URLhaus Database

You are currently viewing the URLhaus database entry for https://tripthaithai.com/cgi-bin/BFcXshRsIWIdbZk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1912129
URL: https://tripthaithai.com/cgi-bin/BFcXshRsIWIdbZk/
URL Status:Offline
Host: tripthaithai.com
Date added:2021-12-22 23:15:12 UTC
Last online:2022-03-10 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-22 23:17:38 UTC to noc{at}premianet[dot]com)
Takedown time:2 months, 18 days, 0 hours, 4 minutes Bad (down since 2022-03-10 23:22:24 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-2358454178.xlsxls 9f16e116a70060507f773bc94da066aed1c061ee297187782804cc292e0bb11dVirustotal results 25.42% Heodo
2021-12-2327929977.xlsxls 0d8f1e5757e420044664a67e1605ac8c6c3d86b2db074dec26bfcea1a22b8cc6Virustotal results 27.12% Heodo
2021-12-234119948218406.xlsxls 3b448a4902f9e1d985beaa5989d261c52da7386dc56af861f0bf19aa28a0b235n/a SilentBuilder
2021-12-2309096044467.xlsxls 4d8d170d7e4981f57bc7f628b4ac01800a7c97e9edc66396e79bb788781ee407n/a Heodo
2021-12-2366808533906.xlsxls ef628739521d7af4df6459f02442985d4a9a3f122cd55c98540bb3a1d648cae5n/a SilentBuilder
2021-12-23900619243398.xlsxls 2991e95d6d3b92341bd33e2c9dc75dab521b1e38be10120fdc3e542ee4eba881n/a SilentBuilder
2021-12-23242875026248.xlsxls 11bacde63fd95e99c4061fabbba6c504fa4e782eb0923513bb8e6433857ada23n/a SilentBuilder
2021-12-2358076075280357.xlsxls 0934d436a87cc83e019e9ee2949ead8c647bb4c26738be5c91f568dd6f023c2cn/a SilentBuilder
2021-12-232674620928186.xlsxls de7de9765eabead5bd6377dc654014f8f40d0db4203a42f4dd041590306627fen/a SilentBuilder
2021-12-2335686829.xlsxls b4fdc798e4c49df58164144b8bc115b1f9757ee3ca92832554dd921e65ea5e24n/a SilentBuilder
2021-12-235600329.xlsxls d518f3288658ae304b6cf729edc4df00aa31c18bc6ddf5586518d077bab48b71n/a SilentBuilder
2021-12-23506316627.xlsxls a36fe3a855e95e22df1200bc1678183cf6e56215d765ae39d4e7728cad9971c6n/aSilentBuilder
2021-12-236449525122112.xlsxls 35be18251c8a0a0f21b6db45c2238f65f17a18168556f31e146652496bf60926n/aHeodo
2021-12-239948421647238213.xlsxls 3872c321886be0e22e3063113e957978408eab0ed39b6430dc5b94e0fe7caa5cVirustotal results 20.69% SilentBuilder
2021-12-2363390458.xlsxls 70d0d557db77f8eaa47a791d85e5323c02a9e1628fabcaa29836bf3d8b877390n/a SilentBuilder
2021-12-23130290068745.xlsxls f76190b18d28381afc2abcba75ae59ed1d8f25fcb03df777dbe0da1eaf1d3fe1n/aSilentBuilder
2021-12-2394218622.xlsxls 3ec8692a3495e85f60bcd436beaf96a2626f10da6ab4c46f545168f92d2d06f4n/a SilentBuilder
2021-12-23643838468577.xlsxls ff86eb3305c0520dd0fa6cecb08120a60af4352e065e5cfce7cff30eeb0259efn/a SilentBuilder
2021-12-23597464357.xlsxls 9fbef3bf291c5ce45854de786b83be78d6d79172da8f3dfddc8c752dbf5390bfn/a SilentBuilder
2021-12-2328367204817237.xlsxls 3800d681c53d137034ff44b7e95a3065379f905a7f3f85733d4550739afe9772n/a SilentBuilder
2021-12-237761595.xlsxls 2f27f733dc8f8f0fbd78adc150ebb307d25a7a94e8e7c0e3f4430277228ee985n/a SilentBuilder
2021-12-2310795081.xlsxls 64fd394081f3e12eecc37b1b20d6b540ca8dcd22dc6cf673c289db5b71e52644n/a SilentBuilder
2021-12-2399186535.xlsxls fc427adb111a2cdd28c3799b619887f125d8c79900419fdd0918cb4f09084ab9n/a SilentBuilder
2021-12-2325009969.xlsxls c835ed1a6caf23a3b743904304bb129af57cdde25b5bda909b79c8403f26ec8fn/a SilentBuilder
2021-12-23219362620998945.xlsxls 46d6a384fe1773327c74c5e6daf03b4e1346cfef7e79d6e16045eccea064acden/a Heodo
2021-12-234580482.xlsxls 5eb66d76f40bfc2a8b27ae16d451f2f8c3eddb77bf14e8fa7006f0d7ed9925c2n/a SilentBuilder
2021-12-234895110232621.xlsxls a77fdd8caa031879de1d7b1219b9699cd855f89cab181b1288263dc2b9aa46aen/a SilentBuilder
2021-12-23209449023646.xlsxls 36e9b3190a9f5aaa096db55662e3b86f587c3437ba1171e3ce4989738ce3a8b3n/a SilentBuilder
2021-12-2392774120189.xlsxls d58f6338b65915d66827a3760075350560ec2789c74cc1b5e6720c1b4ea1fee6n/a SilentBuilder
2021-12-2332610234405946.xlsxls cd4d619ab506aae0783d235a65a5ea81ecf24e23ff0aa826290204b32d09312dn/a SilentBuilder
2021-12-2254808059388.xlsxls b2b44b7062a6cdfb2cf542803949ac33f58e3771be2a1317b1e45563708b76cbn/a Heodo
2021-12-225413482763749981.xlsxls db92f422b8f88e6dd2cc9cdd5a44b484dd285b5c96be3dd600f8bc6930e4d067n/a SilentBuilder
2021-12-229567040509578376.xlsxls a18e4bb956b6b38e27093989c5216b66d255179e4ee3a202b512cb1c2978d30bVirustotal results 8.47% Heodo
2021-12-222995315866795799.xlsxls 8198d38eec5db0d3d520fbd8134884815417db8678630b611fee32b88e02950en/aSilentBuilder