URLhaus Database

You are currently viewing the URLhaus database entry for https://www.kinsleycarpets.com/umti/6KbLwoO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1912585
URL: https://www.kinsleycarpets.com/umti/6KbLwoO/
URL Status:Offline
Host: www.kinsleycarpets.com
Date added:2021-12-23 02:56:09 UTC
Last online:2021-12-23 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-23 04:17:26 UTC to abuse{at}fastly[dot]com)
Takedown time:18 hours, 14 minutes Good (down since 2021-12-23 21:13:02 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-2356142614753471.xlsxls dfd7779828492c51dbf83bfe709e2b29ae854940801beea6a77ad5734a9bd1een/a Heodo
2021-12-235905615.xlsxls dd590eda1c6d650b76a4a7bc6d3d33efe0519aabc2344ecf561cf383334c9a4fVirustotal results 10.17% SilentBuilder
2021-12-23883795447312531.xlsxls d683342dd068bc9cf01c50ecf4dd73d5cf6dcf37ce304d87bb14923b3cc15e0bn/a Heodo
2021-12-2317217802401684.xlsxls 2a170f15029d9d55b7dad42d14f58e962f45df96879073456075ca40bcbdcb68Virustotal results 25.00% Heodo
2021-12-233276485937.xlsxls 0a3621363179b1d5044498696f192289e20959c42feb6779a1167e07cc4ce096Virustotal results 26.67% Heodo
2021-12-23866218944977095.xlsxls 68ed5dfabe948c5eeb56e15202aebe6e35cfa9d38acd0a01198acd98b58f5a6an/a SilentBuilder
2021-12-23130350620.xlsxls 921dfcea3b1086e7243ddfa51fec707c61ef98591493e2c0234b18af5c16d19fn/aHeodo
2021-12-231249374937.xlsxls 60d0b1a03eca2a23c1337d4b0138f3f27e42de6faaf5d3cda9a409cb80cafe06n/a Heodo
2021-12-2394876701660836.xlsxls 3bd76c21ddc8ce464f239926304160909ad0688f9b0e891b08b03e8799eb4ed8n/aHeodo
2021-12-235355090859.xlsxls 076a7365070ab3cfede846be4e6882b3dbadd5ed505514a761e493b27154c593n/a Heodo
2021-12-23883171627432.xlsxls 9f16e116a70060507f773bc94da066aed1c061ee297187782804cc292e0bb11dn/a Heodo
2021-12-238584654094.xlsxls 2c082f893abab3d5123d930a0b32e95cc1fd5876dcf862ee0238c49eaad3bed9Virustotal results 22.41% SilentBuilder
2021-12-239566073483336.xlsxls afdbed432f0ebb3f625b0c3be873ecf66dadcf498552b4fd9bd6e9f2344c268en/a SilentBuilder
2021-12-23319872723101933.xlsxls eec031da304539d9cd2d1107b8ac16fb8415662f96b8b979c103d3ea4c780accn/a Heodo
2021-12-2359317750.xlsxls 3ec8692a3495e85f60bcd436beaf96a2626f10da6ab4c46f545168f92d2d06f4n/a SilentBuilder
2021-12-23512138866527.xlsxls 190fa8d2b5297aeb55c75f696f69cf1a0ea1ab45703e4047dc6baed4708833c1n/aSilentBuilder