URLhaus Database

You are currently viewing the URLhaus database entry for http://globemerchant.com/platinumcannonshipwreck/iqeCvCc5BcWU6YsraYSIorZuPU0AG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122982
URL: http://globemerchant.com/platinumcannonshipwreck/iqeCvCc5BcWU6YsraYSIorZuPU0AG/
URL Status:Offline
Host: globemerchant.com
Date added:2022-03-30 18:01:05 UTC
Last online:2022-03-31 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 18:02:06 UTC to abuse{at}privatesystems[dot]net)
Takedown time:13 hours, 3 minutes Good (down since 2022-03-31 07:05:39 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31QKZ-8336806823.xlsmxlsm bc2b30e9969aa7dc11544b73955d47d12ec3d2febe998b5cef4b57c89dde7215n/a Heodo
2022-03-31OJR-030405889799851.xlsmxlsm 4e313f9f3abefe7d2a05b2d9ce9dae1683f91278ec0ac7cff68b9f232ff656dcn/a Heodo
2022-03-31GVE-401116767194694.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51Virustotal results 41.94% Heodo
2022-03-31FI-39483564.xlsmxlsm a099f9c9c8eff7049da288a1205f1c0ccd52a4954930cabdd7a00dafbe8bbe6dn/a Heodo
2022-03-31EZR-77848570144790.xlsmxlsm 4bf2a2327ebd2d1421b849168375d718ca7eedfca6a369b4d947836eba831db3n/a Heodo
2022-03-31WV-24491853583192.xlsmxlsm 52939ecf287fe6bf3435960c423bf17f7ea8452f102024e9aca86cf806fdd533n/a Heodo
2022-03-31FBW-80956658944427.xlsmxlsm c91108a630fb89be6e53e693ea5240bc7be18d74be099b965d92647bd239c6bfn/a Heodo
2022-03-31RJS-0840255132708.xlsmxlsm 08e924859a3a3f17c099cca75fbb3cfd7f8cd726fa2e89fb47ff02f9687143baVirustotal results 34.43% Heodo
2022-03-30ER-7697699.xlsmxlsm 2909468da77be7c90d3c57fa66be2e6250afde34bd400f2c815be9bfd89be7ddn/a Heodo
2022-03-30WWT-2041764168763.xlsmxlsm ae3937925f18c7db77b2fd19394cb114cb460741dfa2b7c5bd10de9c5c2e35fdVirustotal results 33.87% Heodo
2022-03-30BBZ-1793772.xlsmxlsm 168a9aa1b5fa37a354fd6ccba71dcd29cbcd503a578504c69feb38bd84a8a691Virustotal results 30.65% Heodo
2022-03-30YY-05708457.xlsxls b154f6087e88d4cdf6449d2bef5b4a4b58a012e8d6e6cd6956f11fc9da110227Virustotal results 26.67% SilentBuilder
2022-03-30OOR-0593063.xlsxls 31ad327541ee0627096151e901dee22241e584b78b52c17eee5a1c40a6f25490n/a SilentBuilder
2022-03-30n/ahtml 0a29126936524bf45aa2a1477b9e39f36c1d243a8c3063ac5532ba460108fb60n/a