URLhaus Database

You are currently viewing the URLhaus database entry for http://dulichdichvu.net/libraries/63lx8/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120212
URL: http://dulichdichvu.net/libraries/63lx8/?i=1
URL Status:Offline
Host: dulichdichvu.net
Date added:2022-03-29 18:20:09 UTC
Last online:2022-07-03 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 18:21:15 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:3 months, 5 days, 21 hours, 40 minutes Bad (down since 2022-07-03 16:01:26 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31YC-104999416328.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31NA-8291067.xlsmxlsm 896ef5fb12bd10c84fa96213d6a86aa368388e4806b9c882fd601a113482ff74n/a Heodo
2022-03-31VXE-61962900867240.xlsmxlsm 36828e7a04990e1d0b2b67ccfa64ea170ff92c77cf92107d904f1e106c1d676bn/a Heodo
2022-03-31NO-6485666090.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31NV-380783709911376.xlsmxlsm b034cfc88c6603dc0f5519ecba2dbba8c5382b26b8c25da23f8d40368ce8e7b5Virustotal results 33.87% Heodo
2022-03-31NG-5129259660.xlsmxlsm 4d68481027dc3987acbc7b6e5a8e958cfdcee70287facb9764a512bcf99b1798n/a Heodo
2022-03-31SK-612104993627.xlsmxlsm 54bb2433c32ae91e6033d49276536fd303652e555e7d1cdf5e1aa0bf9f483d18Virustotal results 40.32% Heodo
2022-03-31WYP-5943264.xlsmxlsm eb39b29661d81cbcd7a00f191c61ce9902b80b68e1e03215e56221bfc85863efVirustotal results 39.68% Heodo
2022-03-31CLB-510631435.xlsmxlsm 41a73a914406df97e2944f7742f48272bab7d25486c9c2a5084a7f158fdb2aafn/a Heodo
2022-03-31AQ-9085905005899.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564n/a Heodo
2022-03-31WP-86000860826.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231n/a Heodo
2022-03-31UK-63262474898.xlsmxlsm 355981d4c8400968deaa8a13a04a79c90bf9aab795af2ff1b3273b825a477968Virustotal results 38.10% Heodo
2022-03-30NTN-98750819906.xlsmxlsm 3bfd193ea92a687030d7b2fb3354e52980ad28ba1cae92579b53f5473b44f37an/a Heodo
2022-03-30PL-6201731.xlsmxlsm ae3937925f18c7db77b2fd19394cb114cb460741dfa2b7c5bd10de9c5c2e35fdVirustotal results 33.87% Heodo
2022-03-30AOP-28080935948891.xlsmxlsm 62d1d7ac5dc3614c29d2cfb29770606387b67506cab5b3e5996c44638a8897e1n/a Heodo
2022-03-30AI-7739643819.xlsmxlsm 93629f0e94046fc0c1c1a2779a8e58d101136842695fc4ad3addbde6c7757dcdVirustotal results 31.67% Heodo
2022-03-30BMG-8797013025.xlsxls 02dcdf42ff1966a5e9b02308ee87de554cecdeb8e8bd8d58b6f95dccc8cd7e79n/a Heodo
2022-03-30808087648766.xlsxls fab59013420b775b3fd0ec46d35267784ccda6fd2c7b8479f2fa578cdc8d45ddn/a SilentBuilder
2022-03-3013643195055750.xlsxls e6816092d6eb5bec7ab8d5463c45994379e212925e29994c9a28a826b9f0ee92n/a SilentBuilder
2022-03-306796475583.xlsxls 8e9fb85ebb086fea213c227c680f15a2a7de9341306b5e10f593744e696b05ben/aSilentBuilder
2022-03-30659511497939408257.xlsxls 4609576ebe318d7f78f3afabd1dc9fa8228b2a4926a14173363c59bb47840ef1n/a SilentBuilder
2022-03-30856762198313415741.xlsxls 4a8dc45ea58de4b92ed3dc2761d4afd8cf1889bfe5d9e9a48ed44f7044d764deVirustotal results 25.00% SilentBuilder
2022-03-302476984220261728.xlsxls 4adccfb55e1dbaf4bc348399dba97bef41a32d54b914f06c7b838930663f2130n/aSilentBuilder
2022-03-30540604396585.xlsxls 82dd13809bbcd68f4c4cb0b98c2c979c8275fd86dfaaeb01eb3c1e17d6a3d990Virustotal results 21.67%Heodo
2022-03-30305935683017792.xlsxls 0629ed421025185f6d11af39101c88cc6d6c1b3d6bf659238b5fb82af185a9e3n/aHeodo
2022-03-3015878438637.xlsxls e4b3720702c9e2904b9acc83e65446087d22bc3011dc99987f2f4a373cfc4fe8n/a Heodo
2022-03-302621958262567.xlsxls 94572bba7488c332400063524bfc88171b7996d51e066f58d4edbb620d5ead70n/a SilentBuilder
2022-03-301557906655377844.xlsxls b4eaeacc2e88877f2ed945d286fb3e537a6aef17314fc0182e7467c4daae0141n/a SilentBuilder
2022-03-302213303733655144285.xlsxls 60e88edf882041b4b5d3d2d44bef62b53fc478dc719df2d61ce6f55771cda593n/a SilentBuilder
2022-03-3077690903388918417.xlsxls 9580b70ecd826b21ad9e0ff4e1a49b40e9f1412b2793d1c838a8dbed34112bf8n/a SilentBuilder
2022-03-3056588343666275019417.xlsxls be30c324bc85d3aa1be2048f89f1cec9c904743add5112f737b689d9f56c1820n/a SilentBuilder
2022-03-300418471807475014.xlsxls 5e42f72b6f48384d2369d13cce199bc20da44c757705ba69765152d0d1d02f96n/a SilentBuilder
2022-03-30444142211827.xlsxls fc11990e224dccd621a3e096de9d3ba9ea970ea8434a56a20ff5dbf00ac1bd90Virustotal results 25.00% SilentBuilder
2022-03-30983433081060.xlsxls 905937ee43f2fc5221d18f42e0e1b2514bd1059016ddac70a5fe00c2092cf34an/a SilentBuilder
2022-03-3069554707455897695.xlsxls 7d9969135b930be92c93aac7e3057b98410a43fd0af360ee02b88b9ad570d116n/a SilentBuilder
2022-03-30433595019595122044.xlsxls 562cb8922d82b50caf2e7452a6db106849432c9577c62aca3f1fd5fe90cd5308n/a SilentBuilder
2022-03-302817341988.xlsxls 8268e3b187b04e9310ead1910af5d33341941f04739fe068e06eb341969b71afn/a SilentBuilder
2022-03-300479495237728429.xlsxls 8afc3601bdf149acb399f6b30fe3188535845cbd8af7c0cf469d02e7524b2b6an/a SilentBuilder
2022-03-30569453081619261004.xlsxls 0ef1d87a8603f19dbb5c1e6352e3668afad3b3c384b0d5b3dc198a3b9786a318n/a SilentBuilder
2022-03-301998279339647254.xlsxls 795d1cb7302f7f2d226a7a50f9a1dfaca81c320aabc71f47113736bc0712a6a7n/a SilentBuilder
2022-03-3034868792068808135.xlsxls 805ea337e3e761a017b54b6a0dd8dacc8e1e05f20f2b5ae129fa1882c4e2ecf4Virustotal results 23.33% SilentBuilder
2022-03-3083050320198196935.xlsxls 02b5337bcb296ecdfcfb246bb1bcb172c23ed58f92126db52f8c135d6eaed416Virustotal results 23.73%SilentBuilder
2022-03-3036721508809713.xlsxls 0d02c7086648aa7d020cc5a5ed181f99f3d51c2c9a2522726d0bf1cc14b9110fVirustotal results 23.33% Heodo
2022-03-299602364877.xlsxls 1dbea40fcbd816ab601a760ef3a43708219096749c335057165212872cf8833dVirustotal results 23.33% Heodo
2022-03-29792231532265.xlsxls 82849ce6e855720fb0463e024aca7d74a5adf9e7dafaeef5b1422982a12d26d8n/a SilentBuilder
2022-03-29028957854925558553.xlsxls cad159477bdcc1a893cefc1b3c89fb0108c077f05f516817b1d9b1c226df132bVirustotal results 21.67%SilentBuilder
2022-03-29238352588440201671.xlsxls 5facd7e6e06801b2f98d8622d9dfa7549dc7fbcc4d2f1cd957f193d81a1e7e31Virustotal results 23.33% Heodo
2022-03-29417627448273690300.xlsxls aa7f8032eea8a66f2a2fcb725bfc16899f61552dfb4e2e7b9c6a4d1bfad9d604n/a SilentBuilder
2022-03-298842105153588467918.xlsxls 912ef80d96550207598474c59820892d1bf52be76ac1c04f833228027a222f0cn/a SilentBuilder
2022-03-2964132837556572835.xlsxls a547aed1d65611b428003c7e43a76e655c5d49d41f62c42f041744d7700922fbVirustotal results 21.67% Heodo