URLhaus Database

You are currently viewing the URLhaus database entry for http://visionnextgroup.net/saharaUK/2UXmSjlPLoroRMOjJ2AfDM/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123202
URL: http://visionnextgroup.net/saharaUK/2UXmSjlPLoroRMOjJ2AfDM/?i=1
URL Status:Offline
Host: visionnextgroup.net
Date added:2022-03-30 20:17:05 UTC
Last online:2022-09-27 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 20:18:05 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:6 months, 1 days, 1 hours, 14 minutes Bad (down since 2022-09-27 21:32:05 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-02LC-195601619124.xlsmxlsm d0e1bf9a8969b0e7856ed1015033cef4c745a120413c76d61b1560e323de2359Virustotal results 48.39% Heodo
2022-03-31EKD-142606908.xlsmxlsm c3a5d5bc890f935056c127bdeda35cfcfbb8e292e59774a24ca5611e94430907Virustotal results 37.70% Heodo
2022-03-31MZ-69514860964.xlsmxlsm d4f941f7232c98be2d39a4a97edcad5b4648430bb60ad5a21747b37e705ff2d2n/a Heodo
2022-03-31JQX-701010413.xlsmxlsm f869263419a75a1350a78400b9e3dd186488c7c76d299e7984af7e5e0c91d75dn/a Heodo
2022-03-31GNF-866237674854.xlsmxlsm a4e22b806505d549a037a67123efb6b397193d7d2ff28e32d8b73185438fb5acn/a Heodo
2022-03-31OAV-26132396986.xlsmxlsm db67f0509c5f982c9eb1fab5a17d14ea07d5a1e13b2f5ee3b35ccf93700588e4n/a Heodo
2022-03-30VF-713022603.xlsmxlsm 7bd47c2f3e932a049d450f5a54be51e401ea041d669c7df91f71b903358f99d9n/a Heodo
2022-03-30AQO-5263973347.xlsmxlsm cd87c584d61ecb87fbf42b6e2214664f3d1feb22fee767b261b3c269b8210d92n/a Heodo
2022-03-30NH-61155926.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51n/a Heodo
2022-03-30FD-627793545100.xlsxls 403c28ce1df56f185d0824575299bea20d7d1738e6a9688c551d039b6d1aaea2n/a Heodo
2022-03-308944189144940744428.xlsxls 3493b3210a3ce325a05cc7da5ffc69d323e0a0a645d8bdfaf1016a2de52ee1b5Virustotal results 26.67% SilentBuilder