URLhaus Database

You are currently viewing the URLhaus database entry for https://www.grs-law.co.il/wp-content/Iy6LJel5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1912273
URL: https://www.grs-law.co.il/wp-content/Iy6LJel5/
URL Status:Offline
Host: www.grs-law.co.il
Date added:2021-12-23 00:21:10 UTC
Last online:2021-12-30 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-24 12:34:53 UTC to abuse{at}upress[dot]io)
Takedown time:7 days, 12 hours, 30 minutes Bad (down since 2021-12-30 12:52:22 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-24S80163932.xlsxls 62ad1a5b37f3214fdc0f53728e419bc917b25887aa8606f8e7fc0a0d67b405c3n/a SilentBuilder
2021-12-23021306358.xlsxls 0bbeda098ad556597fe0db6dd2b80691c40b7b7615e03d893c58fa72c15bb81an/a Heodo
2021-12-237368912908.xlsxls 6d076a0d09a400f6eb5296a78f5cf87f65f12796479513180f680cf1d94639a2n/a Heodo
2021-12-2347775109050.xlsxls 91d4f32d6a37e6013639cd5e523e6328604a95436f8d3b266480f57a97599f2cn/a Heodo
2021-12-2365857314.xlsxls 5d04c011401a98e948beccb6839b44c77b81f51f10ed48fdfa37da8bdfcfef01n/a Heodo
2021-12-23207395183.xlsxls 5aa2dcb4727416fa7c4f3578d71e2229175dad5cd1740520fa76afd45a12e243n/aHeodo
2021-12-234775316881156931.xlsxls f76d3ae4cd2e076ad86e9185b914c361bd2f07390b2425574dfdf3259fe2c6a7n/a Heodo
2021-12-232222271380.xlsxls 4c9b243a083c632568be76fbf2e3f79e8d4a072e74a6d793931ed1c18f4b6981n/a Heodo
2021-12-235377663.xlsxls 3d030daa4c5a1c0b9c41373517edbe229eac34181afd3cd75e3dfe9d98534e37n/a Heodo
2021-12-238794285160325.xlsxls a547209a951270ede9c330ecd88bfe8591ed48858e9c7aa5a4be24db990899bbn/a Heodo
2021-12-234143989808974472.xlsxls 9383486b0fe5c54abfaa21cc7578940e82c13a08426d83f50e223eef94c17c12n/a SilentBuilder
2021-12-23482870129319487.xlsxls 0a59b8c055a3c609d940912bda66463dda4e0f6be4de2db902fa53208e728da0n/a SilentBuilder
2021-12-236128994311.xlsxls 70630d3780a6cfd4e0228c9d5fc5f629fd9824d39d31498f9260e6fd9de6a3e4n/a SilentBuilder
2021-12-238459415720540517.xlsxls 11bacde63fd95e99c4061fabbba6c504fa4e782eb0923513bb8e6433857ada23n/a SilentBuilder
2021-12-23368555872.xlsxls 0934d436a87cc83e019e9ee2949ead8c647bb4c26738be5c91f568dd6f023c2cn/a SilentBuilder
2021-12-23188826737632846.xlsxls de7de9765eabead5bd6377dc654014f8f40d0db4203a42f4dd041590306627fen/a SilentBuilder
2021-12-232692549786187.xlsxls 0f0eb6a7891445a5fe95c48b056bc0439853688ed4b1ad430745ec700eaf8415n/a SilentBuilder
2021-12-23968528814607.xlsxls c4357d9b592c32ab709d295c6f0c06530f1747ffc07e8939c2743c3fcb76df59Virustotal results 23.73%Heodo
2021-12-233918709.xlsxls ca19624a8586a5e6a6ea2e56dad4bd0da8ec01da384b89d5fcab2a74cfd0ca5bVirustotal results 22.03% SilentBuilder
2021-12-231530312242.xlsxls 52a5a4d7c1aa0abcc55b9f88a4f0879c142237774c175dcb7f448f08561ce2b6n/a SilentBuilder
2021-12-23204573205054264.xlsxls 7322337b79e75a1a0b494af3b323e8c60e134eab541ab836ee4a943ada51a268Virustotal results 11.86% Heodo
2021-12-2325265635629.xlsxls fd626c1e1cbf1df5d6d159cc221f384bfde0996a4ffc766cd69792ebded851d4n/a SilentBuilder
2021-12-2315733808135.xlsxls f0a52190156e0ad7421c35e3061cf465750194ce1fc5e418cc4810228c11d2dfn/a SilentBuilder
2021-12-2304921877581.xlsxls 9fbef3bf291c5ce45854de786b83be78d6d79172da8f3dfddc8c752dbf5390bfn/a SilentBuilder
2021-12-238621328.xlsxls 22f3dd823009e3b1c3547eaf2ae78c54fcb499e4a0055c5db099ea28bdea93acn/a SilentBuilder
2021-12-23965846067.xlsxls 190fa8d2b5297aeb55c75f696f69cf1a0ea1ab45703e4047dc6baed4708833c1n/aSilentBuilder
2021-12-23272326330.xlsxls 3a6ed7a4a26c48e5ea2eea613923ea7b8655a6d24e0b1b8abf1bc6ab97393a47n/a SilentBuilder
2021-12-238606475958827277.xlsxls f7099e9d8d7f7a6ebd3090991db365d9d18a1df71f9c2b7fe6cfbb12200b97e1n/a SilentBuilder
2021-12-230930697336024.xlsxls 46549909e329faf4ef851f602d8c1091c253897e0292ae05d83b73da7914077en/aSilentBuilder
2021-12-2323423946.xlsxls 36ac70c1b4e019434bdf1314c3bc51b08014520af73a445b3d85070a7bc9bf39n/a SilentBuilder
2021-12-23155125044.xlsxls c7f887f62cc9dfe2d1671f88ad3a5ffff3aeb616d0cc417794417ecb8eb2e2a6n/a SilentBuilder
2021-12-23939946541263.xlsxls bfba685c79afbf6e71cfa6d89ee8b0c7e87673c4e33556b6eb5fb2852830b480n/a Heodo
2021-12-2335725273807.xlsxls 4b44ab8cc51eb8831ddcc736814dc7db7cd04dc480e782d3284721df581aaa00n/a Heodo
2021-12-23487346539.xlsxls d58f6338b65915d66827a3760075350560ec2789c74cc1b5e6720c1b4ea1fee6n/a SilentBuilder