URLhaus Database

You are currently viewing the URLhaus database entry for https://galaxy-catering.com.vn/galxy/cX9eVP/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123168
URL: https://galaxy-catering.com.vn/galxy/cX9eVP/
URL Status:Offline
Host: galaxy-catering.com.vn
Date added:2022-03-30 19:47:12 UTC
Last online:2022-08-10 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 19:48:05 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:4 months, 12 days, 11 hours, 2 minutes Bad (down since 2022-08-10 06:50:35 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01GZF-68060283063.xlsmxlsm 1cb0214ebc21c13015d927c504acfbe080983909d8839ef9b28c5e270d1f4f1cVirustotal results 46.77% Heodo
2022-04-01YBS-5912816222.xlsmxlsm 97fc1c969103278fd6fddd2f117d3b418d3f7925a9971bafa8bafd8b2d3df632Virustotal results 36.51% Heodo
2022-04-01BPJ-295155947804054.xlsmxlsm 2cd047043da3c815bb5554f75749f89f6b7f44bf302c395f9685e485e7cf3d77n/a Heodo
2022-04-01OP-0709415330272.xlsmxlsm 178e56af34b8983297784e7e795578c7567350c8ef3be2b30a43a05de59b9e8bVirustotal results 47.62% Heodo
2022-04-01VKB-7432996632.xlsmxlsm d058072d305f952c54981e50bbd34cf23dd0386a4924a4bdb8a91f46e0498d4fVirustotal results 45.16% Heodo
2022-04-01RXI-5431334044372.xlsmxlsm b67f378396a813307cf0d9d7c4f272be83010272fcfa9af1791b517cf4f1ba05Virustotal results 42.62% Heodo
2022-04-01FU-830727528800697.xlsmxlsm d5e9766c94d91e4da90999a0ea0d9a7b3918973c857c7f9faca5686288b53db2n/a Heodo
2022-04-01JD-559557847622611.xlsmxlsm 534f4ab246459c91599d4d14e916a2f16707134075a5a88d897105a0e782632bn/a Heodo
2022-04-01JH-027654762879751.xlsmxlsm f29f0ba02cb498dad7d65453ecc558f159db3694f8f5cdba8d96fe63fb61d986Virustotal results 41.94% Heodo
2022-04-01XTB-26649724151.xlsmxlsm 606cbdc0ecdc8c68efea96696850b401a2f42925109a960adc15b100ad3c8175n/a Heodo
2022-04-01INI-48891079.xlsmxlsm b25b9d420c3585bd014abd2e590a74feab98bbb0ee612c465a5e152b28c67e0bn/a Heodo
2022-04-01ZFP-818183313619889.xlsmxlsm 8cfdb13bd3fba245b5e3c5a06b90cdab4f8970b13e3ea5262aeb7bd089474bb3Virustotal results 36.67% Heodo
2022-04-01FH-5711394029470.xlsmxlsm 1a8adefa7d083432f592ddc3797611b4e8076869a11177ebbdc1b5b6bc22982fn/a Heodo
2022-04-01KCG-0740377645.xlsmxlsm 7fb7f42e37addbbb2765549460c94f9747dba7a15365f6621d0e9fb2d80ae701Virustotal results 40.32% Heodo
2022-04-01OD-9868641149.xlsmxlsm 525f6667c0439d7c21905eb0aec33c64c4b4ee34d0f3896f67f5140927b44d90Virustotal results 42.62% Heodo
2022-04-01BU-8429919835.xlsmxlsm 5118b85e7ffcf61644564e2660990ff4e6becc430b13aca19a931d25f3d4c1d9Virustotal results 38.10% Heodo
2022-04-01SDM-35363757609.xlsmxlsm f3c06e72e6b0cddb3d66545d59bef1288458f9c106ede60b0507f095971e7067n/a Heodo
2022-04-01VY-686523257002.xlsmxlsm c201ae0ab0516a27d14400b4af28d4189bb2c6d8b589c4fadb025c26645f19bfVirustotal results 48.39% Heodo
2022-04-01LP-2312521583.xlsmxlsm 41169580013c884c968404a805765bab464032270676b792b39ae2b521a64dfeVirustotal results 40.32% Heodo
2022-04-01HJN-285135919718.xlsmxlsm 45a99040aab95ccb6eae75a169ae10f79883e11c53c29bc41ffffd0a329940cen/a Heodo
2022-04-01AVE-824179747.xlsmxlsm 4c7b060bb7b1693ef3943692ce9c62204426393f9af92ca39c4c57e09b03cc25n/a c8fc17ff030feb3383d8889f69abbb
2022-04-01ZJ-8436639.xlsmxlsm a4653047d35b63e4cfb6020be4149b484aa5e68354d53a9da860dcc3cdeef038n/a c8fc17ff030feb3383d8889f69abbb
2022-04-01QG-548444819.xlsmxlsm dbdb99093276ddabe9897f83028bb608b9fafa75d7e53cc2953aa00fa13fe78cn/a Heodo
2022-04-01AZ-3936758.xlsmxlsm dcc6409e704780116523a3e6ca35edf1399b381568d26b6d0373d1d9e00be491n/a Heodo
2022-04-01GZ-799914359.xlsmxlsm 55af29e8285944f573d931d856bd099dac92ab1868000f8346d13a0bce7f1e3dn/a Heodo
2022-04-01HC-6100220.xlsmxlsm d17e95fb87ae8a3011b050d5c9c089f3bc06fddd1a61feb4812380e96b541e73Virustotal results 46.77% Heodo
2022-03-31ZY-488854670513322.xlsmxlsm bbf1ee7ac4c4ec95b8f5be027d6d0063d9067480f0bd4f7efcdbeeaa827dceefn/a Heodo
2022-03-31EKM-8252725761236.xlsmxlsm b240ff1edec81e1d31562cbd34499c1f2085346a7de34e51016cb82e3cb85716n/a Heodo
2022-03-31MYV-463692248.xlsmxlsm 64d92f79a2d87571d428b7b19ef4f5c1680c24c8952a2f46b84f217cfba19766Virustotal results 39.68% Heodo
2022-03-31ZRB-11471510999890.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 35.48% Heodo
2022-03-31FX-168803274888.xlsmxlsm 99bacd00ff714e00339dc64c1418b2c0c26ca69120e34bd32ba8e73d2044cd9cn/a Heodo
2022-03-31KPQ-036553219805436.xlsmxlsm 5255a810d7f6ce0a8c496654d7751b05993139ba23432677b64b01c9c44af0fdn/a Heodo
2022-03-31VBQ-965153610579.xlsmxlsm 9c234ce84ff77dfc1466c436eea9d46c50c3055c50f0029b81dba5052864f4ban/a Heodo
2022-03-31BX-942982649004259.xlsmxlsm 838aaff9e0b3ff967eb4e3ed2461109e68a0d8273f496f447224e1ae3c55d8ban/a Heodo
2022-03-31HW-36409080.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31WGB-99779314386977.xlsmxlsm fea58fae76c86e5f07c7f8b032f84174206bc489d92c49fe54a5b51d2658faf8Virustotal results 34.92% Heodo
2022-03-31GV-242971566.xlsmxlsm b034cfc88c6603dc0f5519ecba2dbba8c5382b26b8c25da23f8d40368ce8e7b5Virustotal results 33.87% Heodo
2022-03-31GEK-1909007163836.xlsmxlsm ccf8147ef96ae47288019a25336c2935e73d2e06b8fe73823e3596fb1596ba8dVirustotal results 43.55% Heodo
2022-03-31EI-9061336.xlsmxlsm b5df411a9037fcd4dc6b3e92145aae14064c20edf7476a543c778bdb8af22600Virustotal results 36.51% Heodo
2022-03-31DFY-70908421636907.xlsmxlsm 575cdc6658b85600efd2d3c07f461b8adaeb0b181dfacfd318c0806e4915c95bn/a Heodo
2022-03-31QJK-475342173.xlsmxlsm 41a73a914406df97e2944f7742f48272bab7d25486c9c2a5084a7f158fdb2aafn/a Heodo
2022-03-31OKO-235478749133510.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564n/a Heodo
2022-03-31ZX-464015760.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31ARF-10078511.xlsmxlsm 638588dd97949a25ee7322aa73731204406054bf2db2043063ebfdc82d353f65n/a Heodo
2022-03-30ZL-19110111.xlsmxlsm b4f7a7bd6f99c0ea09617160e6bf753419f6d731901828662049ac8abfed4959Virustotal results 36.51% Heodo
2022-03-30JOV-82703774770.xlsmxlsm 39bbb570609ea300f9d959dcf23f2161043c6dedc230f97e7eab2388db651831Virustotal results 37.10% Heodo
2022-03-30FNI-8956052.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30PE-1524563.xlsxls 46218e7a1f860f4758adfd19dc3b12e27771a613ca00f687ccbe48a0c275f83en/aHeodo
2022-03-30XV-912792672352159.xlsxls fcd24781c23e7b39616725080ede580a017e3f9bfaafe8bbda972a4f40297bb8n/a SilentBuilder
2022-03-30n/ahtml 66f382cc5e80ae17c56e58c815a270c904be6226b07e4bb80b76462b6037aca0n/a