URLhaus Database

You are currently viewing the URLhaus database entry for http://xtechgurdu.cluster020.hosting.ovh.net/assets/ZWLeV9PAEOF5j7e4VJG8/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1993164
URL: http://xtechgurdu.cluster020.hosting.ovh.net/assets/ZWLeV9PAEOF5j7e4VJG8/?i=1
URL Status:Offline
Host: xtechgurdu.cluster020.hosting.ovh.net
Date added:2022-01-20 16:39:04 UTC
Last online:2022-01-21 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 16:40:24 UTC to abuse{at}ovh[dot]net)
Takedown time:14 hours, 44 minutes Good (down since 2022-01-21 07:24:46 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-2129146315116005636.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5n/aHeodo
2022-01-211604330576811517.xlsxls 157742d33765bcf84671fcb841d4ac0f5a06a08c26fde8a84b5d90546ccf14fbn/a Heodo
2022-01-213330271758.xlsxls 5d169667000bc1687817d941ea002d71996eca10e2e275c926b485f87827be44n/a Heodo
2022-01-2188460518872312211.xlsxls a012d6c3ff9ac12c39dc7e32fb51008897bf8ec0ea7291f80801a2bcdf195cffn/aSilentBuilder
2022-01-21008273225536877.xlsxls fc79dd33ef2208cbe871b54938ff2ad295a34cb9a720e4995853dfed5761db18n/a SilentBuilder
2022-01-2174677870768.xlsxls c60a6861fc63f90b9f872e0bc131fa85f6af0daef37063eadf6d10890acf3bc0n/a Heodo
2022-01-2167388555132415.xlsxls 199122387889e980d89870e33df8adc2dd5845eb81507a41b912b198e2e7a745n/a Heodo
2022-01-21215310370960.xlsxls c3496d8e7d2ffbb343cb44911bd859ceb08cbac8eb09ebfc58ce6cb1208f2d8eVirustotal results 28.00% Heodo
2022-01-2112022863461201.xlsxls db8baab6295830de9d3d9a59dc3b8c88a5de601deeaffaaa83bb6aa941e29b6cn/aHeodo
2022-01-21376878012472.xlsxls 6232ba47b182fc60d16bf5b9d41f5dc614f2f348e83414c533df7ccbfb940885Virustotal results 38.98% Heodo
2022-01-214222453387907869.xlsxls c1cf0024cf0ea94cafe10459912b6db4e4b66bb5b5a08fd061b4e72b227a63e4n/a Heodo
2022-01-21120474567260229937.xlsxls f81b07415f482920feaf5352e72d1997c9a746dcde98208be75087efd6e4eab2n/a Heodo
2022-01-21420668720124.xlsxls 702e9fcc889535f1c31e1bad34de6e4456520ca0687f9240a318140924bed3cdn/a Heodo
2022-01-2156926847196852.xlsxls 4beb6b5929b3b8354a098b5f4232886f8db6fe5d02cec83ddcce82e47806ec04n/aHeodo
2022-01-2136808192247899.xlsxls 5e822244fcb48ca7098e959edb32e21203c5e1115aa43158ce06fe0bf4b6a628n/a Heodo
2022-01-217573419409547203339.xlsxls 3b8dc8f1f75a66d545d45ee9f4160ea99cff4e8cc3f5b265ea27736a3eabf381n/a Heodo
2022-01-2175576059154215.xlsxls d26fa50d28f1d5fecfbd935c7c439e19ed0336097938d366f8d2cb3e8c039824n/a Heodo
2022-01-210391802449506679516.xlsxls ccd9c6eef79a18615ba690a35d8a2f238ef0d6cf1e715536299b42f9e67357d6n/a Heodo
2022-01-219304812984230.xlsxls 2a76a4f3259fcd851ca4b6600ce2f79b588a682c7dabcc1d1db8269b5021d7ddn/a Heodo
2022-01-2146257064373334681984.xlsxls 2cb043937c5838c3f91d3955127cc444ff420b74448d38395ab177b8369753d0n/a Heodo
2022-01-218088217513.xlsxls 5ba1e7e7b37d9efbafaaa5049277348349998f11e6252edb0aa7fcc37bf94c99Virustotal results 20.34%Heodo
2022-01-21440078143521494.xlsxls 3accfd2337522a6c68a1018979e3ac6603237e13aff0b962ae093662129d8609n/a SilentBuilder
2022-01-2131314977802.xlsxls 132c3baa8263b51b4a2847b2cd87c504be97ca43a01155b688d12d538c8ba7ccn/a Heodo
2022-01-2106109069687868292.xlsxls 8920ee0d313454600eeb9c23142ccbd914ee4e5cfcce0c824eaab99344aca854n/a SilentBuilder
2022-01-210940652507.xlsxls 358e8e25ef848f0530a1b2094f471f68415b1b8f84cf21e6f9f1dbb774759140n/a SilentBuilder
2022-01-210617632177929455.xlsxls 8bf7d7d4defb13d445be8e02c114fbe19561d60aefe633018efe1627b4cf3d24n/aSilentBuilder
2022-01-2185374912561986199.xlsxls 9296f02a362c27b1e3a3b4119ede64ea52b6c0430fc70517e5146730c23c987dn/aHeodo
2022-01-2053405361377336.xlsxls 4656c40697e5b5f76624fad2742aba40ff71f45064f1dd8eba670a21c09678a0n/a Heodo
2022-01-2097388387847766040152.xlsxls 4ae5de8f34f1d8cf899bbe86265b6a4fc23672ac6471628a671f40404ef5302bn/a Heodo
2022-01-207812497263109607.xlsxls 5d36041450aacaf14696b91009e0d0724695c47586467dfad802076b3dd6adden/a Heodo
2022-01-209249351708828698684.xlsxls c3782f393e6dca8cbded5a7bbb73789792cd1bf807f4f71cd863b12992beda95n/aHeodo
2022-01-2044221400306775.xlsxls 514af468cf8a54d3ba4fd08208de3119721d9a9b5e4d2c96373add4d3dd7688dn/a Heodo
2022-01-20369091637928507.xlsxls b069423ac3753a4878bd652c9c55362c541db7529bd0b294ddc47bb7c6475946n/a Heodo
2022-01-201200018825286.xlsxls 0aa692cc9abe6360ac72502a9f27fb0e3d401153dfe067524c82c56b7e5f8625n/aHeodo
2022-01-201191523986215.xlsxls 423c9fe2d7c27c2f91785e754d0281d61626e45074695a9ad965ea73bba4b93cn/aHeodo
2022-01-2014577116118.xlsxls 3d4e63b97a9c9d14c1bc2a47305d634c50680eb52818eb3b42092dd415fb62d4n/a Heodo
2022-01-2000612801509.xlsxls cb260a08f074793cbaebd6b8453ae86b77cdf093ee569aaf06670237d1fe16cen/a Heodo
2022-01-2065946635788496514.xlsxls 51dc452edd7c975ac8f632ad888d6cada4233c19aa061416076abbdb2ac596b4n/aHeodo
2022-01-20207312511929.xlsxls 8697b2c64ef08e5e4bd5ca43dd988dc5ab701d50fb022b74e7413b95a7dc7c02n/a Heodo
2022-01-200507560163.xlsxls caa57a0d7208775ee50b80b88384a83804e8b132229162b88db9a3a57abb7acbn/aHeodo
2022-01-2010019541962159.xlsxls 5d372591b1e8b3107e0e57ec3a38f1d2bfd43afef5f04bee85334f46f57d71bdn/aHeodo
2022-01-205048725228.xlsxls b12e86184ea506fa554f7e29ee00586c73545c1af7f451eb98f49a2ba215b604Virustotal results 35.59% Heodo
2022-01-200642031843003114.xlsxls 88c52c4d1940f16219506b7c10ded1fa314e5f05e0aa03cf441a7dee30f41aa6Virustotal results 22.41%Heodo
2022-01-204778711300.xlsxls c1ee05cc88f49b09c9ca3620a75b0f1ca127afa63af57cc6c989d1023f30177bn/a Heodo
2022-01-201432534029446213422.xlsxls dac93a5dfa21730566aa2899863ef7b65a992bc7934d64f771038391cbd39529n/a Heodo
2022-01-2004998892454.xlsxls ad511015e8c542a03954c1be8721ddcce85dbe997f7b2048bc6e1b35823c5ffcn/aHeodo
2022-01-2035934033387717315.xlsxls 4e012706695112b7e19ba7cb073f14b4858bbe382890106a21cadf220bcd050fVirustotal results 27.12%Heodo
2022-01-20984213606646.xlsxls 164c4462564895150dfc560f123efd7a59af8c5720ed9937070c77875cc54031Virustotal results 22.03%SilentBuilder
2022-01-2061400170910414.xlsxls d0e970149a72b878303b425cbeb058aac6d74f1b94b2c3e150e40ea7da2e9072Virustotal results 22.22% Heodo
2022-01-20870179471221.xlsxls 093eb9276d5df2490f9dc0dd324349648f030d92ca6d4ab24d386d1d0eaea799n/a SilentBuilder
2022-01-200766250430503840448.xlsxls ca1baf60faa9486403587e0fac3c548db3aa5b6fb42897e1569020682499e319Virustotal results 25.42%SilentBuilder
2022-01-209858150833209035.xlsxls fff3ac0f2ce35babb7cf736ec26a8374c8babd255489994937c41a8c005e5b46Virustotal results 22.03%Heodo
2022-01-20915259706460782.xlsxls a38227249265731f1e9195e22b2ba517aade08d43d5a67117592cf0a5f8c3b9bVirustotal results 24.14% Heodo
2022-01-202912065653.xlsxls 61edf37e9c8e80e6ef365ddc3e366b079e027dc74c22230adc8dc709f293600bn/a Heodo
2022-01-201876122431650.xlsxls b7c12da037688c432bf94d80c88811b29b1a4d379a84ff3d6e6ac95eecf15680Virustotal results 25.86%Heodo
2022-01-203157769982619089.xlsxls 053c0755d6a308ffbc4afb3c5a5d38f54f8ce27e09cbdd58c8a262fd078e38f3Virustotal results 43.86% Heodo