URLhaus Database

You are currently viewing the URLhaus database entry for https://nz.welcome-to.com/liitbu/N18R9QR0vbTFtVnsB49Gj/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1992752
URL: https://nz.welcome-to.com/liitbu/N18R9QR0vbTFtVnsB49Gj/?i=1
URL Status:Offline
Host: nz.welcome-to.com
Date added:2022-01-20 14:07:06 UTC
Last online:2022-02-12 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-09 22:21:07 UTC to abuse{at}amazonaws[dot]com)
Takedown time:1 month, 24 days, 16 hours, 43 minutes Bad (down since 2022-03-16 06:51:51 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-21121142531936252045.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 36.67%Heodo
2022-01-21177241367860.xlsxls 3ca3bcd5771a06938cc8e8c44cd2c85b794376401b469fad7e5d4b513449fa27n/a Heodo
2022-01-2102479979962926463.xlsxls aba8e5024172cc0cd240eda2c379e91825cb922f0c5d56d82a560dcb15eef097n/a Heodo
2022-01-2183047561964504.xlsxls 2f51046242d3bd4fc8a58e9ee765707e09c8efbc4bd58b302262b181e9960bf1n/a Heodo
2022-01-21473972915713.xlsxls 8d11a955d5a1c9ef68952d7f5bfe36e84c201e60f9ec3033571bba32d20665ddn/a Heodo
2022-01-2112782958708290262.xlsxls ce8ed57f03c2c3733b81f29e38332753051c9d5917d62760190dbc6b9dcebf45n/aSilentBuilder
2022-01-214454474597949404547.xlsxls 29111d8e5e8306e76660db292e7232ab39e901955014eede21e912c931a09b5fn/aHeodo
2022-01-21980095177441798.xlsxls 595457287262641f193afae7ac66120029ef90f2ba59b310fce3d9335b1cf304Virustotal results 30.51% Heodo
2022-01-217560641977093381.xlsxls 2c9af469fcb89bb2e93d1ac70ce0bec912b78d5c3cbadccc3040c18dd03f5e41n/a Heodo
2022-01-21246518807530694.xlsxls 0e9d63baddd3ed98bd278e9eebbe7724934f24c1e6d98d9734fb88180dbe9d41n/a Heodo
2022-01-2191660175624338.xlsxls 13c3fec523cfe8ac14a7e78a8e2ca86dfd3b8bb8447eb7e733e7b1207de5bea6n/aHeodo
2022-01-210337497700012.xlsxls dac57112411305935ad4318c4ff4f495b8b39f84f001b64d83ea3ae69a994b02n/a Heodo
2022-01-212092617285684.xlsxls bcebf33c0812a0eb18e5261449f212582882eb706df65f5d2f2dd9d3b2c05da1n/aHeodo
2022-01-2102356643552.xlsxls aaec559a9461b2ceb6da5a557186641e67370e83fddc9b23237f6f92c0e22fc3n/aSilentBuilder
2022-01-2181634175597661985910.xlsxls 539a3855a176457a29262e61d738250050450a8a6adb2b1e9c8961a40a6cad57n/a Heodo
2022-01-2100408543801960.xlsxls 69b593eea6e0daa0631dd50e821d30622e6117fbb7e591c5e4b734722d6b5c4an/a Heodo
2022-01-216857129760180.xlsxls 21e23ea56b3d3198bc790c23569c989367c1907f23680e1760b7e76250e87549n/a Heodo
2022-01-21584015746002253838.xlsxls d84d60a9e9f466b7e002480fcc1866ca8824a44db59b31dfb9477d8ffb21c4cdn/a Heodo
2022-01-21781905325182034606.xlsxls 82dd39849f520450c56ac21901abda18f16d08294e0c9569e659ed9133781c7cn/a SilentBuilder
2022-01-21193868304344700.xlsxls eca323ddf5c863072e76cef170025ffcb611946ac3656f641ff0d2a0b17aa382n/a Heodo
2022-01-2176021977932731174872.xlsxls 262c6da8c94de82acce05fdf2a570305c71d940ea6c58416eb020eac64242c27n/a Heodo
2022-01-21060216271115677579.xlsxls 9fdb19b415f24dfd571c8289d1952dd827d1fb2a14e8776e495da67e5b38a176n/a Heodo
2022-01-21815905232029858.xlsxls 4520398e8aeabb1aed9cd4899a2ac014545d9ad9383959288cf2470f9c1c4731n/aHeodo
2022-01-210852758792608014720.xlsxls 8aa9a577a3bd2b2fb4b35339f5593a8a3f1c7635247b6fe78fbbb2983a8cdd4fn/a Heodo
2022-01-21020476226613065436.xlsxls 358e8e25ef848f0530a1b2094f471f68415b1b8f84cf21e6f9f1dbb774759140n/a SilentBuilder
2022-01-2188903821506631645766.xlsxls b056a3191538792998936cef580c7cd75e9b49d40a53452f6e8dd20d5814934en/a 
2022-01-2159605944927929.xlsxls 649143ea8e6ec1173106ac1bc3034951327ffc75a1d8324a1b80d280998e2fa2n/aHeodo
2022-01-2101978401379227125.xlsxls 9296f02a362c27b1e3a3b4119ede64ea52b6c0430fc70517e5146730c23c987dn/aHeodo
2022-01-206524354409819119.xlsxls 531278b90b12ac32bc7671c1f2a52ccc15afe992249b5dda28ae98885b954c99n/a Heodo
2022-01-2091828322576872702.xlsxls 8c1d4b99c5902b2f07b695625c439802eb241110c2f528604a333a18120266c4n/a Heodo
2022-01-203916747211365.xlsxls 79ab6a611483efd4c9e4394ac5c6a91c458857820c4c4b9bdecf0cab92acf8f2n/a Heodo
2022-01-204027056399.xlsxls c3782f393e6dca8cbded5a7bbb73789792cd1bf807f4f71cd863b12992beda95n/aHeodo
2022-01-201112491823672307.xlsxls a72795a18fa2b90928f307e227b1f1a57590672870b3acc9e8cb0eb4d38bdbffn/a Heodo
2022-01-20419012608118599.xlsxls 7758c1ef7b05f4e4e7e283eda2aba34801589c1ed656610c149a5b1a1a0b7fc3Virustotal results 22.03% Heodo
2022-01-202901583613623.xlsxls 8a39d34f5c3133db2f6137b02545e312f05bbdabceda4bd830948380fa4c98c7n/a Heodo
2022-01-20620216368984577332.xlsxls 3b63534dcaf71bdf8293d2a3ce3310a02d2eda37deac68d5ccbdc89cfbc8f408n/aHeodo
2022-01-209809244243.xlsxls 245057c2c16d698dc5399ecd43ca39f9e0b35885a19cc42cd2650eb8e17d0c00n/a Heodo
2022-01-201788536621231650.xlsxls 817f4c96e056390228a3d9ce57239ad521627a3617b13e4043dc99c91569ffccn/a Heodo
2022-01-204837395871.xlsxls 1d51a274899e8d9f5f0d731c91c8308a7437c80c22a0d67f92aa4ed958175e85Virustotal results 22.03%Heodo
2022-01-206211970000.xlsxls 8697b2c64ef08e5e4bd5ca43dd988dc5ab701d50fb022b74e7413b95a7dc7c02n/a Heodo
2022-01-208590775684.xlsxls 43a573dc9dd0dc79dcf228467e8e6820f4a4f8bf344660ea43eb11bb7b3c93f7Virustotal results 21.43%Heodo
2022-01-2032290124660949984329.xlsxls 4102ee23d580a34ad9a1790ea81e7d9739cae27b843165e0daa30b9450585db4Virustotal results 23.73% Heodo
2022-01-2057987035860480938889.xlsxls da9d3b84063bde0697546e7a9b3e2ab5f8283698dfb032f76018f28b367146f4Virustotal results 38.98%Heodo
2022-01-201400587375587521065.xlsxls 402b387ff9eaca12395e5ea30d7252c77d49ce1d1478784bdb329641136043ean/aHeodo
2022-01-20103305010362.xlsxls 0d3ad48559d571f0d260229669d7eb06fa1f724387f2389bd3e44a234c4d33fen/a Heodo
2022-01-2016805758595068460.xlsxls 7a01c853bc0724dd09208ce377a70f2959c37b14fd10bce9c0445437dbb57c6bn/a Heodo
2022-01-20070205471025954357.xlsxls 4e012706695112b7e19ba7cb073f14b4858bbe382890106a21cadf220bcd050fVirustotal results 27.12%Heodo
2022-01-2091999566465488468785.xlsxls 40dd74fb1fba55980387dff7f457cfee8778be09fd503bc397f747bd97d82ffcn/aHeodo
2022-01-2015701797648.xlsxls 2dea7ee99b9ee3e1af8311223fd46e439e34208c91a1b4a4926afff5c0f25265n/a Heodo
2022-01-20949953118320528.xlsxls 093eb9276d5df2490f9dc0dd324349648f030d92ca6d4ab24d386d1d0eaea799n/a SilentBuilder
2022-01-2065566380306.xlsxls ca1baf60faa9486403587e0fac3c548db3aa5b6fb42897e1569020682499e319Virustotal results 25.42%SilentBuilder
2022-01-20098247444108177447.xlsxls 88f602cd8f6b66886acb349720da52c3f5fdb367fe8a72f76812af27347cf32eVirustotal results 22.03%Heodo
2022-01-2011189127045000611.xlsxls 92f65a0fe643c1d601633944790e1263b9dc30881b77636627c624581aac4acbn/a Heodo
2022-01-203247688468271510.xlsxls bcfa7cbaded9c6144689692a9ea193431c16e7bf18e7ab361ef65fce375d93beVirustotal results 43.33%SilentBuilder
2022-01-20088587794186905.xlsxls b3973d991b4f3e3870404c40bf59257bd40f4207f10dd5a6c34a8d4e29e0f7eaVirustotal results 24.14%SilentBuilder
2022-01-2086286625633635766.xlsxls 3bc531482cc543cfaf67ec3c0d55382b129889d770be69196b05221058020958n/a Heodo
2022-01-20892229086884.xlsxls a3182153bbc02b08e54fa468a6a470ede9822cc612dfd6c8f523b9cb5cd4984en/aHeodo
2022-01-2096937479269795.xlsxls d0e970149a72b878303b425cbeb058aac6d74f1b94b2c3e150e40ea7da2e9072Virustotal results 22.22% Heodo
2022-01-2020513175112.xlsxls dbb17e696e6cab92c31a2e8e002262e5381c211d44af8d6c9ee5fea7f6f3386dVirustotal results 22.41% Heodo
2022-01-2008512024751.xlsxls 2bc45370dd6eed0f3059fe82bd82d8aeca954819c9ad8ea823d36a8e01c7e92cVirustotal results 37.93%Heodo
2022-01-202450363557.xlsxls bfb6705f630bdd22900dbc04de2805a63b70dd5b36a8985087a1d4be51308fd9n/a SilentBuilder
2022-01-201099527100443.xlsxls 1db2ec499c11b096c4a468a878a9e6bb791183ca2156eb2e8c233fd7b172b607Virustotal results 45.76%Heodo
2022-01-204275226932295449.xlsxls 489a8d75e0335e05d649b0e5cae103a142020fe00909e4e1f2d83704f07fff84Virustotal results 17.24%Heodo
2022-01-203053292543264842400.xlsxls 6d56c4a60ec2d451673ce2ce76e1fd89e23fa89a05c872736d78e15020cabe71Virustotal results 20.34% Heodo
2022-01-207208219800087313.xlsxls 5c8cb7136b7f89772e79c0a2f6ead69434dbd7cd66ed030ca620de279c9b20a2Virustotal results 18.64%Heodo