URLhaus Database

You are currently viewing the URLhaus database entry for http://drives.tims.se/78bac4t/qMozKSNwwVp4TUrXGUzD/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1991951
URL: http://drives.tims.se/78bac4t/qMozKSNwwVp4TUrXGUzD/?i=1
URL Status:Offline
Host: drives.tims.se
Date added:2022-01-20 09:21:04 UTC
Last online:2023-02-12 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 09:23:00 UTC to abuse{at}glesys[dot]se)
Takedown time:1 year, 0 month, 28 days, 13 hours, 53 minutes Bad (down since 2023-02-12 23:16:41 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-1206140241720.xlsxls 69cce5bc480fc153f2c2565e77466c707647cde2c2f03465d1116c6d970d7ce3Virustotal results 58.33%Heodo
2022-01-2013847255380650494084.xlsxls 0df848cc2bc73fd0f4456020fc3bb2eb4f0c6b517985517e24074c673e5baf76n/a Heodo
2022-01-205623049548.xlsxls 443ca1a5071583b1cff37d5392aeb4d1931ae06d63997f83378cec74d59ddc0bn/a Heodo
2022-01-208463715725.xlsxls cdf871cc0eaf2aae0ebb534c631ff0162e55729a63d5ef7683c896cbbcf344fbn/a SilentBuilder
2022-01-2087786932086802230252.xlsxls 02d34eba192ccf28ef85e8f2a8436593c3050cefdc1e41886baea63affa68d7fn/a SilentBuilder
2022-01-202682014118.xlsxls 0f450bafecb632b74ddccde54cd55f20a344d91a3ac5a6f031aa97113514716cn/a Heodo