URLhaus Database

You are currently viewing the URLhaus database entry for https://hotelconcordia.org/ggvr0/WKmvHSwgBeXokenxdwin/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1914634
URL: https://hotelconcordia.org/ggvr0/WKmvHSwgBeXokenxdwin/
URL Status:Offline
Host: hotelconcordia.org
Date added:2021-12-23 17:21:09 UTC
Last online:2021-12-25 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2021-12-23 17:24:44 UTC to abuse{at}ovh[dot]net)
Takedown time:1 day, 15 hours, 32 minutes Poor (down since 2021-12-25 08:57:33 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-23K114195239032665.xlsxls bf2ab85915cec25bbc91d10f52da8fb358f036ad0d5ee018d0c5667c00ff2bd5n/a Heodo
2021-12-23L72034513798476.xlsxls b48f7b121f5707c3a4c832b519b1a288ef64cadac57b48ffe2a2730f9cf51ea4n/a Heodo
2021-12-23I8518915757618.xlsxls dede6cb4361e8c2bb4483bd6427d7f7d88dd05f2a04d5b4a145122e328015e06n/a Heodo
2021-12-23H04824041799417.xlsxls cdbb955f375a588fa658c5e4b65fecca4256c01531aeaca4dc573ae0f22aa96bn/a Heodo
2021-12-23K026834398503.xlsxls d2244f1a1199be4f3a5c046ff114858c5575f84c425cc6cf59071e506bdc3b39n/a SilentBuilder
2021-12-23G0979901955568.xlsxls a8bb4305ce8a95459b41d2e079fd0b078899672f7ae4c0ed37638933ccc13addn/a Heodo
2021-12-23P44061447768.xlsxls 69694ff40a317e36530c1a44156dfa2469191a44daf84ab5e2f345c7e7c00ef6n/aHeodo
2021-12-23Y2612579886275530.xlsxls 6ff0b718c0d8c09933d3bd3611b25525d00628e3f01d5f55624af3388b90e966n/aHeodo
2021-12-239886176387372.xlsxls 861cb62cead8d40f593f586755b1479dcc59e2ceafa956c149f2ebd073efadb1n/a Heodo
2021-12-2331231397192915.xlsxls a5bc5901f86b006d4956ecc16e7eb5bd82236314ab68e08ffb88dcb31f43b960Virustotal results 10.17% Heodo
2021-12-23813105218.xlsxls dca371cb8fee37211c6c1e43c672edb1375ca96ae71001d33eebf93b59baee97n/a Heodo
2021-12-236342049995261330.xlsxls dfd7779828492c51dbf83bfe709e2b29ae854940801beea6a77ad5734a9bd1een/a Heodo
2021-12-237169265853.xlsxls 3d864a5abb894f87beb6922c0c3e9281328fb736fb6a8aca743622504374bc59Virustotal results 10.17% Heodo
2021-12-23429596141830685.xlsxls dd590eda1c6d650b76a4a7bc6d3d33efe0519aabc2344ecf561cf383334c9a4fn/a SilentBuilder
2021-12-23185714864745416.xlsxls c2310be234dd8d3e21637f41cee21abeb02069f430950a056c43c790c20d650dn/a SilentBuilder
2021-12-2325066077492.xlsxls c94962da6d42ceec80299878801e7b5e130ee8012a381be58b0b70f9dfbe574dn/aHeodo
2021-12-235241927662.xlsxls d683342dd068bc9cf01c50ecf4dd73d5cf6dcf37ce304d87bb14923b3cc15e0bn/a Heodo
2021-12-2394293954.xlsxls 413f08bc8f3e7fa9208b0fb1ed939458fb85527b95056213db419fcc9b809808n/a Heodo
2021-12-232132367377.xlsxls 14865ea40a842988109d809dd63ab3bbc7a013242aa16735c2501aa23db43048n/a Heodo
2021-12-234412058470.xlsxls 2f217b230671809ceb34bdeaff122f8a8751eb223e14e309da0bb2bf6cb57ec9n/a SilentBuilder