URLhaus Database

You are currently viewing the URLhaus database entry for http://thetorchbistro.yacstatic.com/assets/x08v/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1991862
URL: http://thetorchbistro.yacstatic.com/assets/x08v/?i=1
URL Status:Offline
Host: thetorchbistro.yacstatic.com
Date added:2022-01-20 08:57:04 UTC
Last online:2022-01-21 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 08:58:11 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 day, 6 hours, 32 minutes Poor (down since 2022-01-21 15:30:57 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-212052948787.xlsxls c60a6861fc63f90b9f872e0bc131fa85f6af0daef37063eadf6d10890acf3bc0Virustotal results 38.33% Heodo
2022-01-211798260384408.xlsxls aa41c47fd919bc06f4b17ea69e649032b5a995e04b81a34dafbb3f0e4e5f1e43n/a Heodo
2022-01-20087419865780213.xlsxls 48fee052f0fa5361ddc892d4768321a00e5c80adabc60654488ea8fc1ffa135fVirustotal results 22.41%Heodo
2022-01-20143478149421929272.xlsxls 0450c09d5fe3db81273bb016f057664f805ea0dde2c1c53ad512324c191ac2a5n/a Heodo
2022-01-2061714683399.xlsxls 8a07b30e84df7c4db85691e055e4f39fb78621392b7a282b3b64d13a675e14b1n/a Heodo
2022-01-200354458040418956.xlsxls 1d51a274899e8d9f5f0d731c91c8308a7437c80c22a0d67f92aa4ed958175e85Virustotal results 22.03%Heodo
2022-01-2005407852332450521.xlsxls e33811b4dab432d10d50a8357ec88ab255590ac412e6a386ae3cee55c40df20en/a Heodo
2022-01-205630755081384933.xlsxls caa57a0d7208775ee50b80b88384a83804e8b132229162b88db9a3a57abb7acbn/aHeodo
2022-01-20936065816945.xlsxls 54c4606892b1fede80e10591041b980262e6a780b2017de3ce6779d96d862a44Virustotal results 20.34%SilentBuilder
2022-01-204809374694537471666.xlsxls 325659ef6619e8c64629ed81b4155895f88d729382090dbd83d2ca5f2633c517Virustotal results 37.29% Heodo
2022-01-20781357664242.xlsxls b3bbe5c6707c4ecdaab7fb309fd2df58247cfcc4208d3dd5c3570171de51a660Virustotal results 37.29%Heodo
2022-01-204538410698334450.xlsxls 3340c74a1202b3e5f9516584a312c057b828436c35a06bbd7c3d0916e9a85289Virustotal results 18.64% Heodo
2022-01-204018232624521.xlsxls b3f61c413300fc14e38b6ca08af0658891e70a469784a8302a46e5f0a7d91daaVirustotal results 20.34% SilentBuilder
2022-01-2044151530397.xlsxls 8a2c9b82fbe5614656c4cfd78937ba81ecf63e497ed0b3ec2280f38567c6eb51n/a Heodo
2022-01-204699306276.xlsxls 8dbb2081a977b17fb9eeccef92e75765fd2d58c871f2e1af3f39ae5336e6b177n/a Heodo
2022-01-206021612136836834189.xlsxls 6a6f651206b84c84359bb5fe1dd08c81bd05b35d8f6d9c528ee594774373c259n/a Heodo