URLhaus Database

You are currently viewing the URLhaus database entry for http://haircutbar.com/documents/xuPEi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123242
URL: http://haircutbar.com/documents/xuPEi/
URL Status:Offline
Host: haircutbar.com
Date added:2022-03-30 20:59:07 UTC
Last online:2022-06-19 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 21:00:07 UTC to admin{at}frantech[dot]ca,fdias{at}frantech[dot]ca)
Takedown time:2 months, 20 days, 15 hours, 18 minutes Bad (down since 2022-06-19 12:18:34 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01LA-56256066152574.xlsmxlsm 3878263530546f6ae84240c434d7964d52f6da426513e5c6264faa8cc064154fn/a Heodo
2022-04-01XJ-8006280675.xlsmxlsm 83e4fb679d6d1c0567ea98f4800afcb2f1b36a3d0515fa429f17ba52984f6cbdVirustotal results 37.10% Heodo
2022-04-01XZ-41555420344.xlsmxlsm ea8981ffdb13c6d1dd874a5a86e7079bb053c862a92849bc571846a6762dc7d4Virustotal results 45.16% Heodo
2022-04-01YNF-72983566.xlsmxlsm 172069d53028518eba0b857e88be2520acea926685cda54cc456c55d3f94d5f3Virustotal results 42.62% Heodo
2022-04-01UOR-725990705142.xlsmxlsm 178e56af34b8983297784e7e795578c7567350c8ef3be2b30a43a05de59b9e8bVirustotal results 47.62% Heodo
2022-04-01VXH-342422810.xlsmxlsm 4207d8837943656e62fed5e7f98e6247c9a5d63d460a7bbdbb4296428051b3e4n/a Heodo
2022-04-01TIU-301995522555692.xlsmxlsm c144fc2d49c45947f208bce91aa0c8a494807f02db23656e528acbe9e274397an/a Heodo
2022-04-01RPS-630819592.xlsmxlsm dec78675ed65ce3c282f1d9d3e4a1da9209c833b7aca7b14647e1a944b002400Virustotal results 40.32% Heodo
2022-04-01DQ-95370191.xlsmxlsm f29f0ba02cb498dad7d65453ecc558f159db3694f8f5cdba8d96fe63fb61d986Virustotal results 41.94% Heodo
2022-04-01WCO-5622518838.xlsmxlsm f316a9b48040c007a792f5b99f7367b7d6996c7db03a377dd159a22db01e6546n/a Heodo
2022-04-01PW-9309105.xlsmxlsm 151bebbe36787d4fa1411ea5ea657240e196378969813eb1c1e09d0e4e647ee8n/a Heodo
2022-04-01PB-233138541397.xlsmxlsm b25b9d420c3585bd014abd2e590a74feab98bbb0ee612c465a5e152b28c67e0bn/a Heodo
2022-04-01YS-1219535876698.xlsmxlsm 3390185d81ea6becb7bb5c59f26400a3c75b99da77bd95eb76e9417ca984b4dfn/a Heodo
2022-04-01HB-89301868131752.xlsmxlsm 5ea7243ee6fea62276b79e7f2bf602ec3058d33fb8ddbc31faf71eb0eadf1a90n/a Heodo
2022-04-01DTR-64802651937372.xlsmxlsm a5935a412c23ba191d5b45d6c5d4bc9ef13f7e88766c37571502a79ee381ef5dVirustotal results 38.98% Heodo
2022-04-01JSY-8301499081659.xlsmxlsm 525f6667c0439d7c21905eb0aec33c64c4b4ee34d0f3896f67f5140927b44d90Virustotal results 42.62% Heodo
2022-04-01WH-8312912805.xlsmxlsm 5118b85e7ffcf61644564e2660990ff4e6becc430b13aca19a931d25f3d4c1d9Virustotal results 38.10% Heodo
2022-04-01DE-809619441.xlsmxlsm e407f7217907368560ef28caf164f34190a5295c4c75afaaeea21386e8bed99cn/a Heodo
2022-04-01MLP-2054990135564.xlsmxlsm 5e318e7afaeff1da0ab8f38c466b9fb4e911da7fae7a6eb58cfbab3175d51263n/a Heodo
2022-04-01PP-937824281319.xlsmxlsm 41169580013c884c968404a805765bab464032270676b792b39ae2b521a64dfeVirustotal results 40.32% Heodo
2022-04-01GOK-6655849.xlsmxlsm 45a99040aab95ccb6eae75a169ae10f79883e11c53c29bc41ffffd0a329940cen/a Heodo
2022-04-01RGP-00454011888.xlsmxlsm da7fdf635815dc2ebb6fe69fa637d655ab6667aa7195ba89002790a17c19dc19Virustotal results 41.27% Heodo
2022-04-01XEF-478666995.xlsmxlsm 73dc0a16c8430b50b28054c9e0b1e54cc8174554e7b63b4e2fa4be17c3cac1d6n/a Heodo
2022-04-01ALS-538282536.xlsmxlsm 038b2b0b380d3768f3d9527e452bde092d4900c621bdc393d324415ebac36b8bn/a Heodo
2022-04-01BYW-4206997.xlsmxlsm 299bb2145f0b8204975127a266633cb549cef59d4f53ac9a21aa2d9ef1adf13en/a Heodo
2022-04-01EG-027441248588.xlsmxlsm 77bd6aa47a2c099f99f463a04c9f5bead9d13eae0ccdf1821a6cb755d8c70382n/a Heodo
2022-03-31AH-6249601.xlsmxlsm 8ce2a97a8318d629daf6b48ca033dceb8988c32bf5023f8938f354bdfeb5e25bn/a Heodo
2022-03-31NM-4538459.xlsmxlsm c7f63ce6becdd48402150d223d11b5fb003ec48c57f2d856c8d979e5b3da4254n/a Heodo
2022-03-31KO-2229348428242.xlsmxlsm ccd9dcb6dc115061ff6e011cb77ac0c73d785a23c2019aabe11eba9b7500b118Virustotal results 38.10% Heodo
2022-03-31WK-22286563805004.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 35.48% Heodo
2022-03-31UWG-676453396570273.xlsmxlsm c10cd4c9b699a22be539e47e16dbb91c80084b3afa570a9eb66c2206c3096b9aVirustotal results 40.00% Heodo
2022-03-31GJ-47832274012510.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31PY-7182396910581.xlsmxlsm 36828e7a04990e1d0b2b67ccfa64ea170ff92c77cf92107d904f1e106c1d676bn/a Heodo
2022-03-31XU-539661109347.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31LP-303230640.xlsmxlsm 9348419acaaa7a82adb28cd968f8b10b980dcfe9622044ff9a7a0383921a3c5fn/a Heodo
2022-03-31SNW-205249327.xlsmxlsm 6102217f21897ac71dc164ee9cb69526d874d45e748754b44309ae2b1d620880Virustotal results 40.32% Heodo
2022-03-31HBL-15916520032806.xlsmxlsm 578e2f6c9e64cb4de6991bae88f0e1e8d38afce9fb954c64d9ed303053647d94Virustotal results 38.10% Heodo
2022-03-31QKN-45834775763.xlsmxlsm a099f9c9c8eff7049da288a1205f1c0ccd52a4954930cabdd7a00dafbe8bbe6dn/a Heodo
2022-03-31BTD-193374390.xlsmxlsm a43da1637de01a06d72a9d09981de5132b8bd971844704ee9fc7c5e07450a49dn/a Heodo
2022-03-31KTY-61603605.xlsmxlsm 52939ecf287fe6bf3435960c423bf17f7ea8452f102024e9aca86cf806fdd533n/a Heodo
2022-03-31ZW-75168741639800.xlsmxlsm a7ae8fb40c5d93e9ddbfc68b000b65ba19b085e7a19d3a5d9bef1c243a6add91Virustotal results 37.10% Heodo
2022-03-31VNK-047359394542237.xlsmxlsm b73f04d9f7a2ce5624249871b7f1277fcc2959bfe5abcaa33e1da19e0da9cb08Virustotal results 38.10% Heodo
2022-03-30EHC-759265686533.xlsmxlsm 2b1f1f87033e83e264f05939f180b63165e067861f9c6f1253aedc9c9e1efb6en/a Heodo
2022-03-30AL-2856964959327.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30EW-02605521770.xlsmxlsm 70c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080Virustotal results 33.87% Heodo
2022-03-30ZF-400601946.xlsxls 2c52e5c5b59a9935971907d5a7da5617d5abec8d681b68f50c7201fd3943740fVirustotal results 28.33% SilentBuilder