URLhaus Database

You are currently viewing the URLhaus database entry for https://galaxy-catering.com.vn/galxy/cX9eVP/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123166
URL: https://galaxy-catering.com.vn/galxy/cX9eVP/?i=1
URL Status:Offline
Host: galaxy-catering.com.vn
Date added:2022-03-30 19:47:07 UTC
Last online:2022-08-09 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 19:48:05 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:4 months, 12 days, 0 hours, 33 minutes Bad (down since 2022-08-09 20:22:02 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01GZF-68060283063.xlsmxlsm 1cb0214ebc21c13015d927c504acfbe080983909d8839ef9b28c5e270d1f4f1cVirustotal results 46.77% Heodo
2022-04-01YBS-5912816222.xlsmxlsm 97fc1c969103278fd6fddd2f117d3b418d3f7925a9971bafa8bafd8b2d3df632Virustotal results 36.51% Heodo
2022-04-01TGU-74158417311199.xlsmxlsm ed0f2b25cb3cf7567e560afcce0dbe163122a48f317ee5c28d2f6ee259898758n/a Heodo
2022-04-01OOX-558925903.xlsmxlsm 7e96bc74f1eb792d13f6c2f4d32b219833ea235a0ef4802178b44ebd18ef7ce3Virustotal results 47.54% Heodo
2022-04-01YWG-9946454572263.xlsmxlsm d058072d305f952c54981e50bbd34cf23dd0386a4924a4bdb8a91f46e0498d4fn/a Heodo
2022-04-01GA-5461516728.xlsmxlsm 64d236fdcb188d517ddb0fd6ffcaf1759dddd828de26d1cf6b605031589da663n/a Heodo
2022-04-01JD-559557847622611.xlsmxlsm 534f4ab246459c91599d4d14e916a2f16707134075a5a88d897105a0e782632bn/a Heodo
2022-04-01BBH-9160087995.xlsmxlsm 178e56af34b8983297784e7e795578c7567350c8ef3be2b30a43a05de59b9e8bn/a Heodo
2022-04-01SRQ-3694452699178.xlsmxlsm 60833a18e14a8b4eb21cec280bdac63e8a03eeda78c1c5e0e641624b72000be8n/a Heodo
2022-04-01ZEL-442883150445.xlsmxlsm 5270afd30069d36cee5d2bb013f3d1d7765e90cce7cb4d7244c92a62596f108dn/a Heodo
2022-04-01INI-48891079.xlsmxlsm b25b9d420c3585bd014abd2e590a74feab98bbb0ee612c465a5e152b28c67e0bn/a Heodo
2022-04-01KV-7789297.xlsmxlsm 3390185d81ea6becb7bb5c59f26400a3c75b99da77bd95eb76e9417ca984b4dfn/a Heodo
2022-04-01RV-201038198.xlsmxlsm 63e1baa16341383969467beb7fd04519776f8283306f3982a330fc81b9931902n/a Heodo
2022-04-01HR-018400023711.xlsmxlsm 4fe9cdc6b35e9992d206f5a0bb6ebcb063618ed502e651ba2f5c014a2aea5776n/a Heodo
2022-04-01OD-9868641149.xlsmxlsm 525f6667c0439d7c21905eb0aec33c64c4b4ee34d0f3896f67f5140927b44d90Virustotal results 42.62% Heodo
2022-04-01BU-8429919835.xlsmxlsm 5118b85e7ffcf61644564e2660990ff4e6becc430b13aca19a931d25f3d4c1d9Virustotal results 38.10% Heodo
2022-04-01SDM-35363757609.xlsmxlsm f3c06e72e6b0cddb3d66545d59bef1288458f9c106ede60b0507f095971e7067n/a Heodo
2022-04-01XA-4043226682614.xlsmxlsm bae96f9a32122e9edb5b64e650dad2249b1dae898540a74641fdd9a4fe860edfn/a Heodo
2022-04-01QGM-525193000.xlsmxlsm c0e952a6f3524c6ad386d70392deb83c2e0677409d38454d38759abb44e2058cVirustotal results 41.94% Heodo
2022-04-01HJN-285135919718.xlsmxlsm 45a99040aab95ccb6eae75a169ae10f79883e11c53c29bc41ffffd0a329940cen/a Heodo
2022-04-01DVY-8914635.xlsmxlsm 441ae7dcf7d20f39dce4201542202d7c62c067457d1476c2bda9c819979879ebVirustotal results 45.90% Heodo
2022-04-01VKZ-8849712499479.xlsmxlsm 68696caf69e14a066ca54423f72a2e7693b03f5ce299e609265a3e72df925abcVirustotal results 39.68% Heodo
2022-04-01AZ-3936758.xlsmxlsm dcc6409e704780116523a3e6ca35edf1399b381568d26b6d0373d1d9e00be491n/a Heodo
2022-04-01LVN-843388799254.xlsmxlsm d470a9368b15c6f1e3e1c49a452ab86e75500fc1585044f4c9dcdadaadd804d7n/a c8fc17ff030feb3383d8889f69abbb
2022-04-01XT-297973501436078.xlsmxlsm 77bd6aa47a2c099f99f463a04c9f5bead9d13eae0ccdf1821a6cb755d8c70382n/a Heodo
2022-03-31QE-17006861268277.xlsmxlsm a3daf38a9efabc78999651c2b0f4afd47af19450cb0b3f4492221c20b7590c71n/a Heodo
2022-03-31JP-52687164557.xlsmxlsm 1bdada6954ab20722dfb51b2ace2e6fcdfb556210c74bb059752552f5fa8f78fVirustotal results 42.86% Heodo
2022-03-31SD-32930103114710.xlsmxlsm dffde7ff06d4b4d38ae8f02750d5c59b2a1a293d05af04210b8e79d0b3fd4043Virustotal results 38.10% Heodo
2022-03-31ZM-81769904999071.xlsmxlsm ab43f95f76dbd0bafc11d3af407297993a715790014ec2d550185c7eb75293abVirustotal results 37.70% Heodo
2022-03-31EAY-37522503538256.xlsmxlsm c201ae0ab0516a27d14400b4af28d4189bb2c6d8b589c4fadb025c26645f19bfVirustotal results 38.10% Heodo
2022-03-31JOG-698714550946.xlsmxlsm 2fa93c2dfef003816d473094a03ffe57ed6fd6cbbd21f22831af88634fc3287dVirustotal results 37.10% Heodo
2022-03-31VBQ-965153610579.xlsmxlsm 9c234ce84ff77dfc1466c436eea9d46c50c3055c50f0029b81dba5052864f4ban/a Heodo
2022-03-31BX-942982649004259.xlsmxlsm 838aaff9e0b3ff967eb4e3ed2461109e68a0d8273f496f447224e1ae3c55d8ban/a Heodo
2022-03-31QYX-078857134519.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31GV-242971566.xlsmxlsm b034cfc88c6603dc0f5519ecba2dbba8c5382b26b8c25da23f8d40368ce8e7b5Virustotal results 33.87% Heodo
2022-03-31TF-298467224588914.xlsmxlsm 63ba5c63fa8f569c1870ab57faeeec2933a7bdb28c90458f6c5373f1a71dcef4Virustotal results 36.51% Heodo
2022-03-31JKB-39981683907236.xlsmxlsm 2e1db4578a7534abbaeb0e65b01b0da5024a9e27d99c3a9b29b03cca35b3a096n/a Heodo
2022-03-31DQ-622870617267303.xlsmxlsm c3a5d5bc890f935056c127bdeda35cfcfbb8e292e59774a24ca5611e94430907Virustotal results 37.70% Heodo
2022-03-31RIM-95889452847.xlsmxlsm 65b87a95369159fb3d54556f3f316f9e13eadd8b95e9e13f6a8d9cc79f43a8e6Virustotal results 40.68% Heodo
2022-03-31UHQ-0406009260.xlsmxlsm f869263419a75a1350a78400b9e3dd186488c7c76d299e7984af7e5e0c91d75dn/a Heodo
2022-03-31ZX-464015760.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31JCF-1369558.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-30ZL-19110111.xlsmxlsm b4f7a7bd6f99c0ea09617160e6bf753419f6d731901828662049ac8abfed4959n/a Heodo
2022-03-30ARP-123315759.xlsmxlsm 08e64e582d9d42f5f3a21eaff52bcb72b4a3abfc761561ff28f40bf937dedb2cVirustotal results 35.48% Heodo
2022-03-30JH-4135631731037.xlsmxlsm 2e8dfaff0039f7b69af5f699d0efff85cca1b5dbe2a50082b7ccc49503545053n/a Heodo
2022-03-30TYG-6658433.xlsxls a14fb7f51582ec1f9af65f4300ff4dde6a99d12bd2b08f70863ca16d508c72baVirustotal results 28.33% Heodo
2022-03-309318243200.xlsxls 3493b3210a3ce325a05cc7da5ffc69d323e0a0a645d8bdfaf1016a2de52ee1b5Virustotal results 26.67% SilentBuilder
2022-03-3027983395197.xlsxls afab90f284e5f643a8fa8a6eafd154175a22394254db310f0dcddc607a5ed468n/a Heodo