URLhaus Database

You are currently viewing the URLhaus database entry for https://bd.vomitbox.org/docs/G/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1993372
URL: https://bd.vomitbox.org/docs/G/?i=1
URL Status:Offline
Host: bd.vomitbox.org
Date added:2022-01-20 18:01:15 UTC
Last online:2022-09-01 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 18:04:58 UTC to abuse{at}dreamhost[dot]com)
Takedown time:7 months, 13 days, 20 hours, 57 minutes Bad (down since 2022-09-01 15:02:20 UTC)
Tags:doc emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-06n/aunknown 2a356a29ce769f87c1ff7488b3f743c2e2e64f26cdbe38c71d7d5d02c6990616n/a 
2022-06-28n/aunknown d5cbbb98339a4e519e3327e104365ca7e3048517b2299d7ae8170d5b8aec740cn/a 
2022-05-20n/aunknown e4bcd81202e88030e113bab6fab6a2a934455b26cfd6cd1ca34c4c16ae118bd1n/a 
2022-04-04n/aunknown 7a74fe6a2160012e423d925a40c5c1498d043390ebaba29ebc5722941cf96ea8n/a 
2022-03-06n/aunknown 3311add7e4c910f1519369e965cf3648cef763e54528d9281a52b3e805519704n/a 
2022-02-232875020190142.xlsxls d507a6a85d0f208c8662e6cde4d1bd419daefd9b5644146e4a51546fa37131abVirustotal results 24.14% Heodo
2022-01-2030686367235.xlsxls 4627d88cb27d885555625326c40717630dbfc7708869fdde4d0064f2d59e5bb4n/aHeodo