URLhaus Database

You are currently viewing the URLhaus database entry for http://facts-jo.com/init/I1kZedDNMqtRiFo83xv/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120501
URL: http://facts-jo.com/init/I1kZedDNMqtRiFo83xv/?i=1
URL Status:Offline
Host: facts-jo.com
Date added:2022-03-29 20:19:04 UTC
Last online:2022-04-05 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 20:20:07 UTC to abuse{at}inmotionhosting[dot]com)
Takedown time:6 days, 8 hours, 59 minutes Bad (down since 2022-04-05 05:19:46 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31ZHV-6049142.xlsmxlsm 522056ad088097c5c827ddabc4a8e7ad95b16563043dcfde8aa2fc4b0df81a1fVirustotal results 41.94% Heodo
2022-03-31BE-73717320.xlsmxlsm c201ae0ab0516a27d14400b4af28d4189bb2c6d8b589c4fadb025c26645f19bfVirustotal results 38.10% Heodo
2022-03-31GWA-856301526.xlsmxlsm 75f0362196443080531377973dbab9153eecc5ae78da6a2e94b492580d2bdf7an/a Heodo
2022-03-31OWR-074632042540.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31DR-7922196651.xlsmxlsm fcefa2ebaa9e5cce06f5519640eab5413a9b9f6a53ed3fe2f3754c9a610418ban/a Heodo
2022-03-31XTY-132871282092.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31HQ-5026840.xlsmxlsm b0fa5dda99558a54917cc9a5f6269d440cd8b30ed825f72c837d6e4044d9f628Virustotal results 42.62% Heodo
2022-03-31BCD-000139669.xlsmxlsm bc2b30e9969aa7dc11544b73955d47d12ec3d2febe998b5cef4b57c89dde7215Virustotal results 36.67% Heodo
2022-03-31ZI-0206971.xlsmxlsm 4e313f9f3abefe7d2a05b2d9ce9dae1683f91278ec0ac7cff68b9f232ff656dcn/a Heodo
2022-03-31PZG-3863458.xlsmxlsm 9490224310276e55dea4f02cf1d9c3c81919929e8abc13c37b670025f1f7a3d0n/a Heodo
2022-03-31GBD-17512641.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564n/a Heodo
2022-03-31SOH-711818066.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31NXD-4467785528132.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-30NE-7123640.xlsmxlsm 41f790fa1e0f18e897bdad1de2c9452310c964ab0c50e831d9c1150af849edf4Virustotal results 40.98% Heodo
2022-03-30AD-077732438.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30PRZ-82556102112281.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30KVT-35963914490520.xlsxls 2fb5d6b4684b1f180fd682f92fc346420c16376d64b8b8ec6b0564247000dc58n/a SilentBuilder
2022-03-30487621726854.xlsxls 3493b3210a3ce325a05cc7da5ffc69d323e0a0a645d8bdfaf1016a2de52ee1b5n/a SilentBuilder
2022-03-3024898228400307097349.xlsxls d50ff37a85433702c1107c3f20efde94efa785c44886033b550035b23d873ac1Virustotal results 27.12%Heodo
2022-03-3098650512047735866691.xlsxls 6fc96a58c317377d9ff8276f95b48d0891d63dfae2c3ec8b8960037107578322n/a SilentBuilder
2022-03-30450341676484.xlsxls 517ad9640522ddd6180f39e1bdf5dff22b469b04cba6c10f4c0d6e3bcca16b19n/a SilentBuilder
2022-03-3096114613017.xlsxls 539de96d81ed4955f2d70a8c888ba181357736c83b1c56383797bb82f18abb52n/aSilentBuilder
2022-03-305032393195916019020.xlsxls ee62c21812ad75d0a17a1ddf79a52ee84205a1d7f1d63b74f396b80a4ac87c13Virustotal results 26.67%SilentBuilder
2022-03-308948353931604.xlsxls 5206671cef156681bda1a374c1140c4dc8e4796b93d323161c15c6767afe3fcfVirustotal results 23.33%SilentBuilder
2022-03-3044571354726.xlsxls d217d4620ec326b500ee3c5bf7d6a1e37058b93ab33672857f966bbb0c627c6cVirustotal results 25.00% SilentBuilder
2022-03-309653020257763742312.xlsxls 28c1994bc596421a111c75b795d98b2192edc5aa92b6d1e3adcefd40bd9d0bdfVirustotal results 38.18% SilentBuilder
2022-03-3092271794168723.xlsxls 1f4abd57d6305167ea781e255bf801474d77d7415dc16bfa03bcd9c6afb8e977Virustotal results 35.00% SilentBuilder
2022-03-300127256157662926.xlsxls b77b0ef522691f56c326dbd8bfd07faa9b30f9426461ff385a1e744c3e469678n/a SilentBuilder
2022-03-3009483769350524576.xlsxls 667216eb30cfe1aba7324cea583930673acf6e334b4c2c8221225677b35ef430Virustotal results 23.73% SilentBuilder
2022-03-305072442885740.xlsxls 73a7d36de3e4f7ddc7f714ff205b0ccd1660020f04898ec79764150268cc31e5n/a SilentBuilder
2022-03-30273871634888099990.xlsxls c608ea84421874b786b035d63940ce5c0eb73d5ae08770bffa1fa700bca152dan/a SilentBuilder
2022-03-3008843893564371440906.xlsxls 4148c2fcfeafb479b13ec8c2b305fd2ebf671b61fe044476575a5b2be2b929dbn/a SilentBuilder
2022-03-304526209173144.xlsxls 19f6caa7a30df844b400ba5f224bd75901e715d328ef9a38903900f0fa773946n/a SilentBuilder
2022-03-301950972597803768.xlsxls 905937ee43f2fc5221d18f42e0e1b2514bd1059016ddac70a5fe00c2092cf34an/a SilentBuilder
2022-03-305020005892671162.xlsxls 0064a9e50d81734b02d6e46a0c7438caaac87d97c3a8d2e252d116c08094820bn/a SilentBuilder
2022-03-301787550685.xlsxls 9b99b5267d749deddfae5b4090ea4c80afefc23d7379a09618857f7269837c51n/a Heodo
2022-03-30837282893966403.xlsxls b53e7fd809f9e654c0d9d6d4f0aa797529daadc82b205bcecc3b564b45892ac4n/a SilentBuilder
2022-03-304492409388.xlsxls 9e011d77b179dc3075654faa2f570ff83e31cb879ef14891e49805831790a329Virustotal results 25.00% SilentBuilder
2022-03-3012293266895.xlsxls f736398345593d7694cc483eef6daa8b0530fe9ac5371d53d29f75e4ac5293fen/a Heodo
2022-03-30308075414662093461.xlsxls f37c6c8662785514f852d04f94ac6b2217b3c5244e84dae528f13c5b8b95daecn/a SilentBuilder
2022-03-301407170505706304281.xlsxls c014caec272f00448f32115b18b4c88c92ee9e4601ba0e8a8b6912d62c76ef70n/a SilentBuilder
2022-03-30545950277479987430.xlsxls f1b73fd1204e5bfa3f5278a6245d5b69398b19c90505606a6fb07444862ce2d3n/a SilentBuilder
2022-03-295322503790.xlsxls 06b7e588b68d71fcb7b846c7d529df9b5734df14d2059bc6470b9542c9e4360cn/a Heodo
2022-03-2957814437825045944.xlsxls 77dfd2987cf0ee8e69322b8acfde50b12f8deb4b7c5d7ee754f98dbdc2b04bc1Virustotal results 22.03% SilentBuilder
2022-03-2909998054992.xlsxls 3e97f09fc53890ba2d5ae2539b5c8df372ed2506ed217d05ff2cf8899d15b8e6n/aSilentBuilder
2022-03-2964678955860227.xlsxls 6741b0effa1844c85e25015d8c01ab0330e793dc563cfe2977746f5eb7a37fd3n/a SilentBuilder
2022-03-29764007225796155628.xlsxls bbc1337630f46853905e7fa804eb8bf2b3644f3a16a1911ea1fbd7fe1811c1ecVirustotal results 22.03%SilentBuilder
2022-03-294611056402660.xlsxls 7afe6200950f155c027ed0e711a8400a4afdc11f99603506b75ffc757658d460n/a SilentBuilder