URLhaus Database

You are currently viewing the URLhaus database entry for https://dev.centreformanagement.com/wp-admin/6LsGkKhRkrQ6jfngtbsMZR/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1911547
URL: https://dev.centreformanagement.com/wp-admin/6LsGkKhRkrQ6jfngtbsMZR/
URL Status:Offline
Host: dev.centreformanagement.com
Date added:2021-12-22 19:47:10 UTC
Last online:2021-12-23 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-22 19:48:03 UTC to abuse{at}digitalocean[dot]com)
Takedown time:9 hours, 43 minutes Good (down since 2021-12-23 05:31:31 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-2362327507.xlsxls 35be18251c8a0a0f21b6db45c2238f65f17a18168556f31e146652496bf60926n/aHeodo
2021-12-2388626831.xlsxls 3872c321886be0e22e3063113e957978408eab0ed39b6430dc5b94e0fe7caa5cn/a SilentBuilder
2021-12-2340403939450.xlsxls 70d0d557db77f8eaa47a791d85e5323c02a9e1628fabcaa29836bf3d8b877390n/a SilentBuilder
2021-12-2378962362807340.xlsxls 2fe52a04ad50a62b3c0248ad8a319bdc8e22cf9ec351f2d2c21b3e433e41d5c1Virustotal results 11.86% SilentBuilder
2021-12-23457529049625.xlsxls 3ec8692a3495e85f60bcd436beaf96a2626f10da6ab4c46f545168f92d2d06f4n/a SilentBuilder
2021-12-2330941139994.xlsxls 2f693fcf5bc268eeb30480c8dac5abdc03e67b62b6dd37d7488c0c30b7b3d830n/a SilentBuilder
2021-12-23487520733382442.xlsxls 0025199852ca978ef7bce4aaff59fbfa4b7bba5e1a1a0ce30eadfe03665bed22n/a SilentBuilder
2021-12-23078943371541717.xlsxls bb1f500a59544aa8e44a0377cc506dfbebca1ecb7a8c73dc72d3268803976ff5Virustotal results 11.86%Heodo
2021-12-236920296425.xlsxls f2103aadb258b32c6b334b37a3c7d9d34e6ccf93e46cff50be69c9e6c5f4eaefn/a SilentBuilder
2021-12-231026545406783972.xlsxls 58b6f1c79906e917ccd06eb3c83917af37d249284b707e1bfe6220d245c057adn/a SilentBuilder
2021-12-235415885789571.xlsxls f762edc3ae2ee2d4806395532cefca19990e468c50675601ae2fadbac22cf6a1n/a SilentBuilder
2021-12-2342706646642.xlsxls 46d6a384fe1773327c74c5e6daf03b4e1346cfef7e79d6e16045eccea064acden/a Heodo
2021-12-2336169960778.xlsxls fbb0cc09d355c9dc86dfd388b1ba518fa033f164d9fd7d7c153569d634c2d344Virustotal results 8.62% SilentBuilder
2021-12-233566114744037.xlsxls 5eb66d76f40bfc2a8b27ae16d451f2f8c3eddb77bf14e8fa7006f0d7ed9925c2n/a SilentBuilder
2021-12-233561608055944.xlsxls a77fdd8caa031879de1d7b1219b9699cd855f89cab181b1288263dc2b9aa46aen/a SilentBuilder
2021-12-2341951787013325.xlsxls 3562ec05b853a5e0c4a76ff5233111facbbd2f18efa7840486768678d8bc6ffaVirustotal results 8.47% Heodo
2021-12-2390275494599072.xlsxls 71ce4d2a61218d2eb7aa64f6eb54ee882b91858a6637b249236ba2311306a47an/a Heodo
2021-12-23758112711932.xlsxls cd4d619ab506aae0783d235a65a5ea81ecf24e23ff0aa826290204b32d09312dn/a SilentBuilder
2021-12-220208381108034.xlsxls db92f422b8f88e6dd2cc9cdd5a44b484dd285b5c96be3dd600f8bc6930e4d067n/a SilentBuilder
2021-12-22911064522249704.xlsxls a18e4bb956b6b38e27093989c5216b66d255179e4ee3a202b512cb1c2978d30bVirustotal results 8.47% Heodo
2021-12-2235450062485.xlsxls aa17b924f527a07b5971c94621c9147da62dc63e08138231afc771a505f709bdn/a SilentBuilder
2021-12-22198983669523.xlsxls a1b3ca2239e199f15779dcc54004b69e3413b89b0fcde2494fac1fdb7197f7adVirustotal results 8.47% SilentBuilder
2021-12-2251570792649296.xlsxls b080439aaf1036ac2d617cf00fa4021e336c9083d60c134a371f33705d040da7n/a Heodo
2021-12-222760608792987.xlsxls 4ce312179df139b3a8bcaba9729f79e9c54413e250d3124b94050b9656c6c993Virustotal results 8.47% SilentBuilder
2021-12-22813274404.xlsxls c978447405ca3454cf66979431c05f3d14faf52b880eeec119ccec8f18eca36an/a SilentBuilder
2021-12-22034617107910475.xlsxls 33a1d3874c91f4d2d88f52963e8a163828bb4e21c4a527893e9f921fa0fb20c4n/a SilentBuilder
2021-12-224621328298096111.xlsxls 78613d1e859edb786d88023eb65743cbc80582ac3180bdf1745434705e66ca76Virustotal results 8.47% SilentBuilder
2021-12-221336947367495366.xlsxls 4bf5b6ac305620d946404578918fdddfbf63abab8d0963cb687a567025a6bdf8n/a Heodo
2021-12-228539668425.xlsxls 190bc13e5415ab3c9c44c97897bcb5ac462678f7af7f9c84fd97322f7df6b1c0n/a SilentBuilder
2021-12-22246861636.xlsxls 24af5c77b55091be278b48b0440aed89eee457727a415a9c1514b4bc1e529b94n/a SilentBuilder
2021-12-2208118447.xlsxls 9d521d7bbcf62966df8bd7b0f543725aef52cd90e11ef6c6c9d93a6d216d6b28n/a SilentBuilder
2021-12-223510942412517302.xlsxls fd15ac961dee69febf988661c6c65788922c230d40f5f38ea12d33417072ab41n/a Heodo
2021-12-2237420105.xlsxls 0a8faae4d7e493dec8c3846100ba33f253cf92c326b024f198810dfc5ff98096n/a SilentBuilder