URLhaus Database

You are currently viewing the URLhaus database entry for http://customtshirt.sogoflowers.com/cgi-bin/noa12Fe/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1993446
URL: http://customtshirt.sogoflowers.com/cgi-bin/noa12Fe/?i=1
URL Status:Offline
Host: customtshirt.sogoflowers.com
Date added:2022-01-20 18:33:06 UTC
Last online:2022-01-21 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 18:34:54 UTC to abuse{at}corespace[dot]com)
Takedown time:20 hours, 2 minutes Good (down since 2022-01-21 14:37:19 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-217481275760890052523.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 36.67%Heodo
2022-01-21940735981645030.xlsxls 3ca3bcd5771a06938cc8e8c44cd2c85b794376401b469fad7e5d4b513449fa27n/a Heodo
2022-01-2176846478468762694.xlsxls e59173f043483afd41faf0edf28ff91047d48ddbcabe29efe43bbc7d238c9861n/a Heodo
2022-01-21255355774065576856.xlsxls b8fef9073b247386d53e1eba4723994cf6300b257f2b637cb1eccead6b68904cVirustotal results 40.68% Heodo
2022-01-2101525256778.xlsxls 7efacaa6dacfe6bf20d27faaf86184458461e64165c615cede70b42cf913f8aeVirustotal results 38.33%SilentBuilder
2022-01-2143521305310941106.xlsxls fc79dd33ef2208cbe871b54938ff2ad295a34cb9a720e4995853dfed5761db18n/a SilentBuilder
2022-01-216712086235975895591.xlsxls 29111d8e5e8306e76660db292e7232ab39e901955014eede21e912c931a09b5fVirustotal results 35.00%Heodo
2022-01-2175893801880889.xlsxls 2c9af469fcb89bb2e93d1ac70ce0bec912b78d5c3cbadccc3040c18dd03f5e41n/a Heodo
2022-01-218108904103737331280.xlsxls a3d7cb606d8f77987119021ad7d89fac7d02668d86ff90db65c87e54a15e73fbn/a Heodo
2022-01-2127215413851.xlsxls d314b3d22bcf83bf1f0dfb95189d8101cf360bfb61041246129f3f95f8de2402n/a Heodo
2022-01-2186629249100.xlsxls 71b3ba908e6fad97ab7e14ce79d7e0c313fba439d916a3b20a8ec2040e30ed87n/a Heodo
2022-01-2180852248726.xlsxls fe0ea8701f0d1d1b08de951b55324c38441ca10539fdac0274a95e293448f8f3n/a Heodo
2022-01-21182224184399624798.xlsxls 8b24ef9d0556c1351a46d2e0eb996b21b65638c41dc79cd5b676a79bf0d18a17n/a Heodo
2022-01-213490058198105.xlsxls 053d625d162a5e1ad61603ca7d6dfd915cc175e991eaf3377a55b00853fabd07Virustotal results 30.00% Heodo
2022-01-21265425132980274507.xlsxls 3b8dc8f1f75a66d545d45ee9f4160ea99cff4e8cc3f5b265ea27736a3eabf381n/a Heodo
2022-01-2118484481365817462.xlsxls 2847438e4b48ee5f630b8d0a3d5361bf4071aa308d8999a69cba995fa548add5n/aSilentBuilder
2022-01-2169953247157400312606.xlsxls 9eb1535c5aaefb0a3a2b583a4aad8ef65f55b805294dca339ab2f8e632ebffedn/a Heodo
2022-01-219069084806599.xlsxls baa950d432aeb1593d886ae1afff9dbc40b6be9828af26c7d3c72431f4fdafffn/aSilentBuilder
2022-01-21845913767463.xlsxls 2cb043937c5838c3f91d3955127cc444ff420b74448d38395ab177b8369753d0n/a Heodo
2022-01-211220199497.xlsxls 278e2b44764f4223799867c585d886b7fe57313055f5f82d983f7e13e1a49aedn/a Heodo
2022-01-213011392076523.xlsxls 3accfd2337522a6c68a1018979e3ac6603237e13aff0b962ae093662129d8609n/a SilentBuilder
2022-01-21872265086903.xlsxls 132c3baa8263b51b4a2847b2cd87c504be97ca43a01155b688d12d538c8ba7ccn/a Heodo
2022-01-211905509094039254702.xlsxls 1b6134b3db142025a7ebff094a48928647019264965031e089063502561e7ca5Virustotal results 22.03% Heodo
2022-01-21433239873950.xlsxls e57baf9289180802e131633ce599fd55a0a67db3423c45d62f4a88fbf94a0874Virustotal results 18.87% Heodo
2022-01-2168246842498423165.xlsxls 01bab18ffb7052e8d67dc6447267ec775667a721592e609cf62dd08649d7a807Virustotal results 22.03% SilentBuilder
2022-01-21124242592610446.xlsxls cb72aea24f710a0d9b643de1e759ace18205bc20aa8aa7a91ecf20e556cad41fVirustotal results 22.03% Heodo
2022-01-2112163601147242.xlsxls 561f1541d1ce60dd8a10c61c54f99d83e67ed86b0f645a6e564a99baa08f56b3n/a Heodo
2022-01-2028611581814.xlsxls 88c13197081731462e05ef64b1c9abbdc1b85e0e573437506270137fb7b735d8Virustotal results 22.03%Heodo
2022-01-208394842598566.xlsxls b0e176129f7c1c4ae1d31d420d8ecacaceb6c4682002848a769d98e4b0f21399n/a Heodo
2022-01-2068051211212530.xlsxls 5d36041450aacaf14696b91009e0d0724695c47586467dfad802076b3dd6adden/a Heodo
2022-01-20365407800760684.xlsxls 536582463c4d7bc11c931e61b72316d539e0b4ed677451ec3ab8942f6a02a040Virustotal results 20.34%Heodo
2022-01-2098644761719.xlsxls 514af468cf8a54d3ba4fd08208de3119721d9a9b5e4d2c96373add4d3dd7688dn/a Heodo
2022-01-2017431752015761.xlsxls afc76f4aa05482102ea34e10b3d2397db55857510ce6ae3dcfe05e29cc92bde3n/a Heodo
2022-01-201290111064.xlsxls 48fee052f0fa5361ddc892d4768321a00e5c80adabc60654488ea8fc1ffa135fVirustotal results 22.03%Heodo
2022-01-2004866880223995324828.xlsxls 26abe8e8297849c2a5721808548030b0abb405538a62e4a4d7bc0bf2a6279476Virustotal results 22.41% SilentBuilder
2022-01-20399060491962.xlsxls 6f95d343a882d6e800379be638a48804dfc956537ffcc06361e1f57fa2938808n/aHeodo
2022-01-20902325522555.xlsxls ab4456f73cd0d49bd6c2dc5553a33ff128bc765cb07cd47f8e0619d01735f966Virustotal results 22.41%Heodo
2022-01-20961324571426.xlsxls caa57a0d7208775ee50b80b88384a83804e8b132229162b88db9a3a57abb7acbVirustotal results 20.34%Heodo
2022-01-2079944640756111.xlsxls 43a573dc9dd0dc79dcf228467e8e6820f4a4f8bf344660ea43eb11bb7b3c93f7Virustotal results 21.43%Heodo
2022-01-20904805637156.xlsxls 7d3d594c05fa0fb042254c0eea69c93a740d792b77162f0f35f1b1e27e13c9f9n/a Heodo
2022-01-208673254072847.xlsxls 402b387ff9eaca12395e5ea30d7252c77d49ce1d1478784bdb329641136043ean/aHeodo
2022-01-20473315460396.xlsxls 08bb2ccb672e0a1d931b62b0295ea0395bb552551c4787f664c4b7f42839f48fn/a Heodo
2022-01-208092978876.xlsxls 8d84655e38e2387863d37550314c529ba267cf9b6d8f502ab1bbc350156e6d4cn/a Heodo
2022-01-20001612169337989296.xlsxls da9d3b84063bde0697546e7a9b3e2ab5f8283698dfb032f76018f28b367146f4Virustotal results 40.00%Heodo
2022-01-20967665145890.xlsxls 33bcc678281337839c7121adf32e1ea0fab2974709ab30d0099e4bbd147916b6Virustotal results 17.31% Heodo