URLhaus Database

You are currently viewing the URLhaus database entry for http://germanyvisa.co.uk/wp-content/mnbn9EpArzTsm1hMMIr6/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123071
URL: http://germanyvisa.co.uk/wp-content/mnbn9EpArzTsm1hMMIr6/?i=1
URL Status:Offline
Host: germanyvisa.co.uk
Date added:2022-03-30 19:01:05 UTC
Last online:2022-04-02 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 19:02:07 UTC to abuse{at}dacentec[dot]com)
Takedown time:3 days, 2 hours, 43 minutes Bad (down since 2022-04-02 21:45:50 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01XCJ-209605260.xlsmxlsm f5b4ac04b08a06f6b3baa4b35784bcbf477479d425c42cdd443b99aab8fa6d38n/a Heodo
2022-04-01LJE-4925916.xlsmxlsm 0f6cfe4c94b7444729077741d333e0388edf05a02cd4dc40e515a03f5d4bf01bVirustotal results 40.32% Heodo
2022-04-01AN-6536772867994.xlsmxlsm 178e56af34b8983297784e7e795578c7567350c8ef3be2b30a43a05de59b9e8bVirustotal results 47.62% Heodo
2022-04-01GAV-93995814392.xlsmxlsm 0267b8c0e2d5e3b8d03da907a69503fd2553048e9f29aa91171ffa4ab40f2b44n/a Heodo
2022-04-01RJN-3275580.xlsmxlsm bba184efb454972191ec837362eddc4ef35f60b616033ef54cbd77d1a70f8f3fVirustotal results 36.51% Heodo
2022-04-01TCT-680583210906.xlsmxlsm 1cef59b0cfd651edd1b587c50988c75a14b39c325a3f41839e3ce51c08f7f753Virustotal results 42.86% Heodo
2022-04-01YQ-0694496.xlsmxlsm 004f6c9fad398f8dda13f421a6faa1a78916ba04c3eabe988acd669f8cb1b112Virustotal results 39.68% Heodo
2022-04-01JOA-54536590995804.xlsmxlsm f8f5316e59f479286d96010874074660c5afe3ddbbf1bb382c468904b9667595n/a Heodo
2022-04-01MXW-42479596.xlsmxlsm 93209f2037b0a22de1bf7430e9714a5b98cf099620080b5b8426d4825ac6fa03n/a Heodo
2022-04-01TNS-9717657085.xlsmxlsm 3390185d81ea6becb7bb5c59f26400a3c75b99da77bd95eb76e9417ca984b4dfn/a Heodo
2022-04-01KG-464190812646196.xlsmxlsm e487c02def7287335acf2278332f27a4a585960d8ba68a14c0b8370535440c3cVirustotal results 43.55% Heodo
2022-04-01LEM-022328575443645.xlsmxlsm fdaef695835e1a9e056fe2496ef611e4250388f7712102116b6717894e578f50n/a Heodo
2022-04-01CE-5291877.xlsmxlsm f53321cb8389d05b2d4c2f1a82efdf89e8d00a44ed13e02f649c90fb3169a7a5n/a Heodo
2022-04-01NJ-40687501.xlsmxlsm 5118b85e7ffcf61644564e2660990ff4e6becc430b13aca19a931d25f3d4c1d9Virustotal results 38.10% Heodo
2022-04-01NF-5616614.xlsmxlsm f3c06e72e6b0cddb3d66545d59bef1288458f9c106ede60b0507f095971e7067n/a Heodo
2022-04-01VV-53625687471108.xlsmxlsm 5e318e7afaeff1da0ab8f38c466b9fb4e911da7fae7a6eb58cfbab3175d51263n/a Heodo
2022-04-01JG-3319743.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 43.55% Heodo
2022-04-01CU-1571441767687.xlsmxlsm 5144b4176d2f9e56ad483565884642378be09039de1f2a353cb355c00dfa1894Virustotal results 43.55%Heodo
2022-04-01DUC-05407812.xlsmxlsm b9a82fa6fb67d3ca785a7d8d842c76b3beecd65c9789af664049e029ce4e9a7an/a Heodo
2022-04-01WNT-1537353.xlsmxlsm dbdb99093276ddabe9897f83028bb608b9fafa75d7e53cc2953aa00fa13fe78cn/a Heodo
2022-04-01WI-434160390.xlsmxlsm 3005686dd6b770a4a0af0ba70ec91ea407d32838aa2acea56c5ab75f2a47ff56n/a Heodo
2022-04-01LE-257115500.xlsmxlsm 183a6d5a3ef111869776ad189768e9388b9c069c9da1ba02ff7fe00068819894n/a Heodo
2022-03-31TD-452667383278406.xlsmxlsm 26505592fe23711a237d0af8fd2c3644b821bf8b9436bd5b92d3132815ba26b4n/a Heodo
2022-03-31JJ-15264664501381.xlsmxlsm 5fb54e96fe17c395fa69dc06933558b083ae9cfb1391218f12c539c2645a8311n/a Heodo
2022-03-31OEK-0833436989.xlsmxlsm 8090d0b6d046091604553a331f669273c32d27943faae06a33b6ffda57479dafn/aHeodo
2022-03-31XSF-7280179197.xlsmxlsm d0f2b1c8a9b921705df6afe3ace9e58899772b9360014ec12562c488c0eb6608Virustotal results 38.10% Heodo
2022-03-31TKP-1450103983.xlsmxlsm a395d2ca627270c1b53481050d39c6395c778682e98aeedcb00d1f68fd1ec23fn/a Heodo
2022-03-31TX-04637456.xlsmxlsm 522056ad088097c5c827ddabc4a8e7ad95b16563043dcfde8aa2fc4b0df81a1fVirustotal results 41.94% Heodo
2022-03-31DV-173883564921.xlsmxlsm 2fa93c2dfef003816d473094a03ffe57ed6fd6cbbd21f22831af88634fc3287dVirustotal results 36.07% Heodo
2022-03-31QQP-30312780898192.xlsmxlsm 8115bc600c3294ed207ae6a9310eb986b107f74f69a64db674837ba2e2957ac6n/a Heodo
2022-03-31IA-636475373022.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31UH-078984626302.xlsmxlsm c477d7314db2e481dc0afaafdc010642699dff0e0b641a374e91754a51fbf094n/a Heodo
2022-03-31LZS-30033668.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31ELG-6572617071.xlsmxlsm 53ef2d3a553342c46f5d3011cb07634e1f02b36dae99808e47dd459dd384e388n/a Heodo
2022-03-31SKP-3648367875.xlsmxlsm b034cfc88c6603dc0f5519ecba2dbba8c5382b26b8c25da23f8d40368ce8e7b5Virustotal results 33.87% Heodo
2022-03-31TS-4536324.xlsmxlsm 2e1db4578a7534abbaeb0e65b01b0da5024a9e27d99c3a9b29b03cca35b3a096n/a Heodo
2022-03-31TER-30025182589.xlsmxlsm b5df411a9037fcd4dc6b3e92145aae14064c20edf7476a543c778bdb8af22600Virustotal results 36.51% Heodo
2022-03-31RS-894242916824054.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564Virustotal results 38.10% Heodo
2022-03-31LV-3404394991.xlsmxlsm 287f8b49b0107a7e303a4d327d34a8fe117d4696af06bb3bbd73d25e5a39270fVirustotal results 40.98% Heodo
2022-03-31TTQ-7352931.xlsmxlsm 4f1ab8d0a0a6f8a7964b32b8a4bdd94bad95e6774501cf7685028a40efc761e2n/a Heodo
2022-03-31SOE-698473734897.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231n/a Heodo
2022-03-31QA-719753064.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-30AIW-5093482323.xlsmxlsm 41f790fa1e0f18e897bdad1de2c9452310c964ab0c50e831d9c1150af849edf4Virustotal results 40.98% Heodo
2022-03-30JIZ-3027461283.xlsmxlsm 08e64e582d9d42f5f3a21eaff52bcb72b4a3abfc761561ff28f40bf937dedb2cVirustotal results 35.48% Heodo
2022-03-30STP-90121534593516.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30JZJ-6502762.xlsxls 1d74cb46d2219761b01e8425e6ec57120fdb867a48735edee3b9bfafd3706caeVirustotal results 25.00% Heodo
2022-03-3035718807841218352334.xlsxls 3493b3210a3ce325a05cc7da5ffc69d323e0a0a645d8bdfaf1016a2de52ee1b5Virustotal results 26.67% SilentBuilder
2022-03-301724113553554.xlsxls 7c9ef24f3522ff243e77f5d6e0cb50f6766916fcc1ad2fe845f9d509e39a6b3fn/a Heodo
2022-03-303726094552.xlsxls 33b4122a72a4831544324253f4b3c1b30528dec85657369e26b214838e6cbd1an/aHeodo