URLhaus Database

You are currently viewing the URLhaus database entry for https://shilut.co.il/wp-content/XNsvolNOUiNCfdDiORpW/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1912762
URL: https://shilut.co.il/wp-content/XNsvolNOUiNCfdDiORpW/
URL Status:Offline
Host: shilut.co.il
Date added:2021-12-23 04:34:09 UTC
Last online:2021-12-23 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-23 04:37:43 UTC to abuse{at}upress[dot]io)
Takedown time:6 hours, 43 minutes Good (down since 2021-12-23 11:21:32 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-2306928391881913.xlsxls 0e32a98533816d8ab208379bcabce2d48d062e0de5cc36835e883bdf74bfdbe1n/a Heodo
2021-12-2314094129440935.xlsxls b5a8e2f5f7fe82dfbf09bbd6509f57d8b93bb81b5ab1a02e066e0cc7e7745a9dn/a Heodo
2021-12-2398392321933160.xlsxls 3f281c52f76f37ec6c7af45149aa8ee290cc1a5c57589290447e8cb2a4bdce9dn/a Heodo
2021-12-2346825408537664.xlsxls 91d4f32d6a37e6013639cd5e523e6328604a95436f8d3b266480f57a97599f2cn/a Heodo
2021-12-2344384846509220.xlsxls 5d04c011401a98e948beccb6839b44c77b81f51f10ed48fdfa37da8bdfcfef01n/a Heodo
2021-12-231644506930.xlsxls cccfc20f200c0af867f7557dcab45bbfd82ffc96adee9277a7aecef0a01282d1n/a Heodo
2021-12-2300967899871.xlsxls f9d1b2ac0446fed5d00c61bf9767fba85018d86908c3a74398d4f2c30f3d080fn/a Heodo
2021-12-2314244709486.xlsxls 38b0a1134b4dbc0535e2af788c285b2a9a920118a4c467b12de6841242437041n/a Heodo
2021-12-235295716731307876.xlsxls 0d8f1e5757e420044664a67e1605ac8c6c3d86b2db074dec26bfcea1a22b8cc6Virustotal results 27.12% Heodo
2021-12-2340204493423.xlsxls 3b448a4902f9e1d985beaa5989d261c52da7386dc56af861f0bf19aa28a0b235n/a SilentBuilder
2021-12-235555313800314511.xlsxls 9383486b0fe5c54abfaa21cc7578940e82c13a08426d83f50e223eef94c17c12n/a SilentBuilder
2021-12-2356151645674361.xlsxls b958448c944bd3b4afbb38f0b77222b86f3f85fd81d9e788d8b5ec163c0765ccn/a SilentBuilder
2021-12-230034129754.xlsxls 35b3ec235a74c436a5dd96bc91a68d8470967d4fc0a5af81be96d5cfbf8e352bn/a SilentBuilder
2021-12-234353150303310.xlsxls f76190b18d28381afc2abcba75ae59ed1d8f25fcb03df777dbe0da1eaf1d3fe1Virustotal results 18.97%SilentBuilder