URLhaus Database

You are currently viewing the URLhaus database entry for http://9b-p.work/itdb/vC0S9E4XvEsWOUzHKBN3f0Oa/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1994183
URL: http://9b-p.work/itdb/vC0S9E4XvEsWOUzHKBN3f0Oa/?i=1
URL Status:Offline
Host: 9b-p.work
Date added:2022-01-20 23:35:05 UTC
Last online:2022-02-02 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 23:36:13 UTC to abuse{at}gmo[dot]jp)
Takedown time:12 days, 12 hours, 56 minutes Bad (down since 2022-02-02 12:32:19 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-21373082846837.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 36.67%Heodo
2022-01-2173940958460006723901.xlsxls 3ca3bcd5771a06938cc8e8c44cd2c85b794376401b469fad7e5d4b513449fa27n/a Heodo
2022-01-2116313827686405.xlsxls e59173f043483afd41faf0edf28ff91047d48ddbcabe29efe43bbc7d238c9861n/a Heodo
2022-01-21308712486278.xlsxls 5a6ae409ad46c453172d047a1b1d7685cbdcc317653d90c6a968509d1c2229b6n/a Heodo
2022-01-219344419095537.xlsxls b8fef9073b247386d53e1eba4723994cf6300b257f2b637cb1eccead6b68904cn/a Heodo
2022-01-21993551795286588214.xlsxls fc79dd33ef2208cbe871b54938ff2ad295a34cb9a720e4995853dfed5761db18n/a SilentBuilder
2022-01-2169414765022868341464.xlsxls 29111d8e5e8306e76660db292e7232ab39e901955014eede21e912c931a09b5fn/aHeodo
2022-01-217650360594072.xlsxls ab4456f73cd0d49bd6c2dc5553a33ff128bc765cb07cd47f8e0619d01735f966Virustotal results 22.03%Heodo
2022-01-210696664717027.xlsxls 2c9af469fcb89bb2e93d1ac70ce0bec912b78d5c3cbadccc3040c18dd03f5e41n/a Heodo
2022-01-2174460453181909999.xlsxls e06d794800a6c8e29eaee2ec0e2ccd9f60b00c7d6c9b4a80ce605a4c156f9982n/aHeodo
2022-01-21609225209936.xlsxls 13c3fec523cfe8ac14a7e78a8e2ca86dfd3b8bb8447eb7e733e7b1207de5bea6Virustotal results 33.33%Heodo
2022-01-212165604348620294442.xlsxls 6232ba47b182fc60d16bf5b9d41f5dc614f2f348e83414c533df7ccbfb940885n/a Heodo
2022-01-21640103271878681.xlsxls 702e9fcc889535f1c31e1bad34de6e4456520ca0687f9240a318140924bed3cdn/a Heodo
2022-01-211127776573779480.xlsxls 539a3855a176457a29262e61d738250050450a8a6adb2b1e9c8961a40a6cad57n/a Heodo
2022-01-214081419011184855437.xlsxls 053d625d162a5e1ad61603ca7d6dfd915cc175e991eaf3377a55b00853fabd07n/a Heodo
2022-01-2185823198388857.xlsxls fd0a745d8df31045d5044a9ad6c5efb7c678826f14a463a5cf2abf91cd0c1014n/a SilentBuilder
2022-01-2147209021875160.xlsxls d26fa50d28f1d5fecfbd935c7c439e19ed0336097938d366f8d2cb3e8c039824n/a Heodo
2022-01-2126288523944113691.xlsxls 9eb1535c5aaefb0a3a2b583a4aad8ef65f55b805294dca339ab2f8e632ebffedn/a Heodo
2022-01-2100770026827266065.xlsxls afb4a25125020d107aa065816ff0c80dfbc85d700a654a29b73aa8143c2e909fn/a Heodo
2022-01-21668935661742223.xlsxls 2cb043937c5838c3f91d3955127cc444ff420b74448d38395ab177b8369753d0n/a Heodo
2022-01-217783923841042127199.xlsxls 278e2b44764f4223799867c585d886b7fe57313055f5f82d983f7e13e1a49aedn/a Heodo
2022-01-2153344071593623360.xlsxls 3accfd2337522a6c68a1018979e3ac6603237e13aff0b962ae093662129d8609n/a SilentBuilder
2022-01-21250004219441.xlsxls 4520398e8aeabb1aed9cd4899a2ac014545d9ad9383959288cf2470f9c1c4731n/aHeodo
2022-01-2152428852956422.xlsxls c3deaaa5202a717b68951cf04c00e24200a91aeee0eceb58cc032a0471fbda36n/a Heodo
2022-01-2181730510275008040.xlsxls e57baf9289180802e131633ce599fd55a0a67db3423c45d62f4a88fbf94a0874n/a Heodo
2022-01-2182519935978.xlsxls 01bab18ffb7052e8d67dc6447267ec775667a721592e609cf62dd08649d7a807n/a SilentBuilder
2022-01-216051824245725272.xlsxls 9296f02a362c27b1e3a3b4119ede64ea52b6c0430fc70517e5146730c23c987dVirustotal results 22.41%Heodo
2022-01-217414754328340.xlsxls 561f1541d1ce60dd8a10c61c54f99d83e67ed86b0f645a6e564a99baa08f56b3n/a Heodo
2022-01-201349156096979071.xlsxls 2d259bd946fb388d1a7d75d28ba591aca3377e0ca8b49e0add414fe82b76f483n/aSilentBuilder
2022-01-2085437390889.xlsxls b0e176129f7c1c4ae1d31d420d8ecacaceb6c4682002848a769d98e4b0f21399n/a Heodo