URLhaus Database

You are currently viewing the URLhaus database entry for http://facts-jo.com/init/I1kZedDNMqtRiFo83xv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120499
URL: http://facts-jo.com/init/I1kZedDNMqtRiFo83xv/
URL Status:Offline
Host: facts-jo.com
Date added:2022-03-29 20:18:07 UTC
Last online:2022-04-05 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 20:19:05 UTC to abuse{at}inmotionhosting[dot]com)
Takedown time:6 days, 9 hours, 38 minutes Bad (down since 2022-04-05 05:57:40 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31ZHV-6049142.xlsmxlsm 522056ad088097c5c827ddabc4a8e7ad95b16563043dcfde8aa2fc4b0df81a1fVirustotal results 41.94% Heodo
2022-03-31GWA-856301526.xlsmxlsm 75f0362196443080531377973dbab9153eecc5ae78da6a2e94b492580d2bdf7an/a Heodo
2022-03-31JX-68541683985.xlsmxlsm 764dc9c37da82215bfa8dce451fc0946c901984084015a98478a65bd670835c2n/a Heodo
2022-03-31RYZ-0669829.xlsmxlsm 36828e7a04990e1d0b2b67ccfa64ea170ff92c77cf92107d904f1e106c1d676bn/a Heodo
2022-03-31MUI-17390009564705.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31HQ-5026840.xlsmxlsm b0fa5dda99558a54917cc9a5f6269d440cd8b30ed825f72c837d6e4044d9f628Virustotal results 42.62% Heodo
2022-03-31BCD-000139669.xlsmxlsm bc2b30e9969aa7dc11544b73955d47d12ec3d2febe998b5cef4b57c89dde7215n/a Heodo
2022-03-31BX-8551521753.xlsmxlsm 9098c46a233798193c0587711f5a9be2a4aa97567db08504452748dde516053an/a Heodo
2022-03-31RNP-790254414746.xlsmxlsm f88eb7101fdc0fe20190969ec3bb4651bf4f270d9a9636d6c1e1a84ae46a9cd6Virustotal results 37.10% Heodo
2022-03-31XPY-2561642915.xlsmxlsm 39bbb570609ea300f9d959dcf23f2161043c6dedc230f97e7eab2388db651831Virustotal results 38.71% Heodo
2022-03-31GU-11765578.xlsmxlsm 2617b3b15f0d97a163be4c1cf6df03a45313c05bf0f36c3c2b37e56732608493n/a Heodo
2022-03-31JB-6293069401.xlsmxlsm 4409b097292f1ed1adedbae38fcecf71370a64209f9bb5ffff019b71e8a88533n/a Heodo
2022-03-31HT-3886464.xlsmxlsm a4e22b806505d549a037a67123efb6b397193d7d2ff28e32d8b73185438fb5acn/a Heodo
2022-03-31NXD-4467785528132.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-30NE-7123640.xlsmxlsm 41f790fa1e0f18e897bdad1de2c9452310c964ab0c50e831d9c1150af849edf4Virustotal results 40.98% Heodo
2022-03-30ME-07079738989340.xlsmxlsm 08e64e582d9d42f5f3a21eaff52bcb72b4a3abfc761561ff28f40bf937dedb2cVirustotal results 35.48% Heodo
2022-03-30MHA-108878327165326.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51Virustotal results 33.87% Heodo
2022-03-30CQR-929082964.xlsxls 34c12fb797211966f38e1025e683ec8ecc00b70e39d5f463213f7b09eea896c4Virustotal results 28.33%SilentBuilder
2022-03-30XKU-058324459.xlsxls 7813b5f2ba1876b183aec911e5a55402903c7b4702fef4c3c0055557490ef04aVirustotal results 28.33%SilentBuilder
2022-03-29n/ahtml f7a2fc3db9eb451d57dc07927c4168228b9a178d323921bd167634713604967en/a