URLhaus Database

You are currently viewing the URLhaus database entry for https://group-celit.com/img/bqLL1uiRPRIsjGd5uM7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122865
URL: https://group-celit.com/img/bqLL1uiRPRIsjGd5uM7/
URL Status:Offline
Host: group-celit.com
Date added:2022-03-30 16:46:06 UTC
Last online:2022-04-08 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 16:47:06 UTC to abuse{at}gigared[dot]com[dot]ar,abuse{at}gblx[dot]net,abuse{at}gigared[dot]com[dot]ar)
Takedown time:8 days, 20 hours, 7 minutes Bad (down since 2022-04-08 12:54:22 UTC)
Tags:emotet link epoch4 heodo link redir-doc xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01XJ-009097739.xlsmxlsm 4207d8837943656e62fed5e7f98e6247c9a5d63d460a7bbdbb4296428051b3e4Virustotal results 45.16% Heodo
2022-04-01VRK-7150559.xlsmxlsm 6ed54827dec62355fd8b2ea657c6ddba821096f92b961dbb54c92fda72f6bee9n/a Heodo
2022-04-01CEF-46263313.xlsmxlsm bba184efb454972191ec837362eddc4ef35f60b616033ef54cbd77d1a70f8f3fVirustotal results 36.51% Heodo
2022-04-01LMD-22336889788.xlsmxlsm 303c09084f427ef59bc3be795f3eca2fdbe4a953816cee78c711da6d57a944b6n/a Heodo
2022-04-01ZQ-6692860.xlsmxlsm 67761263609b4bd35b14d39f6eddb7e7554a73b9d317d53d533dac64ce3f30d4n/a Heodo
2022-04-01SBR-57714971288.xlsmxlsm 004f6c9fad398f8dda13f421a6faa1a78916ba04c3eabe988acd669f8cb1b112n/a Heodo
2022-04-01QO-70716156007943.xlsmxlsm 5ee7da1557872d5aa45f2b0dd720348fa08f31e3b2b3bb5aa5fcac583cc2d9adn/a Heodo
2022-04-01VU-0812976018.xlsmxlsm 0c4ef4b03683b5c927b33e01bc6c59d7e6af72175bf42280dbe042b628d56eaan/a Heodo
2022-04-01SPU-933541226.xlsmxlsm 393d4fe454720708127a511564d5d5aab745e714a3e0dedafea5aa94c2d4980en/a Heodo
2022-04-01TP-8281496771480.xlsmxlsm 1a8adefa7d083432f592ddc3797611b4e8076869a11177ebbdc1b5b6bc22982fn/a Heodo
2022-04-01HMO-847389378.xlsmxlsm 4fe9cdc6b35e9992d206f5a0bb6ebcb063618ed502e651ba2f5c014a2aea5776n/a Heodo
2022-04-01CPD-2720251308506.xlsmxlsm e99a1144b3f8e1ef8f39b170d03c0b95f551aef01c0f6ad02a526b61bdbd0442n/a Heodo
2022-04-01CNC-26848892230665.xlsmxlsm d3052eaa2931548083181b1e4724bff791218f947c3f7640f9efeabeed21244cn/a Heodo
2022-04-01YJ-55103371136093.xlsmxlsm 05aecb805762b1c7cae04f8f46d0d43392d1b6e4880c93d82f69ef52d8dd2660n/a Heodo
2022-04-01JTO-62416899563590.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 43.55% Heodo
2022-04-01QAW-76767285452669.xlsmxlsm 764dc9c37da82215bfa8dce451fc0946c901984084015a98478a65bd670835c2Virustotal results 46.77% Heodo
2022-04-01RTD-8156520884027.xlsmxlsm b7a2ba71c06e47b7011fb3b7f3a263a34c991d3eead33a69dbcf967bdeda5a96n/a Heodo
2022-04-01KQ-3798035586836.xlsmxlsm a88019c1e8c87847f6816dba7e30475a768da155993e7fa208063dffd2422811n/a Heodo
2022-04-01KWN-56400530.xlsmxlsm 3005686dd6b770a4a0af0ba70ec91ea407d32838aa2acea56c5ab75f2a47ff56n/a Heodo
2022-04-01KP-8314340870720.xlsmxlsm a3daf38a9efabc78999651c2b0f4afd47af19450cb0b3f4492221c20b7590c71Virustotal results 39.68% Heodo
2022-03-31HUZ-0493623401.xlsmxlsm 816139a521f5f7194347aea048e100b8893fa8ce7d6a86910a72bb190425e553n/a Heodo
2022-03-31FQ-903848716877.xlsmxlsm 10ce10aeef8f6d0f3daf5292f589879e748af9adc9d29ad0bf9143c2115cfa23n/a Heodo
2022-03-31WG-589721551343241.xlsmxlsm 47033d733745aada415882d83566cebcc301505ddbb55d72e84ee221332e812bVirustotal results 34.92% Heodo
2022-03-31ZL-161291591.xlsmxlsm dffde7ff06d4b4d38ae8f02750d5c59b2a1a293d05af04210b8e79d0b3fd4043Virustotal results 38.10% Heodo
2022-03-31ZC-1898458.xlsmxlsm a395d2ca627270c1b53481050d39c6395c778682e98aeedcb00d1f68fd1ec23fn/a Heodo
2022-03-31GNR-8303666568.xlsmxlsm 522056ad088097c5c827ddabc4a8e7ad95b16563043dcfde8aa2fc4b0df81a1fVirustotal results 41.94% Heodo
2022-03-31RC-35117685748370.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31LRM-439442276061875.xlsmxlsm fcefa2ebaa9e5cce06f5519640eab5413a9b9f6a53ed3fe2f3754c9a610418ban/a Heodo
2022-03-31VD-040501166177.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31AJW-498997731435390.xlsmxlsm 2550670f68b05aae7f04bfed13c37b7f3ee48a1677ac9eef2e7c3c0a88aefdffVirustotal results 43.55% Heodo
2022-03-31CY-2208172.xlsmxlsm 409e55effd488af9a3d098060e33fe5d66743135fc711a07d6ce4c57e2f2c2bbVirustotal results 33.33% Heodo
2022-03-31BOE-53875870693306.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564Virustotal results 38.10% Heodo
2022-03-31OBE-2012755357.xlsmxlsm 287f8b49b0107a7e303a4d327d34a8fe117d4696af06bb3bbd73d25e5a39270fVirustotal results 40.98% Heodo
2022-03-31ER-3971219.xlsmxlsm f869263419a75a1350a78400b9e3dd186488c7c76d299e7984af7e5e0c91d75dVirustotal results 37.10% Heodo
2022-03-31YZ-4920422062.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31EK-53451932.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-30UCK-161661740093.xlsmxlsm 41f790fa1e0f18e897bdad1de2c9452310c964ab0c50e831d9c1150af849edf4Virustotal results 40.98% Heodo
2022-03-30NM-40584828.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30FO-68429659.xlsmxlsm 2e8dfaff0039f7b69af5f699d0efff85cca1b5dbe2a50082b7ccc49503545053Virustotal results 32.26% Heodo
2022-03-30AFG-954538748.xlsxls 46218e7a1f860f4758adfd19dc3b12e27771a613ca00f687ccbe48a0c275f83eVirustotal results 26.67%Heodo
2022-03-30n/ahtml e0eed26816e212e69a163e8cfe37fab3fe7e63f841a87153441cb80c7459723bn/a