URLhaus Database

You are currently viewing the URLhaus database entry for https://www.ajltc.com/error/7Nt1KQYskFuK4aM0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1912853
URL: https://www.ajltc.com/error/7Nt1KQYskFuK4aM0/
URL Status:Offline
Host: www.ajltc.com
Date added:2021-12-23 05:20:09 UTC
Last online:2021-12-23 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2021-12-23 05:22:49 UTC to abuse{at}contabo[dot]de)
Takedown time:7 hours, 4 minutes Good (down since 2021-12-23 12:27:30 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-232050705.xlsxls e3a9d309c10cb7a17ffaee1c74fa30e5e123aaec12fd8c0dd3ca206d69fb4691n/a Heodo
2021-12-23330542060.xlsxls 8e265de839b78193a00679ecba6cd61052a5b33aeebbc0546d198e6adb3807b6n/a Heodo
2021-12-236245596792181.xlsxls 6f83a6ead72ff0d14bb2a3d7b8eb3db5f845be37678dc1577f8aa199b4aeab22n/a Heodo
2021-12-23016488044.xlsxls a9380ad0743d9b5eb5e7fab8c4e512349f81e5273ee5c12efd2ae97b23c6bdd2n/a Heodo
2021-12-232339187484016127.xlsxls b5a8e2f5f7fe82dfbf09bbd6509f57d8b93bb81b5ab1a02e066e0cc7e7745a9dn/a Heodo
2021-12-2353493880677.xlsxls 6d076a0d09a400f6eb5296a78f5cf87f65f12796479513180f680cf1d94639a2n/a Heodo
2021-12-23232778843.xlsxls 4393bf49903e8d699fa450df1c35c2bcaf3d6669c092433f7f788f7214c64f9bn/a Heodo
2021-12-232077129.xlsxls 435a3b34c0bd974f368bce0cc95457050f3e727c580c104534377c66edfc8ec2n/a Heodo
2021-12-2317843604712199.xlsxls cccfc20f200c0af867f7557dcab45bbfd82ffc96adee9277a7aecef0a01282d1n/a Heodo
2021-12-2338161294.xlsxls 708baaf025f75fa82c574eb1da9af0b5cc5cc2db4f602eed6f4a976a8bd0d8faVirustotal results 28.07%Heodo
2021-12-233328603002.xlsxls 38b0a1134b4dbc0535e2af788c285b2a9a920118a4c467b12de6841242437041n/a Heodo
2021-12-239075539861.xlsxls fe2203b02b75563948e0147d2e17f6481116f2a58551df60416c61fcd764c37cn/a Heodo
2021-12-2377781315.xlsxls a830905d19c1b1a262f5b6484dcbf74166b52e6742b363f5049fa03cec849557Virustotal results 25.86%Heodo
2021-12-2309974901821.xlsxls 4d8d170d7e4981f57bc7f628b4ac01800a7c97e9edc66396e79bb788781ee407n/a Heodo
2021-12-236006254676.xlsxls ef628739521d7af4df6459f02442985d4a9a3f122cd55c98540bb3a1d648cae5n/a SilentBuilder
2021-12-23942447308313.xlsxls 2991e95d6d3b92341bd33e2c9dc75dab521b1e38be10120fdc3e542ee4eba881n/a SilentBuilder
2021-12-236013639045382.xlsxls c8c7b870ad369ca2d82bbde60db56a271583f85d80bb3acd3a6821e966cc49c2n/a SilentBuilder
2021-12-238973239545.xlsxls afdbed432f0ebb3f625b0c3be873ecf66dadcf498552b4fd9bd6e9f2344c268en/a SilentBuilder
2021-12-2354344076.xlsxls de7de9765eabead5bd6377dc654014f8f40d0db4203a42f4dd041590306627fen/a SilentBuilder
2021-12-2368107910832563.xlsxls 98129ad7ffef48ee9545ff21e9295f54d6062e38ba637fc26d01a4db71878f90Virustotal results 22.03% SilentBuilder
2021-12-231184089133814604.xlsxls bdf78e25ae666795658b92797fad50ff224cd5f52f4c2b7a38259dea667d6681Virustotal results 10.17% SilentBuilder
2021-12-236922642743207.xlsxls c4357d9b592c32ab709d295c6f0c06530f1747ffc07e8939c2743c3fcb76df59Virustotal results 23.73%Heodo