3109867f5c66552ed2cb8f624bd0d7b882b0c68ede96f53782bde872794n/a Heodo
2022-01-208634_5702549.xlsmxlsm de0b33c3c71a43da9e30795f36c6e98ca85e1685853d66977dc5dd8cf228a667Virustotal results 28.57% Heodo
2022-01-207550_77467782.xlsmxlsm f48ab458724fad35a7456e9f640afa8c061c0b6bd04acbc9cb0d0dbb2f4d3202n/a Heodo
2022-01-20150LOOTLIUBAW5966338.xlsmxlsm 1b8a7503b95b685e1c29207ac2a9a9d75b188abfc9c492e670eb365377c1ad90n/a Heodo
2022-01-2054299DTUBQD98396984.xlsmxlsm 40b52631655bde48abffe4d280833b1b6019e1ab64d64762283108f4cbaa0c5fn/a Heodo
2022-01-20uxmjcj_4422.xlsmxlsm 7958e1bfaf69559731cb60fe11f9c580061f8a474f7b4223ebaa3bc795b433d2n/a Heodo
2022-01-20QJSQ_3.xlsmxlsm 7798bb812270c2c7736281585caab8c2f272c52405a7d2f9cf5da363192e9904Virustotal results 27.42%Heodo
2022-01-20AIT-81.xlsmxlsm 201992f1c56e9d2b5739e06dadff7d492feb7c3b7d35a68045369875a0b92257n/a Heodo
2022-01-2002604_21.xlsmxlsm 66f754fa0c762bb97ca72ff0da7ed505aced3d99925ab65efc7402ff27e56039Virustotal results 28.57% Heodo
2022-01-2019552586171.xlsmxlsm 3e1d8a58301390ec349624e2de43757253fc9bdcf31814236dcaa980a8875699Virustotal results 25.81% Heodo
2022-01-2025310815_13644507.xlsmxlsm 3b4c7690fa48369fdc9a684e697c5ba23a23d5e89955484364a79fc0e74c99den/a Heodo
2022-01-20382ZEHVJB_543.xlsmxlsm 46473d491bc661da90163ce5ed77341a80de9595296e65cacc351343a6b278d9n/a Heodo
2022-01-2095647717_957655.xlsmxlsm 645e264c2f657e1f901918767938090cbb4403348a8eb2a6c4eca245175dbd18n/a Heodo
2022-01-20B_023.xlsmxlsm 3429d6a8cfb23e471c568a683d16e627e3797bb2d27a1780d4f6ebfd739bf221n/a Heodo
2022-01-20DU4459.xlsmxlsm 45f519a4d390f4ba9d3185baec87cde107ac189f10bea414ed41d614f438209en/a Heodo
2022-01-20806261AVG3463.xlsmxlsm a36dff00e52206c1e50eafb43ef3969a7ad412cacac5aab83743b86b2c790483n/a Heodo
2022-01-20LGQ_4391268.xlsmxlsm 745d54c9957257622f8009a18c4ecf6d99a2f407ed5dd0cb211649fbfe4d2b90Virustotal results 27.87% Heodo
2022-01-2046168078-5382991.xlsmxlsm e812d0407be6f5f61d6266dd8eb193af17bb71f3cb34231e0758122f624bee44Virustotal results 25.81% Heodo
2022-01-20215325-04185050.xlsmxlsm dc538d8c326048d59dfae049619e3364ddc87ae4f9db61eaca4f2294fca2fca7n/a Heodo
2022-01-20etzblb_13691.xlsmxlsm 45236b922fe0452378bcbc300f48a2aae3cdd17a03fbb9411a36e6540e700086Virustotal results 28.57% Heodo
2022-01-202427127UUXUJT00990.xlsmxlsm a9e6bc506a460667e8a9355d2a6d3b0f32d89124cfa00034e83a314d8c955860Virustotal results 25.40% Heodo
2022-01-2063051975KMBUD-1.xlsmxlsm 950477a11af1110ac463d4cd3ffe9770d71810c8e74025df9992e848d9ecb74dn/a Heodo
2022-01-2020072153.xlsmxlsm 90efaa15b995bb08889711638b146f326ab1c46cdf557b0dff717746481184ccn/a Heodo
2022-01-20GZXRL_1.xlsmxlsm b9510c284bf2350a71ff66a248c97768d98b4e04146ade4a28fd9f1fab9137c3Virustotal results 28.57% Heodo
2022-01-19s-85.xlsmxlsm 6bf0a6ea26787e80034772f3e46ac98d7ce874d99213dbea144e9f2cf4892ef8n/a Heodo
2022-01-1998068875_554662.xlsmxlsm a6681bcaacbec6bccec6e70517b523ce00b73cd496cc3458b242fa7c8088edabn/a Heodo
2022-01-19R-8257.xlsmxlsm 97313991ad9bc5b9cfb36aa7eafd9afbf163fe97c7180ff29a23173331387e5eVirustotal results 25.81% Heodo
2022-01-1964545636_15.xlsmxlsm c3c36da69de48f38c2d39dc8a6675c4d397b745e01d5b8e9f314cf465fe849d8n/a Heodo
2022-01-1938750_1155.xlsmxlsm 2ef3416e562bce54a825d048a989566f6f14e3f396d453e6efab5664d6066b3bVirustotal results 27.87% Heodo
2022-01-1974_0315.xlsmxlsm 8f1383b4d7504257b4e3da2743e895eead15a36132d6bac13452a546fd20bbdbVirustotal results 28.57% Heodo
2022-01-1965576181-623996132.xlsmxlsm c3f53e74cbc71cf1956d17dae939c2d9f31a1c2e81328a3ca88ceb1e3bf652c0n/a Heodo
2022-01-191056174.xlsmxlsm 892cb5000c5657175c29ea88c181fd1c0ebe8ebce03702df7b7340973c0f52b6n/a Heodo