URLhaus Database

You are currently viewing the URLhaus database entry for http://kurenai.travel.coocan.jp/Blog/Lj6/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1992978
URL: http://kurenai.travel.coocan.jp/Blog/Lj6/?i=1
URL Status:Offline
Host: kurenai.travel.coocan.jp
Date added:2022-01-20 15:32:08 UTC
Last online:2022-01-24 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 15:34:35 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Takedown time:3 days, 10 hours, 23 minutes Bad (down since 2022-01-24 01:57:36 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-2142120732390684.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 36.67%Heodo
2022-01-21290769399060688.xlsxls e59173f043483afd41faf0edf28ff91047d48ddbcabe29efe43bbc7d238c9861n/a Heodo
2022-01-210520016008556680.xlsxls b8fef9073b247386d53e1eba4723994cf6300b257f2b637cb1eccead6b68904cVirustotal results 40.68% Heodo
2022-01-21411965449610.xlsxls f35abc3dbc3faa333da128234f2b7778969e1ea5f8ef088498cc8ecf325f8a9cVirustotal results 35.59% SilentBuilder
2022-01-21408952979358190.xlsxls fc79dd33ef2208cbe871b54938ff2ad295a34cb9a720e4995853dfed5761db18n/a SilentBuilder
2022-01-21714821230577428649.xlsxls 29111d8e5e8306e76660db292e7232ab39e901955014eede21e912c931a09b5fn/aHeodo
2022-01-21874665448201401649.xlsxls ab4456f73cd0d49bd6c2dc5553a33ff128bc765cb07cd47f8e0619d01735f966Virustotal results 22.03%Heodo
2022-01-2145240899803248179.xlsxls c3496d8e7d2ffbb343cb44911bd859ceb08cbac8eb09ebfc58ce6cb1208f2d8eVirustotal results 28.00% Heodo
2022-01-21521896685861140.xlsxls 6027b0c0ed3191c277bd14f9bfca0e7110c5b306dba6bdc3e5bf123d0b31e6aen/a Heodo
2022-01-21564391495328907062.xlsxls 13c3fec523cfe8ac14a7e78a8e2ca86dfd3b8bb8447eb7e733e7b1207de5bea6n/aHeodo
2022-01-216609234314234061.xlsxls 6232ba47b182fc60d16bf5b9d41f5dc614f2f348e83414c533df7ccbfb940885n/a Heodo
2022-01-210760050757012704.xlsxls fe0ea8701f0d1d1b08de951b55324c38441ca10539fdac0274a95e293448f8f3n/a Heodo
2022-01-219016845020200882544.xlsxls 8b24ef9d0556c1351a46d2e0eb996b21b65638c41dc79cd5b676a79bf0d18a17n/a Heodo
2022-01-2179548362167579.xlsxls 053d625d162a5e1ad61603ca7d6dfd915cc175e991eaf3377a55b00853fabd07n/a Heodo
2022-01-2185007912483001970993.xlsxls 3b8dc8f1f75a66d545d45ee9f4160ea99cff4e8cc3f5b265ea27736a3eabf381n/a Heodo
2022-01-21739973150268856390.xlsxls 2847438e4b48ee5f630b8d0a3d5361bf4071aa308d8999a69cba995fa548add5n/aSilentBuilder
2022-01-2123075059372885831166.xlsxls 9eb1535c5aaefb0a3a2b583a4aad8ef65f55b805294dca339ab2f8e632ebffedn/a Heodo
2022-01-215540776881.xlsxls baa950d432aeb1593d886ae1afff9dbc40b6be9828af26c7d3c72431f4fdafffn/aSilentBuilder
2022-01-21754870710104146.xlsxls 4c2ddd629e265246f75b3e606e6bc899afb3c82020fc9a8f440e7793d6fed047n/a Heodo
2022-01-2117407556500799.xlsxls 278e2b44764f4223799867c585d886b7fe57313055f5f82d983f7e13e1a49aedn/a Heodo
2022-01-21186206804764061765.xlsxls c853e3e650463ca03b11d37a51d45c21e90abb85fe410073c435eba0d168d28cn/a Heodo
2022-01-2100545844468732245.xlsxls 4520398e8aeabb1aed9cd4899a2ac014545d9ad9383959288cf2470f9c1c4731n/aHeodo
2022-01-215957247024.xlsxls 1b6134b3db142025a7ebff094a48928647019264965031e089063502561e7ca5Virustotal results 22.03% Heodo
2022-01-21452629810910850.xlsxls 46e07bbc26b054bd482b53d0528f74edc997f805951abdafb92a26dc38b7bf64n/a Heodo
2022-01-216203463958344.xlsxls 01bab18ffb7052e8d67dc6447267ec775667a721592e609cf62dd08649d7a807n/a SilentBuilder
2022-01-218726729014950508482.xlsxls 9296f02a362c27b1e3a3b4119ede64ea52b6c0430fc70517e5146730c23c987dVirustotal results 22.41%Heodo
2022-01-21161497358522806492.xlsxls 2d259bd946fb388d1a7d75d28ba591aca3377e0ca8b49e0add414fe82b76f483n/aSilentBuilder
2022-01-2008862163637270904645.xlsxls 88c13197081731462e05ef64b1c9abbdc1b85e0e573437506270137fb7b735d8Virustotal results 22.03%Heodo
2022-01-2028296067102732.xlsxls 2181997083632b17484474d7152e18c8a65175b823c871b164d15d2e20a8ae16Virustotal results 18.52%SilentBuilder
2022-01-208960945130.xlsxls 536582463c4d7bc11c931e61b72316d539e0b4ed677451ec3ab8942f6a02a040Virustotal results 20.34%Heodo
2022-01-2000506730208.xlsxls 3e36c6f45c9f9361f6c28f811cd2048a727e022281815b02c021811cab7ed01en/a Heodo
2022-01-202647013876292095.xlsxls 7758c1ef7b05f4e4e7e283eda2aba34801589c1ed656610c149a5b1a1a0b7fc3n/a Heodo
2022-01-2033936080738529683450.xlsxls cc087101e48ffeece56deba54e6da814a6d35e371396b07cc4e10b121aac9907n/aHeodo
2022-01-205773905823272.xlsxls 48fee052f0fa5361ddc892d4768321a00e5c80adabc60654488ea8fc1ffa135fVirustotal results 22.03%Heodo
2022-01-2099550877282190458922.xlsxls 26abe8e8297849c2a5721808548030b0abb405538a62e4a4d7bc0bf2a6279476n/a SilentBuilder
2022-01-206999864814.xlsxls 6f95d343a882d6e800379be638a48804dfc956537ffcc06361e1f57fa2938808n/aHeodo
2022-01-2083957299521.xlsxls caa57a0d7208775ee50b80b88384a83804e8b132229162b88db9a3a57abb7acbVirustotal results 20.34%Heodo
2022-01-205116807710660.xlsxls 43a573dc9dd0dc79dcf228467e8e6820f4a4f8bf344660ea43eb11bb7b3c93f7Virustotal results 21.43%Heodo
2022-01-2003681540922351.xlsxls 40f9154664b770c66a090165c65473921f7bb51ab60e7c84a46e5e63af00ae29n/a Heodo
2022-01-20989712341136.xlsxls 402b387ff9eaca12395e5ea30d7252c77d49ce1d1478784bdb329641136043ean/aHeodo
2022-01-20529257778283.xlsxls 08bb2ccb672e0a1d931b62b0295ea0395bb552551c4787f664c4b7f42839f48fn/a Heodo
2022-01-20366815284020118.xlsxls a2f32b5bfd78eeee7b3d4d44b4da8c8aeb98ab866a7998e2adaabc80cd1247a4Virustotal results 42.37%Heodo
2022-01-203166997654058.xlsxls c962232ce7c3c2cff3baa81deffa085cab3750504b71d870c81685ca3283dd08n/a Heodo
2022-01-2029555936417.xlsxls da9d3b84063bde0697546e7a9b3e2ab5f8283698dfb032f76018f28b367146f4Virustotal results 40.00%Heodo
2022-01-2096793341355809646186.xlsxls 33bcc678281337839c7121adf32e1ea0fab2974709ab30d0099e4bbd147916b6Virustotal results 17.31% Heodo
2022-01-2046118780381.xlsxls 093eb9276d5df2490f9dc0dd324349648f030d92ca6d4ab24d386d1d0eaea799Virustotal results 40.00% SilentBuilder
2022-01-2002876897804898675154.xlsxls d16d836fa1d7bcd99b7a2b65ca2d4deb2a54b552ecac9141c735e793c23a2a3fn/a Heodo
2022-01-205858545712421207.xlsxls fff3ac0f2ce35babb7cf736ec26a8374c8babd255489994937c41a8c005e5b46Virustotal results 22.03%Heodo
2022-01-2046941200678093736423.xlsxls a38227249265731f1e9195e22b2ba517aade08d43d5a67117592cf0a5f8c3b9bVirustotal results 24.14% Heodo
2022-01-2091799301655363550.xlsxls 92f65a0fe643c1d601633944790e1263b9dc30881b77636627c624581aac4acbn/a Heodo
2022-01-203254209768250.xlsxls bcfa7cbaded9c6144689692a9ea193431c16e7bf18e7ab361ef65fce375d93ben/aSilentBuilder
2022-01-2040216628947148815975.xlsxls f364484e6d3e00f20019e36759be54c6c36fab26ca0d5dbe5819354754423a1cVirustotal results 22.41% Heodo
2022-01-207413729880829.xlsxls b24ab935f6d7ae64a036e919f70a63590db56ebd6dea1660d89827851be32e93Virustotal results 20.69% Heodo
2022-01-205506531478453331.xlsxls 0f450bafecb632b74ddccde54cd55f20a344d91a3ac5a6f031aa97113514716cVirustotal results 35.09% Heodo
2022-01-20818652334295.xlsxls e7fa5a535aaa83921ba3f69b0965a6a20697916ec4e0896c29a684ef1f5850ebn/a Heodo
2022-01-2067118999319173.xlsxls fa118d305bad13e6c33a570a4bcd6159971ca1c5c3cf06eb7c8a5612e0d42aafVirustotal results 23.73% Heodo