URLhaus Database

You are currently viewing the URLhaus database entry for https://flybloom.uk/md1h8qxm/2Z/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1990693
URL: https://flybloom.uk/md1h8qxm/2Z/?i=1
URL Status:Offline
Host: flybloom.uk
Date added:2022-01-19 23:23:05 UTC
Last online:2022-01-20 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-19 23:24:35 UTC to abuse{at}cloudflare[dot]com)
Takedown time:15 hours, 35 minutes Good (down since 2022-01-20 15:00:24 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-204590594208390.xlsxls a1d4e9c497ec94e9c1182741b7096c47396c0057014747c17e618e82538eae72Virustotal results 17.31%Heodo
2022-01-206399917779685642.xlsxls ceafd90b9d8a1fa4ba9b8f81f1c3b138570c8768b75ac1ef0d3bb126cc6d497cn/aHeodo
2022-01-2088682607240245.xlsxls 6802d962671c5de15753c1ed53a75e0993691d66b44426226d8c24ad5b667664n/a Heodo
2022-01-20281741907750.xlsxls aec8e11077b3155936201e3011ee82bc5f9736383849d3070901ffc60cd62ca6n/a Heodo
2022-01-202933885327473882322.xlsxls 6b85f542b57e575c08c896ad4d70f32c8d93ed21af22407cf95e7db3005d5b60n/a Heodo
2022-01-20273820972108476449.xlsxls ef8562b363253996a0a2f5902bafc7d8f345d05e3bef28c3791c48e10d14c78bn/a Heodo
2022-01-20712435075807011.xlsxls 042d4b59153d75848595e19536f77437dcb1a52e851dfa507596159c99c74adcn/a Heodo
2022-01-2034962253583.xlsxls 1cf09e78181661d05a2e9e41e578ec23bfc41f6cad88f9cccff741d12df4c570n/a Heodo
2022-01-20994267570523551347.xlsxls 93e3c367bda53786b1288bbbcf96770a8865d3b8a3132a90a33d10bc91a31009n/a Heodo
2022-01-2095366695599690.xlsxls 1a19e1b7b3ea831480dc76486dc3692a3231826c231f08c81898d6aeb508ff71n/a Heodo
2022-01-20257646747635.xlsxls f43c7941272a2ffa5252dd03a62fcf67ebcedb4eeefb62b83e282df408cbd899n/a Heodo
2022-01-200299574787.xlsxls 5ec87a479b9e5146659d31735fb5623b0228ae859bb32ea019a465d85aa76950n/a Heodo
2022-01-2084554584637.xlsxls 980229215a4a60f739f9ef51f351e1ccdd055d509f62df8354277db46af45319n/a Heodo
2022-01-2067107552655046791672.xlsxls 9e2f1d0f201f452c51c21d9e00eb6cffc3bbe14d90c4adbf799577dd71c296cfn/a Heodo
2022-01-207525619778191619.xlsxls 8abb9df7dbb7c37ef4298c320074b668493d97486fa893ed0ef7c33001f20966Virustotal results 18.18% Heodo
2022-01-201295086507926448.xlsxls 9a67d9ce62f5eaabb79400048ed2c8864f20c79663f0f7c0f3a237ed3c8495ddn/a Heodo
2022-01-209710243718521876.xlsxls ffedad564b619c6e6c73bb544d8916e3b58ca40a11c2f97cbefb2fd742c43fe3n/a Heodo
2022-01-20748135304632.xlsxls 705b278aadff8692a2c128dd1a898d737e72e423aac2878595046d1d72dc9a03n/a Heodo
2022-01-203544588698188.xlsxls 1721d1176db895601d861e05ef2ca153746eb52ebe309bddf537b2bd9e539b3fn/a Heodo
2022-01-20419174144720639.xlsxls 5d4e5e94d71f8cd829e79c8b158960ddbb53203dcb8d5228373a924964985fc2n/a SilentBuilder
2022-01-2077458610662.xlsxls 76f8c0c2b92b7b85aa7ef66bd57dc746f07630eb13fbea8ec29b5115701d68d0n/a SilentBuilder
2022-01-20693805549992770797.xlsxls 06be4ce3aeae146a062b983ce21dd42b08cba908a69958729e758bc41836735cVirustotal results 27.12%SilentBuilder
2022-01-20811275654085637.xlsxls bdc735ff6181cafca367001ce29ddc5389cfdfd6c2f12957415231a74215f525n/a Heodo
2022-01-19221089278988.xlsxls 71218d4b13d7c5ab1cd1583b1646b4e495f88b8acedb0376a89e02a11354d674n/a Heodo
2022-01-1966511746269849.xlsxls 6b3e355a49db68b7601915ef40cd22d3647bf8316e43a2ec51ee375fce85339en/a Heodo
2022-01-19426704948776279.xlsxls 1b56b512e143bf588017e0ef26bea37c85688b638e6b4aa2ca0d7a443ecf95ben/a Heodo