URLhaus Database

You are currently viewing the URLhaus database entry for https://antikuignace.cz/zhwhqpzf/n8t0kkM0wwwD8H0RAS7fxDH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1912755
URL: https://antikuignace.cz/zhwhqpzf/n8t0kkM0wwwD8H0RAS7fxDH/
URL Status:Offline
Host: antikuignace.cz
Date added:2021-12-23 04:29:11 UTC
Last online:2021-12-23 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-23 04:31:45 UTC to abuse{at}active24[dot]cz)
Takedown time:8 hours, 2 minutes Good (down since 2021-12-23 12:34:18 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-23732730879813.xlsxls 0ad385922a01543568e212cfb1e35edf9089b10809986ef0790cebbb8cea45fan/a Heodo
2021-12-2333100080842.xlsxls 99ed0d39c05e7f5c0495b4112cdf0cbc2fe07e88066b644524f134b0450a87cbn/a Heodo
2021-12-23420531376167352.xlsxls 61130a5847b536ab3ea8864f5117bb92b3408849d4cc5a8ab3443f7c20872ff2n/a Heodo
2021-12-23198274152.xlsxls 6f83a6ead72ff0d14bb2a3d7b8eb3db5f845be37678dc1577f8aa199b4aeab22n/a Heodo
2021-12-2335761280970674.xlsxls a2930c425172e491112c3240dc1b5112a659050d0aab05594c04b30248232808n/a Heodo
2021-12-233524697.xlsxls b5a8e2f5f7fe82dfbf09bbd6509f57d8b93bb81b5ab1a02e066e0cc7e7745a9dn/a Heodo
2021-12-23600996165767125.xlsxls 6d076a0d09a400f6eb5296a78f5cf87f65f12796479513180f680cf1d94639a2n/a Heodo
2021-12-239197941515992745.xlsxls 4393bf49903e8d699fa450df1c35c2bcaf3d6669c092433f7f788f7214c64f9bn/a Heodo
2021-12-2395031402391.xlsxls 435a3b34c0bd974f368bce0cc95457050f3e727c580c104534377c66edfc8ec2n/a Heodo
2021-12-239458194.xlsxls f9d1b2ac0446fed5d00c61bf9767fba85018d86908c3a74398d4f2c30f3d080fn/a Heodo
2021-12-2387816793924604.xlsxls 708baaf025f75fa82c574eb1da9af0b5cc5cc2db4f602eed6f4a976a8bd0d8fan/aHeodo
2021-12-231381496923724905.xlsxls 9f16e116a70060507f773bc94da066aed1c061ee297187782804cc292e0bb11dn/a Heodo
2021-12-23636438865.xlsxls a830905d19c1b1a262f5b6484dcbf74166b52e6742b363f5049fa03cec849557Virustotal results 25.86%Heodo
2021-12-23637691293365.xlsxls bd1ddfbb2390d5865299be2f8da009b582da2c9aab723d7e0f5f6077b692de14Virustotal results 21.05% SilentBuilder
2021-12-2305926020296.xlsxls ef628739521d7af4df6459f02442985d4a9a3f122cd55c98540bb3a1d648cae5n/a SilentBuilder
2021-12-23374474702.xlsxls 2c082f893abab3d5123d930a0b32e95cc1fd5876dcf862ee0238c49eaad3bed9Virustotal results 22.41% SilentBuilder
2021-12-237796722.xlsxls c8c7b870ad369ca2d82bbde60db56a271583f85d80bb3acd3a6821e966cc49c2n/a SilentBuilder
2021-12-237474629951635.xlsxls 0564019bae796d2300aaac993d851131a1ef1b3d348be92356ecbdfe3bce29b0n/a SilentBuilder
2021-12-235703800.xlsxls 0f0eb6a7891445a5fe95c48b056bc0439853688ed4b1ad430745ec700eaf8415n/a SilentBuilder
2021-12-2300595020.xlsxls 35be18251c8a0a0f21b6db45c2238f65f17a18168556f31e146652496bf60926n/aHeodo
2021-12-236638373359024.xlsxls 3872c321886be0e22e3063113e957978408eab0ed39b6430dc5b94e0fe7caa5cVirustotal results 20.69% SilentBuilder
2021-12-23050284431.xlsxls 7322337b79e75a1a0b494af3b323e8c60e134eab541ab836ee4a943ada51a268Virustotal results 11.86% Heodo