URLhaus Database

You are currently viewing the URLhaus database entry for https://xn----dxfcb0dpc9czaq0a0b1aj1dxcfb3fwgna1b5hpb2h.com/wp-includes/UI7LCyrpzZQvk5Xjl5M3gyQ9kb4z/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1911926
URL: https://xn----dxfcb0dpc9czaq0a0b1aj1dxcfb3fwgna1b5hpb2h.com/wp-includes/UI7LCyrpzZQvk5Xjl5M3gyQ9kb4z/
URL Status:Offline
Host: เอ็มบีที-โซลูชั่นเซอร์วิส.com
Date added:2021-12-22 21:41:10 UTC
Last online:2021-12-23 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-22 22:59:37 UTC to ip_admin{at}csl[dot]co[dot]th)
Takedown time:15 hours, 26 minutes Good (down since 2021-12-23 13:09:31 UTC)
Tags:emotet link heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-2320272045137.xlsxls 081ba0d2825548ebed528cadc5c597819690cbb0a93451d15bfd71aa089f278cVirustotal results 30.00% Heodo
2021-12-233984370301298.xlsxls 06a7f7a6296b774253c7bc810254dac777e521daaef2ee031849b9194c635529Virustotal results 25.00% Heodo
2021-12-2353499333344.xlsxls 296e3773821633c66d27b4c4438ec9ae76ee2cad7fc00a9f6b852394ca2b1a41Virustotal results 22.41% Heodo
2021-12-23991906544229.xlsxls 99ed0d39c05e7f5c0495b4112cdf0cbc2fe07e88066b644524f134b0450a87cbn/a Heodo
2021-12-2336945048.xlsxls bf9c5da5a619725b7e1236035d41d5bfd7d3aa3d88d0be766d31deafc00bf5b0n/a Heodo
2021-12-23222242738191.xlsxls 6f83a6ead72ff0d14bb2a3d7b8eb3db5f845be37678dc1577f8aa199b4aeab22n/a Heodo
2021-12-233297499.xlsxls 0e32a98533816d8ab208379bcabce2d48d062e0de5cc36835e883bdf74bfdbe1n/a Heodo
2021-12-2380490424147862.xlsxls 3f281c52f76f37ec6c7af45149aa8ee290cc1a5c57589290447e8cb2a4bdce9dn/a Heodo
2021-12-230491475.xlsxls 4393bf49903e8d699fa450df1c35c2bcaf3d6669c092433f7f788f7214c64f9bn/a Heodo
2021-12-235276359761.xlsxls 435a3b34c0bd974f368bce0cc95457050f3e727c580c104534377c66edfc8ec2n/a Heodo
2021-12-23239641234662009.xlsxls cccfc20f200c0af867f7557dcab45bbfd82ffc96adee9277a7aecef0a01282d1n/a Heodo
2021-12-23325579345982.xlsxls f9d1b2ac0446fed5d00c61bf9767fba85018d86908c3a74398d4f2c30f3d080fn/a Heodo
2021-12-2346696781782034.xlsxls 38b0a1134b4dbc0535e2af788c285b2a9a920118a4c467b12de6841242437041n/a Heodo
2021-12-231483021397807848.xlsxls 0d8f1e5757e420044664a67e1605ac8c6c3d86b2db074dec26bfcea1a22b8cc6Virustotal results 27.12% Heodo
2021-12-2382355591.xlsxls a830905d19c1b1a262f5b6484dcbf74166b52e6742b363f5049fa03cec849557Virustotal results 25.86%Heodo
2021-12-237022402.xlsxls bd1ddfbb2390d5865299be2f8da009b582da2c9aab723d7e0f5f6077b692de14n/a SilentBuilder
2021-12-23206176686.xlsxls fa2dbb22999bae5686e353cc57b1b76fe79d4181c5f8360a6325f643deeaec3dn/a SilentBuilder
2021-12-230892258.xlsxls 2991e95d6d3b92341bd33e2c9dc75dab521b1e38be10120fdc3e542ee4eba881n/a SilentBuilder
2021-12-2308381554546747.xlsxls 11bacde63fd95e99c4061fabbba6c504fa4e782eb0923513bb8e6433857ada23n/a SilentBuilder
2021-12-23758882574.xlsxls 0934d436a87cc83e019e9ee2949ead8c647bb4c26738be5c91f568dd6f023c2cn/a SilentBuilder
2021-12-23690927966547.xlsxls f43334acc07f6a013334b7399e0e4ce391fbfd6a73dd40daf68397d1de426731n/a SilentBuilder
2021-12-231220296.xlsxls b4fdc798e4c49df58164144b8bc115b1f9757ee3ca92832554dd921e65ea5e24n/a SilentBuilder
2021-12-235296404979583.xlsxls b7c6a3d65ca7c2fe92b81b8271ebf8d781a8e17295133aef89864ff6cc0db08cn/a SilentBuilder
2021-12-236600755810.xlsxls a36fe3a855e95e22df1200bc1678183cf6e56215d765ae39d4e7728cad9971c6n/aSilentBuilder
2021-12-2393920073925834.xlsxls eec031da304539d9cd2d1107b8ac16fb8415662f96b8b979c103d3ea4c780accn/a Heodo
2021-12-23900429050723596.xlsxls 3872c321886be0e22e3063113e957978408eab0ed39b6430dc5b94e0fe7caa5cn/a SilentBuilder
2021-12-2340044273768629.xlsxls 70d0d557db77f8eaa47a791d85e5323c02a9e1628fabcaa29836bf3d8b877390n/a SilentBuilder
2021-12-23859125897606.xlsxls f76190b18d28381afc2abcba75ae59ed1d8f25fcb03df777dbe0da1eaf1d3fe1n/aSilentBuilder
2021-12-2349733951506951.xlsxls a74a6a8140c11fc076d82f4a808994b267aaa839b9076dd2bae14909922e7efdVirustotal results 15.25% SilentBuilder
2021-12-238920444342007072.xlsxls 1aa52da08de6b2732f449f29515ec792060270972541fe18d3494b4dd4779c7en/a SilentBuilder
2021-12-232684155358664.xlsxls 0025199852ca978ef7bce4aaff59fbfa4b7bba5e1a1a0ce30eadfe03665bed22n/a SilentBuilder
2021-12-2312940049089319.xlsxls 22f3dd823009e3b1c3547eaf2ae78c54fcb499e4a0055c5db099ea28bdea93acn/a SilentBuilder
2021-12-23622425373166362.xlsxls f2103aadb258b32c6b334b37a3c7d9d34e6ccf93e46cff50be69c9e6c5f4eaefn/a SilentBuilder
2021-12-23638424447.xlsxls 7ab793a1270a4fb7bd09fb7de0de1e7b5888d779d754cad8c37e66f9c67324d3Virustotal results 10.34% Heodo
2021-12-23516328936174879.xlsxls c835ed1a6caf23a3b743904304bb129af57cdde25b5bda909b79c8403f26ec8fVirustotal results 8.62% SilentBuilder
2021-12-2382398258.xlsxls 46d6a384fe1773327c74c5e6daf03b4e1346cfef7e79d6e16045eccea064acden/a Heodo
2021-12-233844735.xlsxls fbb0cc09d355c9dc86dfd388b1ba518fa033f164d9fd7d7c153569d634c2d344n/a SilentBuilder
2021-12-233375351965.xlsxls c7f887f62cc9dfe2d1671f88ad3a5ffff3aeb616d0cc417794417ecb8eb2e2a6n/a SilentBuilder
2021-12-239109083.xlsxls bfba685c79afbf6e71cfa6d89ee8b0c7e87673c4e33556b6eb5fb2852830b480n/a Heodo
2021-12-237092621.xlsxls 27f8caadd89e37f700e1f7d559e30ab71197ebd6ee61c11a47cfb196022f1181n/a SilentBuilder
2021-12-23300187753.xlsxls 71ce4d2a61218d2eb7aa64f6eb54ee882b91858a6637b249236ba2311306a47an/a Heodo
2021-12-2394421570544.xlsxls cd4d619ab506aae0783d235a65a5ea81ecf24e23ff0aa826290204b32d09312dn/a SilentBuilder
2021-12-225821130.xlsxls b2b44b7062a6cdfb2cf542803949ac33f58e3771be2a1317b1e45563708b76cbn/a Heodo
2021-12-229423066132.xlsxls 782ce88a29e9dd5110563619aaa8f38aaadee5e45274bffa62cbb9add8c268f7n/aSilentBuilder
2021-12-223961828060497938.xlsxls a18e4bb956b6b38e27093989c5216b66d255179e4ee3a202b512cb1c2978d30bVirustotal results 8.47% Heodo
2021-12-225334808.xlsxls 8198d38eec5db0d3d520fbd8134884815417db8678630b611fee32b88e02950en/aSilentBuilder
2021-12-2268098318.xlsxls 4bc82c0fffc76a0de6a0c01538814e95761bf7a623aca56f4c09e08ee1a35dban/a SilentBuilder
2021-12-222609331.xlsxls b080439aaf1036ac2d617cf00fa4021e336c9083d60c134a371f33705d040da7n/a Heodo
2021-12-2295376286341.xlsxls 42b1a56d963f34383be3599330ecc37c2d003379e082fda309f2648189091cf6n/a SilentBuilder
2021-12-22866908278447.xlsxls 74b0a40422f59f58409cb66005be0bff31a108460ca83d61ca0a28818ebfe8b9n/a Heodo
2021-12-220451774174183431.xlsxls feeac990622d076845452171c5e728463e91f6aef7a9377e30b9584608c6c384Virustotal results 8.47% Heodo