URLhaus Database

You are currently viewing the URLhaus database entry for http://helmprecision.com/Helm/main/css/zkWu29ADVHwfnAZQ3rQSZx/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122757
URL: http://helmprecision.com/Helm/main/css/zkWu29ADVHwfnAZQ3rQSZx/?i=1
URL Status:Offline
Host: helmprecision.com
Date added:2022-03-30 15:41:05 UTC
Last online:2022-04-04 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 15:42:09 UTC to security{at}level3[dot]com)
Takedown time:5 days, 0 hours, 2 minutes Bad (down since 2022-04-04 15:44:28 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01DT-9241364543379.xlsmxlsm 2ac3bf7095647237fe3a5bd46c3c7e85f0332e2bd3b8024452aad240a740c064Virustotal results 44.44% Heodo
2022-04-01HS-34767075271.xlsmxlsm 7e16b96f674b1b3fa812fb1720851a37cb88e781ae92220bb858320fbe62c331Virustotal results 39.68% Heodo
2022-04-01AP-23644170592.xlsmxlsm 534f4ab246459c91599d4d14e916a2f16707134075a5a88d897105a0e782632bn/a Heodo
2022-04-01FRD-80776309133.xlsmxlsm 2efeae28ad35e91b7abb28eec555e20e394693d8454514a43fc119fde473348en/a Heodo
2022-04-01NIR-665110712403.xlsmxlsm 004f6c9fad398f8dda13f421a6faa1a78916ba04c3eabe988acd669f8cb1b112Virustotal results 39.68% Heodo
2022-04-01HJ-318347849444.xlsmxlsm 5270afd30069d36cee5d2bb013f3d1d7765e90cce7cb4d7244c92a62596f108dn/a Heodo
2022-04-01OH-2692805609.xlsmxlsm b25b9d420c3585bd014abd2e590a74feab98bbb0ee612c465a5e152b28c67e0bn/a Heodo
2022-04-01IC-7821150.xlsmxlsm 8cfdb13bd3fba245b5e3c5a06b90cdab4f8970b13e3ea5262aeb7bd089474bb3Virustotal results 36.67% Heodo
2022-04-01BQ-4164211160.xlsmxlsm 1a8adefa7d083432f592ddc3797611b4e8076869a11177ebbdc1b5b6bc22982fn/a Heodo
2022-04-01YXA-89166325950.xlsmxlsm 4e6c2dd2bb0183aa17caa2084632719d1b9d42cae3e0c96f6770b216822b8d01Virustotal results 46.77% Heodo
2022-04-01ZA-900894083018.xlsmxlsm 6463322a887744e8e04715bf20b67bc671561c87d8cf5ef5d4791ddfb5f1eb0an/a Heodo
2022-04-01WYE-68479692.xlsmxlsm d3052eaa2931548083181b1e4724bff791218f947c3f7640f9efeabeed21244cn/a Heodo
2022-04-01ANO-879006316388434.xlsmxlsm e407f7217907368560ef28caf164f34190a5295c4c75afaaeea21386e8bed99cn/a Heodo
2022-04-01WU-174474825451.xlsmxlsm c201ae0ab0516a27d14400b4af28d4189bb2c6d8b589c4fadb025c26645f19bfVirustotal results 48.39% Heodo
2022-04-01TP-1169107001.xlsmxlsm 9ae3ff917d99c0e0ba1f6dde3bcfebd781ab332d65552b032855ca627606cccbn/a Heodo
2022-04-01GI-52645437954334.xlsmxlsm b67f378396a813307cf0d9d7c4f272be83010272fcfa9af1791b517cf4f1ba05n/a Heodo
2022-04-01TRM-078018750524692.xlsmxlsm ff29c4e7acfa113d826b2fcfcc5e8dea43a58a5db3ad37376750c95e58335050n/a Heodo
2022-04-01WPC-891448017886611.xlsmxlsm a88019c1e8c87847f6816dba7e30475a768da155993e7fa208063dffd2422811n/a Heodo
2022-04-01YK-3969392360284.xlsmxlsm 57a73cab7fb65bf97b094b8ea188937cff862e7e55cb179ad32cc6d9200d8855n/a Heodo
2022-04-01IHZ-7156876.xlsmxlsm d32c4d0a8c9ac509e3acbd4b041b2d01cc771c0e20828ebd64d2d8fbf49fba7an/a Heodo
2022-03-31WL-10907914804247.xlsmxlsm 5fb54e96fe17c395fa69dc06933558b083ae9cfb1391218f12c539c2645a8311n/a Heodo
2022-03-31JK-1052518292489.xlsmxlsm c7f63ce6becdd48402150d223d11b5fb003ec48c57f2d856c8d979e5b3da4254n/a Heodo
2022-03-31BHG-4446378237.xlsmxlsm ccd9dcb6dc115061ff6e011cb77ac0c73d785a23c2019aabe11eba9b7500b118n/a Heodo
2022-03-31DL-656043800.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 35.48% Heodo
2022-03-31DPL-810094208.xlsmxlsm 99bacd00ff714e00339dc64c1418b2c0c26ca69120e34bd32ba8e73d2044cd9cn/a Heodo
2022-03-31UXQ-01709383642.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31OYR-498276096875558.xlsmxlsm 9c234ce84ff77dfc1466c436eea9d46c50c3055c50f0029b81dba5052864f4ban/a Heodo
2022-03-31NIL-0836708396.xlsmxlsm fcefa2ebaa9e5cce06f5519640eab5413a9b9f6a53ed3fe2f3754c9a610418ban/a Heodo
2022-03-31XO-4672007.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31NQE-8304045290874.xlsmxlsm fea58fae76c86e5f07c7f8b032f84174206bc489d92c49fe54a5b51d2658faf8Virustotal results 34.92% Heodo
2022-03-31JAQ-8615820485549.xlsmxlsm 97f11e4cd509aefb731d8b1a4b299c8ab4096e270f05f52d8e0eb6d2366fa501Virustotal results 38.71% Heodo
2022-03-31FR-87936655337622.xlsmxlsm 3f0534a7da98fb167cda2d3abd3e89f8f8f0ec65bd7146de1ad2ce762f1486b6Virustotal results 40.32% Heodo
2022-03-31XI-77879708734204.xlsmxlsm 409e55effd488af9a3d098060e33fe5d66743135fc711a07d6ce4c57e2f2c2bbn/a Heodo
2022-03-31KKS-74852720596864.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564Virustotal results 38.10% Heodo
2022-03-31WIU-4153527568264.xlsmxlsm 41a73a914406df97e2944f7742f48272bab7d25486c9c2a5084a7f158fdb2aafn/a Heodo
2022-03-31ZI-2625418750.xlsmxlsm 4409b097292f1ed1adedbae38fcecf71370a64209f9bb5ffff019b71e8a88533n/a Heodo
2022-03-31WO-649567053926.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31GC-46540396.xlsmxlsm db67f0509c5f982c9eb1fab5a17d14ea07d5a1e13b2f5ee3b35ccf93700588e4n/a Heodo
2022-03-31NL-1208713184709.xlsmxlsm 7bd47c2f3e932a049d450f5a54be51e401ea041d669c7df91f71b903358f99d9Virustotal results 39.68% Heodo
2022-03-30ERL-500298488611075.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30KL-0152320082109.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30CDH-392938455489.xlsxls c83aefdafdc478ffff051002d1c7b4675c068648d57fca17f788d575ce297596Virustotal results 28.33%SilentBuilder
2022-03-30QV-13737791.xlsxls bc8049d90da2c6ed214cd043d2d754a1f8fc802010a6367d5cac254aa1853a67Virustotal results 26.67%SilentBuilder
2022-03-3054794795752.xlsxls 2cb06bc703f4db3b4f3d5d574ea8ffea1629ff6166037191f58ef01206ca0ef6n/a SilentBuilder
2022-03-30263150384944.xlsxls 8a6effb1430c591fa0e6e8ac6f84b1991bf8cc18f70a432ae63e6bda131914c6Virustotal results 28.33% Heodo
2022-03-30247322939472446115.xlsxls c2300b5d42357aec3b193bd2b998f9310b6d2656dc87e0ea5d4fce958c07f315Virustotal results 27.12%SilentBuilder
2022-03-3051125148011859192.xlsxls ec525c39ad25d59ac4ac1f1de75dca892bfda29514701e4bf109f00894895fa5Virustotal results 26.67%Heodo
2022-03-30463753010614021035.xlsxls 3e7c9a89e957262b014b07250f015ccefdb050661e9564930d813c033a96b2e9Virustotal results 23.33% SilentBuilder
2022-03-301427337730865.xlsxls 5206671cef156681bda1a374c1140c4dc8e4796b93d323161c15c6767afe3fcfn/aSilentBuilder