URLhaus Database

You are currently viewing the URLhaus database entry for http://germanyvisa.co.uk/wp-content/mnbn9EpArzTsm1hMMIr6/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123070
URL: http://germanyvisa.co.uk/wp-content/mnbn9EpArzTsm1hMMIr6/
URL Status:Offline
Host: germanyvisa.co.uk
Date added:2022-03-30 19:00:06 UTC
Last online:2022-04-02 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 19:01:06 UTC to abuse{at}dacentec[dot]com)
Takedown time:3 days, 2 hours, 46 minutes Bad (down since 2022-04-02 21:47:12 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01XCJ-209605260.xlsmxlsm f5b4ac04b08a06f6b3baa4b35784bcbf477479d425c42cdd443b99aab8fa6d38Virustotal results 44.26% Heodo
2022-04-01XAY-95196852301.xlsmxlsm dd701c6097144f29f8fbdddc93a18a1c0ce3c3b51d5b4f0c6683e906ba8426d9Virustotal results 42.86% Heodo
2022-04-01OM-67613739212993.xlsmxlsm aeeb5ed9e799b620a487617a35049f204d1465f85fb5a5296dba3bd811c2168an/a Heodo
2022-04-01PNH-6834399732067.xlsmxlsm e4458a21923b4abdd20bd02710b29fafe8a0e249a9515cc2e4aff94a30d7d9a4n/a Heodo
2022-04-01ARN-2830955.xlsmxlsm 4207d8837943656e62fed5e7f98e6247c9a5d63d460a7bbdbb4296428051b3e4n/a Heodo
2022-04-01RJN-3275580.xlsmxlsm bba184efb454972191ec837362eddc4ef35f60b616033ef54cbd77d1a70f8f3fVirustotal results 36.51% Heodo
2022-04-01TCT-680583210906.xlsmxlsm 1cef59b0cfd651edd1b587c50988c75a14b39c325a3f41839e3ce51c08f7f753Virustotal results 42.86% Heodo
2022-04-01EB-426592273324.xlsmxlsm b9a82fa6fb67d3ca785a7d8d842c76b3beecd65c9789af664049e029ce4e9a7aVirustotal results 45.16% Heodo
2022-04-01KT-028230821.xlsmxlsm 60833a18e14a8b4eb21cec280bdac63e8a03eeda78c1c5e0e641624b72000be8Virustotal results 41.27% Heodo
2022-04-01ZDI-74711922757959.xlsmxlsm 3ae76b8b56720b9de3d4d679e5e5b70232ade7e9461635465d025c0a9b861ffdn/a Heodo
2022-04-01MXW-42479596.xlsmxlsm 93209f2037b0a22de1bf7430e9714a5b98cf099620080b5b8426d4825ac6fa03n/a Heodo
2022-04-01DU-573219099.xlsmxlsm 8cfdb13bd3fba245b5e3c5a06b90cdab4f8970b13e3ea5262aeb7bd089474bb3Virustotal results 36.67% Heodo
2022-04-01GLP-889575350210.xlsmxlsm 5ea7243ee6fea62276b79e7f2bf602ec3058d33fb8ddbc31faf71eb0eadf1a90n/a Heodo
2022-04-01KW-7610279583072.xlsmxlsm 8c3a1df0298f1bddbc6946c5ab191ef80476cf4a3a8cefe7493c189035d2f0cbn/a Heodo
2022-04-01SH-6764342.xlsmxlsm 0a5cc2b92b228a835529cc7fa4fe679ebabedd3166e10b19c80c5f4d6795f4f1Virustotal results 43.55% Heodo
2022-04-01TW-2134242634.xlsmxlsm f9c9f51df261403227f4db33c8a418d0d9e90e02cba1b750d1b6c0cbd6b1892an/a Heodo
2022-04-01NF-5616614.xlsmxlsm f3c06e72e6b0cddb3d66545d59bef1288458f9c106ede60b0507f095971e7067n/a Heodo
2022-04-01QR-037203837349808.xlsmxlsm 9f342795c6ad73cb790eb75a652804c6a00f21b0806986310ce8ac0208d7ec58n/a Heodo
2022-04-01JG-3319743.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 43.55% Heodo
2022-04-01SM-21112215677.xlsmxlsm dbf83f486a7c984113454c8adbaf67592ca234b8918c265d2f37e174aa0bc1ean/a Heodo
2022-04-01BXG-1722757514171.xlsmxlsm 4c7b060bb7b1693ef3943692ce9c62204426393f9af92ca39c4c57e09b03cc25n/a c8fc17ff030feb3383d8889f69abbb
2022-04-01WNT-1537353.xlsmxlsm dbdb99093276ddabe9897f83028bb608b9fafa75d7e53cc2953aa00fa13fe78cn/a Heodo
2022-04-01JC-641851212853410.xlsmxlsm 038b2b0b380d3768f3d9527e452bde092d4900c621bdc393d324415ebac36b8bn/a Heodo
2022-04-01LE-257115500.xlsmxlsm 183a6d5a3ef111869776ad189768e9388b9c069c9da1ba02ff7fe00068819894n/a Heodo
2022-04-01WHT-63652390124.xlsmxlsm f5c6daab49bfa705475fb8dc2bba6cbeb7510db8798fac83b6423fbd7ae70988n/a Heodo
2022-03-31TD-452667383278406.xlsmxlsm 26505592fe23711a237d0af8fd2c3644b821bf8b9436bd5b92d3132815ba26b4n/a Heodo
2022-03-31FB-967128249547879.xlsmxlsm aa3fff2c2d0daf56b10654b5f1f501b45c0cfd50fef9004498bca2a83c359e69Virustotal results 36.51% Heodo
2022-03-31HLE-7840473839.xlsmxlsm ab43f95f76dbd0bafc11d3af407297993a715790014ec2d550185c7eb75293abVirustotal results 37.70% Heodo
2022-03-31HE-08428711669070.xlsmxlsm 48e097ffa3b8052caca9ce79bab384f701c23adfe0a5132dbb026d341b33a1aen/a Heodo
2022-03-31TX-04637456.xlsmxlsm 522056ad088097c5c827ddabc4a8e7ad95b16563043dcfde8aa2fc4b0df81a1fVirustotal results 41.94% Heodo
2022-03-31DV-173883564921.xlsmxlsm 2fa93c2dfef003816d473094a03ffe57ed6fd6cbbd21f22831af88634fc3287dn/a Heodo
2022-03-31IA-636475373022.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31FZ-182506947.xlsmxlsm 55df1b7705bbb280a99fd4ca6d5a9bc090ebda3009a6bb113bb48daff7dda5c2n/a Heodo
2022-03-31QER-66583488278340.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31TXG-75871222.xlsmxlsm fea58fae76c86e5f07c7f8b032f84174206bc489d92c49fe54a5b51d2658faf8Virustotal results 34.92% Heodo
2022-03-31UK-527132052317.xlsmxlsm a7ae8fb40c5d93e9ddbfc68b000b65ba19b085e7a19d3a5d9bef1c243a6add91Virustotal results 43.55% Heodo
2022-03-31OQF-038285317.xlsmxlsm 63ba5c63fa8f569c1870ab57faeeec2933a7bdb28c90458f6c5373f1a71dcef4Virustotal results 36.51% Heodo
2022-03-31RF-52909966.xlsmxlsm 83071445fecb136d595c8b4c6edbe66c5127e003402a4a41ccaab915687ec19cVirustotal results 38.33% Heodo
2022-03-31RS-894242916824054.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564Virustotal results 38.10% Heodo
2022-03-31TL-229508194272281.xlsmxlsm d4f941f7232c98be2d39a4a97edcad5b4648430bb60ad5a21747b37e705ff2d2n/a Heodo
2022-03-31VB-26667903562.xlsmxlsm f869263419a75a1350a78400b9e3dd186488c7c76d299e7984af7e5e0c91d75dn/a Heodo
2022-03-31LZM-95798396.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31VVW-9586286872750.xlsmxlsm db67f0509c5f982c9eb1fab5a17d14ea07d5a1e13b2f5ee3b35ccf93700588e4n/a Heodo
2022-03-30AIW-5093482323.xlsmxlsm 41f790fa1e0f18e897bdad1de2c9452310c964ab0c50e831d9c1150af849edf4Virustotal results 40.98% Heodo
2022-03-30GQM-0440562.xlsmxlsm 39bbb570609ea300f9d959dcf23f2161043c6dedc230f97e7eab2388db651831Virustotal results 37.10% Heodo
2022-03-30BO-5209877172036.xlsmxlsm 7b790cb9f037644da2aa7daf038bef787f020bc8aad1932fb1e8c4c5ab3b4766n/a Heodo
2022-03-30HZ-33066419429818.xlsxls 34c12fb797211966f38e1025e683ec8ecc00b70e39d5f463213f7b09eea896c4Virustotal results 28.33%SilentBuilder
2022-03-30n/ahtml 4eb6c9cdb850a214f27e9b7ce9fd5543a0ee8d2c9bd608e155d410e4c91eb99cn/a