URLhaus Database

You are currently viewing the URLhaus database entry for https://altheqa.policyfest.com/Fox-C/uHPOovOxa2Bmad/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1993475
URL: https://altheqa.policyfest.com/Fox-C/uHPOovOxa2Bmad/?i=1
URL Status:Offline
Host: altheqa.policyfest.com
Date added:2022-01-20 18:43:05 UTC
Last online:2022-01-22 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 18:44:11 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 day, 13 hours, 39 minutes Poor (down since 2022-01-22 08:23:11 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-216777980921281297.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 36.67%Heodo
2022-01-217843568784806810751.xlsxls 3ca3bcd5771a06938cc8e8c44cd2c85b794376401b469fad7e5d4b513449fa27n/a Heodo
2022-01-21592594505679.xlsxls e59173f043483afd41faf0edf28ff91047d48ddbcabe29efe43bbc7d238c9861Virustotal results 36.67% Heodo
2022-01-219248613123.xlsxls b8fef9073b247386d53e1eba4723994cf6300b257f2b637cb1eccead6b68904cn/a Heodo
2022-01-21875592919963495.xlsxls fc79dd33ef2208cbe871b54938ff2ad295a34cb9a720e4995853dfed5761db18n/a SilentBuilder
2022-01-21845468271803553.xlsxls 29111d8e5e8306e76660db292e7232ab39e901955014eede21e912c931a09b5fVirustotal results 35.00%Heodo
2022-01-217565959915.xlsxls c3496d8e7d2ffbb343cb44911bd859ceb08cbac8eb09ebfc58ce6cb1208f2d8eVirustotal results 28.00% Heodo
2022-01-2100830408075234.xlsxls a3d7cb606d8f77987119021ad7d89fac7d02668d86ff90db65c87e54a15e73fbn/a Heodo
2022-01-213178642392000.xlsxls e06d794800a6c8e29eaee2ec0e2ccd9f60b00c7d6c9b4a80ce605a4c156f9982n/aHeodo
2022-01-2114538905664674.xlsxls 71b3ba908e6fad97ab7e14ce79d7e0c313fba439d916a3b20a8ec2040e30ed87n/a Heodo
2022-01-2154944299591141455499.xlsxls 539a3855a176457a29262e61d738250050450a8a6adb2b1e9c8961a40a6cad57n/a Heodo
2022-01-21225412663734511851.xlsxls 053d625d162a5e1ad61603ca7d6dfd915cc175e991eaf3377a55b00853fabd07Virustotal results 30.00% Heodo
2022-01-2127662803483910358680.xlsxls 9ad38c251b929edaf974d16b81d02e8b87ca16da14c4aa4eea44df09aa210c69n/aHeodo
2022-01-21156924830664674.xlsxls d26fa50d28f1d5fecfbd935c7c439e19ed0336097938d366f8d2cb3e8c039824n/a Heodo
2022-01-215783997620984.xlsxls 9eb1535c5aaefb0a3a2b583a4aad8ef65f55b805294dca339ab2f8e632ebffedn/a Heodo
2022-01-2185590524335.xlsxls baa950d432aeb1593d886ae1afff9dbc40b6be9828af26c7d3c72431f4fdafffn/aSilentBuilder
2022-01-2135707338185.xlsxls 2cb043937c5838c3f91d3955127cc444ff420b74448d38395ab177b8369753d0n/a Heodo
2022-01-217687893878033615.xlsxls 4c2ddd629e265246f75b3e606e6bc899afb3c82020fc9a8f440e7793d6fed047n/a Heodo
2022-01-210555435923614056328.xlsxls 3accfd2337522a6c68a1018979e3ac6603237e13aff0b962ae093662129d8609n/a SilentBuilder
2022-01-2142760413376665738277.xlsxls c3deaaa5202a717b68951cf04c00e24200a91aeee0eceb58cc032a0471fbda36Virustotal results 22.03% Heodo
2022-01-219397706318985136.xlsxls 1b6134b3db142025a7ebff094a48928647019264965031e089063502561e7ca5Virustotal results 22.03% Heodo
2022-01-210040125279640.xlsxls bf377a8c8ae5170949a1ea2d2f8fb6d63a24839276a2fd63bc2a4525f1839a59Virustotal results 24.56% Heodo
2022-01-2177558131021677823170.xlsxls 46e07bbc26b054bd482b53d0528f74edc997f805951abdafb92a26dc38b7bf64n/a Heodo
2022-01-2104517741741.xlsxls 9296f02a362c27b1e3a3b4119ede64ea52b6c0430fc70517e5146730c23c987dVirustotal results 22.41%Heodo
2022-01-214200746629.xlsxls 561f1541d1ce60dd8a10c61c54f99d83e67ed86b0f645a6e564a99baa08f56b3n/a Heodo
2022-01-206641037839839264.xlsxls 2d259bd946fb388d1a7d75d28ba591aca3377e0ca8b49e0add414fe82b76f483n/aSilentBuilder
2022-01-20578935595448.xlsxls b0e176129f7c1c4ae1d31d420d8ecacaceb6c4682002848a769d98e4b0f21399n/a Heodo
2022-01-2046970297569221.xlsxls 5d36041450aacaf14696b91009e0d0724695c47586467dfad802076b3dd6adden/a Heodo
2022-01-2052254888249213387.xlsxls 3e36c6f45c9f9361f6c28f811cd2048a727e022281815b02c021811cab7ed01en/a Heodo
2022-01-200400968774850131689.xlsxls 514af468cf8a54d3ba4fd08208de3119721d9a9b5e4d2c96373add4d3dd7688dn/a Heodo
2022-01-20887981506872688755.xlsxls afc76f4aa05482102ea34e10b3d2397db55857510ce6ae3dcfe05e29cc92bde3n/a Heodo
2022-01-2081666484320464212666.xlsxls 48fee052f0fa5361ddc892d4768321a00e5c80adabc60654488ea8fc1ffa135fVirustotal results 22.03%Heodo
2022-01-2075438165490619.xlsxls 02beb553bb2d04182e73cf34f42a9dc4c52f84b4278e97f9fbce8f111af576d3Virustotal results 22.41% Heodo
2022-01-20708687526588082.xlsxls 26abe8e8297849c2a5721808548030b0abb405538a62e4a4d7bc0bf2a6279476Virustotal results 22.41% SilentBuilder
2022-01-204732868868824279.xlsxls e099be7b0c6f692f34ca73c32d72d85e9f0465fcf630dc6d929ff4280496c27bVirustotal results 21.05%Heodo
2022-01-20365571977011741957.xlsxls ab4456f73cd0d49bd6c2dc5553a33ff128bc765cb07cd47f8e0619d01735f966Virustotal results 22.03%Heodo
2022-01-2021583378803681338.xlsxls caa57a0d7208775ee50b80b88384a83804e8b132229162b88db9a3a57abb7acbVirustotal results 20.34%Heodo
2022-01-204766683274070.xlsxls 5d372591b1e8b3107e0e57ec3a38f1d2bfd43afef5f04bee85334f46f57d71bdn/aHeodo
2022-01-203607715267323672356.xlsxls b9da67f07dffac92070453903df7e7b7ba55f0535b5c64111357c3f70d836787Virustotal results 17.24% Heodo
2022-01-200833264595697284.xlsxls 670b10a706a22c6efc34af36bf591688d08eb44be993d5901a66525c6369bd9en/aHeodo
2022-01-20413613379262367952.xlsxls db6061f8252704ee6f243e9d5792be120e6743cd366b4ae8f3b56d12b00866ffn/a Heodo
2022-01-20958898873648328457.xlsxls ad511015e8c542a03954c1be8721ddcce85dbe997f7b2048bc6e1b35823c5ffcn/aHeodo
2022-01-2096566324367468157.xlsxls 039adcca4d205850117d5b2348ceec561c57868668ab822350ef94a9b9467842Virustotal results 41.67%Heodo
2022-01-207657491122675113.xlsxls a871770ef1ba329147828026ab5d7d1d0edf83ea93fca2bb2d0faada51cf48e1n/a Heodo