URLhaus Database

You are currently viewing the URLhaus database entry for http://soundcoolgist.com/dcvuxobs/zGedl/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1991864
URL: http://soundcoolgist.com/dcvuxobs/zGedl/?i=1
URL Status:Offline
Host: soundcoolgist.com
Date added:2022-01-20 08:57:06 UTC
Last online:2022-01-20 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 08:58:14 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:10 hours, 45 minutes Good (down since 2022-01-20 19:43:53 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-2043900389614192.xlsxls 23dc54d35406a09e9c7ebc21aed24c81434f62784b5a94ff6b762b39008d3a05Virustotal results 17.24%Heodo
2022-01-2089011914121194831.xlsxls ad511015e8c542a03954c1be8721ddcce85dbe997f7b2048bc6e1b35823c5ffcn/aHeodo
2022-01-203849234805482950967.xlsxls 4e012706695112b7e19ba7cb073f14b4858bbe382890106a21cadf220bcd050fVirustotal results 27.12%Heodo
2022-01-2073501631133.xlsxls da9d3b84063bde0697546e7a9b3e2ab5f8283698dfb032f76018f28b367146f4n/aHeodo
2022-01-2055224849333770266.xlsxls 48645d321856636203f209613f50ae87684d0e12bae3421baf88c25657717abbVirustotal results 27.59%Heodo
2022-01-202164062664069.xlsxls d507a6a85d0f208c8662e6cde4d1bd419daefd9b5644146e4a51546fa37131abVirustotal results 24.14% Heodo
2022-01-20441771339967290.xlsxls 4627d88cb27d885555625326c40717630dbfc7708869fdde4d0064f2d59e5bb4n/aHeodo
2022-01-2041151542386959259.xlsxls d16d836fa1d7bcd99b7a2b65ca2d4deb2a54b552ecac9141c735e793c23a2a3fn/a Heodo
2022-01-20079374553178.xlsxls a38227249265731f1e9195e22b2ba517aade08d43d5a67117592cf0a5f8c3b9bVirustotal results 24.14% Heodo
2022-01-200733849067.xlsxls 92f65a0fe643c1d601633944790e1263b9dc30881b77636627c624581aac4acbn/a Heodo
2022-01-207168973950.xlsxls b7c12da037688c432bf94d80c88811b29b1a4d379a84ff3d6e6ac95eecf15680Virustotal results 25.86%Heodo
2022-01-203285433321585828643.xlsxls 2307899d29ea25d1c7dfcda009141119f8247bf367616d522944a4f1c81f3138Virustotal results 22.03%Heodo
2022-01-20969653521328369.xlsxls b24ab935f6d7ae64a036e919f70a63590db56ebd6dea1660d89827851be32e93Virustotal results 20.69% Heodo
2022-01-20303975456287362064.xlsxls a3182153bbc02b08e54fa468a6a470ede9822cc612dfd6c8f523b9cb5cd4984en/aHeodo
2022-01-2067832349632410297.xlsxls c964bd44cc4dfa14cdab694d620128715a62156b83e9aeb8496b88228937afbaVirustotal results 20.69% Heodo
2022-01-203186407467801.xlsxls 6bbb5397ac0522358d1f79729993bb746eed8844ad3a4ebae8f4baafb29a1285n/a Heodo
2022-01-2070634401211336562031.xlsxls ee212ba040e6857e56a3e2e8be38c52d0501f8a315b6c9599c63aa1490cd5ac3Virustotal results 25.42%Heodo
2022-01-2067958643185606407140.xlsxls bfb6705f630bdd22900dbc04de2805a63b70dd5b36a8985087a1d4be51308fd9n/a SilentBuilder
2022-01-206237018381171299.xlsxls 0a20a1b82fd605aaca4441f2be6c35ce6d486d0a55de5efda00150db78b3e6d4n/aHeodo
2022-01-201653695646.xlsxls 5c8cb7136b7f89772e79c0a2f6ead69434dbd7cd66ed030ca620de279c9b20a2Virustotal results 18.64%Heodo
2022-01-20430888452693.xlsxls b8da4b3b5705e6c881a49b0e94bf1a9592bd260de46a435d0c07a401e295e0e0n/a Heodo
2022-01-203949301720.xlsxls f8746c0e7d492357a8f30e424870c4fce49699d165260610a62360668541035aVirustotal results 20.34%Heodo
2022-01-201554623372714052107.xlsxls da70bf56ce1781f9fcaf72fbe0a6a7c24d6d3ac5595d1274204f636b738a6de9n/a Heodo
2022-01-2089852303700751.xlsxls 32e843c35f0b39a4ff9d669a80da88322cdd4206caa24710e7fbe60db710597fVirustotal results 16.95% Heodo
2022-01-20638692516037902608.xlsxls 22948141e8f020d01dbd92abd0eeacb3eb1d69fcf145fee4b65cdc395d309a57n/aHeodo
2022-01-208135999216.xlsxls fcf5fda3ac792863157c2b73fae2d1cd422d34220bd7ad41dcf76d7102cb93d8n/a Heodo
2022-01-2015774318437219277223.xlsxls 9abfbf06900053672f9e159b4c57db0807dc5a3d5816702f17c5b07fe83370d0n/aHeodo
2022-01-208968819406222894601.xlsxls 54afab7495df32a4992bbf3b49a156d0701358881ff8c996345fa6788a80d789n/a Heodo
2022-01-205216925756009455.xlsxls a99f7de860cfb66f3f1a0778792b72358d2565902f648d7ad68017ef40b8b804n/a Heodo
2022-01-2093888268998041366420.xlsxls 2b7fb1d9849ed25b33a5d477c71965b5ff31bfbf98d5892d510caf3eb0de221dVirustotal results 33.90% Heodo
2022-01-204180836293062548880.xlsxls 5465205536141902913bb0d169eedee0298e12bad0351a8bfd13972224991675Virustotal results 18.64% Heodo
2022-01-20812461879617547118.xlsxls bcd8ed1268cd0c50c33f2cf7065c26dcaeb1efcaf2604008895f84c94e9d3c2fn/a Heodo
2022-01-2043450727859577193244.xlsxls a94875a62546e0ff04e0a0ff648b48bc6ad7071b539a8d41c8d1176ce4e1252bn/aHeodo
2022-01-20664963735035114.xlsxls 586e224b3318cab7302593d796161ac68658fde8b22259b5d2151438239e566fn/aHeodo
2022-01-2097648243799.xlsxls 54e9647bc352365f2a744bb950f492198b196b2a592f2dcb53ce20160eab25b8Virustotal results 37.93% Heodo
2022-01-2041991910765382.xlsxls 248036930165cb013a8e2478890a6a70a4e4ff3d2b014d9e92c06ce590a0b029n/a Heodo
2022-01-207142212278007.xlsxls 4102ee23d580a34ad9a1790ea81e7d9739cae27b843165e0daa30b9450585db4Virustotal results 23.73% Heodo
2022-01-20673729215696987.xlsxls 5ca0d333916a14824f0434d5c88430e1f929f2ada4da94f2b1aa4deaa262d132Virustotal results 14.29%SilentBuilder
2022-01-204679828106455.xlsxls 5d627dc856dc8c64aa75c80ce9a8df74e8c5e7d08d280cf5b7f47bd6b5f8aab5Virustotal results 34.48% Heodo
2022-01-20712557342524833073.xlsxls 13eaf2acd17c26f3590753935f2733b116f0e2bf68ea6994b2a434df4c72e838Virustotal results 14.04% Heodo