URLhaus Database

You are currently viewing the URLhaus database entry for http://behaviouralworkshop.com/msuvpkl/9qWc9TvYVwZ8XMRII3nEXYt0vzfj/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1993091
URL: http://behaviouralworkshop.com/msuvpkl/9qWc9TvYVwZ8XMRII3nEXYt0vzfj/?i=1
URL Status:Offline
Host: behaviouralworkshop.com
Date added:2022-01-20 16:08:05 UTC
Last online:2022-02-03 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 16:10:25 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:13 days, 21 hours, 44 minutes Bad (down since 2022-02-03 13:55:05 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-2150434879073077843.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 36.67%Heodo
2022-01-2163747188194.xlsxls b443a467b699497e7eabc0c3bdf7bf6a86705a29944ec4ee8e249abb7d17828fVirustotal results 37.29% Heodo
2022-01-214122244340.xlsxls b11d267860a7dfa12d415540e8d6b6e4b7813b2a4d633c966ce2c405a20b9a95n/a Heodo
2022-01-212303742179402864.xlsxls 2f51046242d3bd4fc8a58e9ee765707e09c8efbc4bd58b302262b181e9960bf1Virustotal results 40.00% Heodo
2022-01-2180803053592850030126.xlsxls a012d6c3ff9ac12c39dc7e32fb51008897bf8ec0ea7291f80801a2bcdf195cffVirustotal results 40.00%SilentBuilder
2022-01-219591758186642927120.xlsxls ce8ed57f03c2c3733b81f29e38332753051c9d5917d62760190dbc6b9dcebf45n/aSilentBuilder
2022-01-2119834954840348965.xlsxls 1f8c4b036377f2a61d53cb148ad29e36409e2248ccb66479eea7f3e5eac3cb78Virustotal results 20.00% Heodo
2022-01-217798111350383.xlsxls 17fd6dde30c8df304a856b8907a053772fe7300d8ca7f8164b72d0c5f5f51215n/a Heodo
2022-01-2141177104248997.xlsxls 7ecf0d5b556f400f2d98ef9f7e90373854ec0bda7732f5300223f9c600405235Virustotal results 29.31%Heodo
2022-01-21195293752718652.xlsxls db8baab6295830de9d3d9a59dc3b8c88a5de601deeaffaaa83bb6aa941e29b6cVirustotal results 33.90%Heodo
2022-01-2144554240339972.xlsxls ad583c4b877a37dbf913c275e1bce335b8e73817d61039a2a510e28f325d3e6cVirustotal results 31.67%Heodo
2022-01-2121769241771.xlsxls dac57112411305935ad4318c4ff4f495b8b39f84f001b64d83ea3ae69a994b02n/a Heodo
2022-01-2144553543870808.xlsxls f81b07415f482920feaf5352e72d1997c9a746dcde98208be75087efd6e4eab2n/a Heodo
2022-01-211535036333175.xlsxls b25424269b681aeaf1aa59f18c0e7a39d6f8e41a76c47fde6377681254a4c440n/a Heodo
2022-01-2192102282483732697.xlsxls 9ec21209d6b8b473f19ca78ea762fbaa3a555169ec4462aac5ee5bb1682a27efn/a Heodo
2022-01-21420075053627053.xlsxls f8d6b99d4c2313eca81f477de5763048a8606e5e06adf6e6cd4dc0675f8b891dVirustotal results 32.76% Heodo
2022-01-214954686682822293.xlsxls 21e23ea56b3d3198bc790c23569c989367c1907f23680e1760b7e76250e87549n/a Heodo
2022-01-21169104451564252259.xlsxls 4f0d506bde4b58d49d13c50470ec44e3cb2d9b084afa1186e857445ea66faccfn/a Heodo
2022-01-2115022459409371124777.xlsxls eca323ddf5c863072e76cef170025ffcb611946ac3656f641ff0d2a0b17aa382n/a Heodo
2022-01-2112134885033112586.xlsxls 5d8d1d8cee7bfa315d6091608aaad9d7d72ffe649d9dd9d4583369298b45160cn/a Heodo
2022-01-21021068627732667.xlsxls 9fdb19b415f24dfd571c8289d1952dd827d1fb2a14e8776e495da67e5b38a176n/a Heodo
2022-01-216965386017.xlsxls c98dcba86d1537e49d66765a60268850b112fbb98f23aa6d3b91cc5f93c2a232n/a Heodo
2022-01-2120720884893838.xlsxls 8aa9a577a3bd2b2fb4b35339f5593a8a3f1c7635247b6fe78fbbb2983a8cdd4fn/a Heodo
2022-01-21902481671166413343.xlsxls 358e8e25ef848f0530a1b2094f471f68415b1b8f84cf21e6f9f1dbb774759140n/a SilentBuilder
2022-01-219732713842952547.xlsxls 649143ea8e6ec1173106ac1bc3034951327ffc75a1d8324a1b80d280998e2fa2n/aHeodo
2022-01-21474490767232729046.xlsxls 71ef7935e65760f4ec2fc7a2d24246ee5db75c28000b0a7303ec8ac0c9e98634Virustotal results 22.03% Heodo
2022-01-2118676074751736.xlsxls af86124d12773c861ad103419ab9f04ada33b95ff6919a1a9f9c4dfe2d49131fn/aHeodo
2022-01-20603202558222217.xlsxls 5d36041450aacaf14696b91009e0d0724695c47586467dfad802076b3dd6adden/a Heodo
2022-01-20088170774502.xlsxls 536582463c4d7bc11c931e61b72316d539e0b4ed677451ec3ab8942f6a02a040Virustotal results 20.34%Heodo
2022-01-2058771439543.xlsxls 3e36c6f45c9f9361f6c28f811cd2048a727e022281815b02c021811cab7ed01en/a Heodo
2022-01-2035754753326670.xlsxls afc76f4aa05482102ea34e10b3d2397db55857510ce6ae3dcfe05e29cc92bde3n/a Heodo
2022-01-2051489040410.xlsxls 48fee052f0fa5361ddc892d4768321a00e5c80adabc60654488ea8fc1ffa135fVirustotal results 22.03%Heodo
2022-01-20171203800250.xlsxls 26abe8e8297849c2a5721808548030b0abb405538a62e4a4d7bc0bf2a6279476n/a SilentBuilder
2022-01-20499928703352029.xlsxls e099be7b0c6f692f34ca73c32d72d85e9f0465fcf630dc6d929ff4280496c27bn/aHeodo
2022-01-204933669234250390515.xlsxls 51dc452edd7c975ac8f632ad888d6cada4233c19aa061416076abbdb2ac596b4Virustotal results 22.41%Heodo
2022-01-20781301501976.xlsxls e33811b4dab432d10d50a8357ec88ab255590ac412e6a386ae3cee55c40df20en/a Heodo
2022-01-2093127959472.xlsxls caa57a0d7208775ee50b80b88384a83804e8b132229162b88db9a3a57abb7acbVirustotal results 20.34%Heodo
2022-01-20280572027537163763.xlsxls 5d372591b1e8b3107e0e57ec3a38f1d2bfd43afef5f04bee85334f46f57d71bdn/aHeodo
2022-01-204814888609084012550.xlsxls b9da67f07dffac92070453903df7e7b7ba55f0535b5c64111357c3f70d836787Virustotal results 17.24% Heodo
2022-01-2074010597250.xlsxls 88c52c4d1940f16219506b7c10ded1fa314e5f05e0aa03cf441a7dee30f41aa6Virustotal results 22.41%Heodo
2022-01-2071520982294.xlsxls 670b10a706a22c6efc34af36bf591688d08eb44be993d5901a66525c6369bd9en/aHeodo
2022-01-203102050122066.xlsxls 23dc54d35406a09e9c7ebc21aed24c81434f62784b5a94ff6b762b39008d3a05Virustotal results 17.24%Heodo
2022-01-2052561998779.xlsxls db6061f8252704ee6f243e9d5792be120e6743cd366b4ae8f3b56d12b00866ffn/a Heodo
2022-01-20204206792530829.xlsxls 039adcca4d205850117d5b2348ceec561c57868668ab822350ef94a9b9467842n/aHeodo
2022-01-208036453796366527256.xlsxls a871770ef1ba329147828026ab5d7d1d0edf83ea93fca2bb2d0faada51cf48e1n/a Heodo
2022-01-2087131328695.xlsxls d0e970149a72b878303b425cbeb058aac6d74f1b94b2c3e150e40ea7da2e9072Virustotal results 22.22% Heodo
2022-01-2020306458373479933.xlsxls 1406e7176ae6fb7aba0fb00e8658291ffeb38c2c9d844bdb47a8131c697342a5n/a Heodo
2022-01-20755529921271486.xlsxls e202d02eeb40c6b2bfd8da52e0297679c1a7df39592bba24d12079257a8bdf8aVirustotal results 42.31%Heodo
2022-01-20936090682937513.xlsxls 88f602cd8f6b66886acb349720da52c3f5fdb367fe8a72f76812af27347cf32eVirustotal results 22.03%Heodo
2022-01-203916405256518009110.xlsxls 06be4ce3aeae146a062b983ce21dd42b08cba908a69958729e758bc41836735cVirustotal results 27.12%SilentBuilder
2022-01-205570559864958.xlsxls 687e234c7b54e2590520375221eec756b91e6e03b05bbb313e8765457906c707Virustotal results 41.67%Heodo
2022-01-20724818141458.xlsxls b7c12da037688c432bf94d80c88811b29b1a4d379a84ff3d6e6ac95eecf15680Virustotal results 25.86%Heodo
2022-01-2014305499668428901428.xlsxls b3973d991b4f3e3870404c40bf59257bd40f4207f10dd5a6c34a8d4e29e0f7eaVirustotal results 24.14%SilentBuilder
2022-01-206907241903387080.xlsxls 7f47c50d92a3da634e5e5810bf1d27d35cd110242f9148c1506e2da375a056e8Virustotal results 41.67% Heodo
2022-01-2077047272419202.xlsxls fa39e0b7c55be8b0a1237b7757dfb1428554fbca8ae6e2e3f118494033ae6819n/a Heodo