URLhaus Database

You are currently viewing the URLhaus database entry for http://ftp.colibriconstruction.net/cc/sOY0Z/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120603
URL: http://ftp.colibriconstruction.net/cc/sOY0Z/?i=1
URL Status:Offline
Host: ftp.colibriconstruction.net
Date added:2022-03-29 21:45:04 UTC
Last online:2022-04-03 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 21:46:07 UTC to abuse{at}lws[dot]fr)
Takedown time:4 days, 3 hours, 55 minutes Bad (down since 2022-04-03 01:42:01 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31LSK-6243631.xlsmxlsm 73a1d60faa31200f09f2567671137d6b5f9be02a97eec33fc20971d151d5c8f1Virustotal results 38.10% Heodo
2022-03-31NMH-7678466704.xlsmxlsm dffde7ff06d4b4d38ae8f02750d5c59b2a1a293d05af04210b8e79d0b3fd4043Virustotal results 38.10% Heodo
2022-03-31TP-71868370.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 35.48% Heodo
2022-03-31IDW-4692604786514.xlsmxlsm be738143f60cb6f52b7bb48b7a9b84e25571305dd32c5fddaefd80ad1dd80b27Virustotal results 42.62% Heodo
2022-03-31CIU-302812817344.xlsmxlsm 75f0362196443080531377973dbab9153eecc5ae78da6a2e94b492580d2bdf7an/a Heodo
2022-03-31JGB-2603762.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31ZB-934886752703548.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31KJS-137362795264.xlsmxlsm a1057f814e603d7b7ff7b711305cac0ef15e48b78499802d411424a19ee235f8Virustotal results 40.98% Heodo
2022-03-31IO-94155297951.xlsmxlsm 9098c46a233798193c0587711f5a9be2a4aa97567db08504452748dde516053an/a Heodo
2022-03-31OLQ-969191168696.xlsmxlsm 578e2f6c9e64cb4de6991bae88f0e1e8d38afce9fb954c64d9ed303053647d94Virustotal results 38.10% Heodo
2022-03-31DPP-661857213.xlsmxlsm bb415157a1b9bbe60b44a718eaed436370f6a07df786986c3adde6f5f22c12feVirustotal results 39.68% Heodo
2022-03-31EL-667809655832349.xlsmxlsm a099f9c9c8eff7049da288a1205f1c0ccd52a4954930cabdd7a00dafbe8bbe6dn/a Heodo
2022-03-31EOH-876475446075896.xlsmxlsm a43da1637de01a06d72a9d09981de5132b8bd971844704ee9fc7c5e07450a49dn/a Heodo
2022-03-31EL-0496141819.xlsmxlsm c91108a630fb89be6e53e693ea5240bc7be18d74be099b965d92647bd239c6bfn/a Heodo
2022-03-31JFD-65049213935097.xlsmxlsm f93f882fe4bac2b1210512c64a2985c99282b49a95a2aaa3bfcf6865d6dd0056n/a Heodo
2022-03-30QOP-099549475912.xlsmxlsm d3ad5641b527c4ec7e77e037ed81f1913c394f063e13677b8744b26fb09bdecen/a Heodo
2022-03-30XZX-04355300604045.xlsmxlsm 2909468da77be7c90d3c57fa66be2e6250afde34bd400f2c815be9bfd89be7ddn/a Heodo
2022-03-30NH-75399161.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51n/a Heodo
2022-03-30DE-33651157728.xlsxls 82be92d18fb73fad9b6f0e90da074abbf2aaffd91c4493491620452f19bd281dn/aSilentBuilder
2022-03-300572193078249061221.xlsxls 7324fd5254825996acb024055b8f85c89b19897ef327543836bad401b074d0b6n/a SilentBuilder
2022-03-30742007311673.xlsxls e5eb6472a9ddc2f0f808a992ef282a1041cdd7fc37af5cd3a7e90cd3c0466008Virustotal results 27.12% Heodo
2022-03-3070009324647.xlsxls d50ff37a85433702c1107c3f20efde94efa785c44886033b550035b23d873ac1n/aHeodo
2022-03-307590217569359979875.xlsxls c2300b5d42357aec3b193bd2b998f9310b6d2656dc87e0ea5d4fce958c07f315Virustotal results 27.12%SilentBuilder
2022-03-300282147316564294565.xlsxls 48f8db12e68c170ee127dbfc92d5052aecb6e381f85910d86ba35b032a7737dfn/aHeodo
2022-03-305792093212709524.xlsxls f3566d44127d0f6eb363de3be31b3ea1a8fcc667fad5aaea2db948a4a728cc41Virustotal results 25.86% SilentBuilder
2022-03-3015387179815984734957.xlsxls 0064a9e50d81734b02d6e46a0c7438caaac87d97c3a8d2e252d116c08094820bn/a SilentBuilder
2022-03-3033071890518804788724.xlsxls 153ed0822091516925dc6d0878a91cce7c48cf3015c7b66490832a19bd11eb4bn/a SilentBuilder
2022-03-3098217880018712721.xlsxls a4206c582c5af97000782abf9ccf8ccafa231a34f5a74ac9b534286ef656d253n/a SilentBuilder
2022-03-307336014629817308.xlsxls 9e011d77b179dc3075654faa2f570ff83e31cb879ef14891e49805831790a329Virustotal results 25.00% SilentBuilder
2022-03-301339703176067612.xlsxls 7750729ac7ac67c70c2263d1795171a4181f7821da3efa5be8a41060489fe24cn/a SilentBuilder
2022-03-3055293934324904879.xlsxls 39e9199a1a4f3bdec4b6df74937c1a5b178d8f55f2a9ed84a1480e5dbb2be75cn/a SilentBuilder
2022-03-3092566507441.xlsxls 01409366f137f73a060ee83b1e33ce1812614f9182737ebfa8b621d931f2aef4n/a SilentBuilder
2022-03-308806158895.xlsxls 6e59acf9d3a2753b58d6e85224cd82fa45cd9e7e392cc4bc18d0577ae539036cn/a SilentBuilder
2022-03-29667483740483.xlsxls 5945c872c336b1839e2d24e8ade8c28cd4bfda3b45281798c978e0989334a219n/a Heodo
2022-03-29699261232256306608.xlsxls 8df3f2fcef32aec4125e68197feb793704dc9d4dc3a7a2b06a048774cbbb2a62n/aHeodo
2022-03-2912555556314243984206.xlsxls b26329204d4a737b51b710c6fb4ca573291be87a1fb5606f0e0b75987c09908fVirustotal results 23.33% SilentBuilder
2022-03-2919760230951268423.xlsxls a679c80a799b163cf0ad3f464c4a1bc023c7d6dd0715662da376d6260a4b9040Virustotal results 23.33% Heodo