URLhaus Database

You are currently viewing the URLhaus database entry for https://dentalinstruments.webarrive.com/cgi-bin/AtIPjgqGBr9ueSL2k1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1915439
URL: https://dentalinstruments.webarrive.com/cgi-bin/AtIPjgqGBr9ueSL2k1/
URL Status:Offline
Host: dentalinstruments.webarrive.com
Date added:2021-12-23 23:34:09 UTC
Last online:2021-12-24 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2021-12-24 03:57:57 UTC to abuse{at}1and1[dot]com)
Takedown time:17 days, 10 hours, 1 minutes Bad (down since 2022-01-10 09:22:09 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-03N39146115572239784991.xlsxls 7021bf769c34b61609893087696b1b3cee41e5408c601f997434868ea6b79b18Virustotal results 48.28% Heodo
2021-12-24N136255107.xlsxls 06dc6b5144f2cef6252ac56e82e3e9ca5ffc30d613192797754afc34f9a6f064n/a Heodo
2021-12-24I1102805.xlsxls 28c3e4ea4a9a851789cc708abc3603a5bf9918d6e2f9c09c07c265616c615122n/a Heodo
2021-12-24B44976629987.xlsxls 00a0231a0404a3d34c4e1ac3b596de550e696cccae94c7d26fcb9b997eedfe6dn/a Heodo
2021-12-24Z825931073235177413276.xlsxls 4bc6426e9b3e82b0f2a8472b28dd62d91af6800f6bf24bfa295d2ed71085514fn/a Heodo
2021-12-24J7490517989883260616.xlsxls 88c5d701915407e6b24d8e53e41b428e1bbb0aa2d884fcf827ae1cac5e5a5754n/a Heodo
2021-12-24X0999098474751162248.xlsxls 3f57072db1305df792976a963481eb602e50d59352e7f047036f52f8fbe2c0dcn/a Heodo
2021-12-24N612162411641.xlsxls 5c4bed08cf0d978f804e68979b291f17925d691b3c355a44fb69994b49f82a63n/a Heodo
2021-12-24D942653655818.xlsxls b1d873c780abcbba6b60f6bf4cd133b87f96d114e234e10d459916fa56dbbedan/a Heodo
2021-12-24R55094680673.xlsxls 44f64a39ae4ada2c738b6193b6d59084a99e57475e0c6902ff370f21b4cbc984n/a Heodo
2021-12-24M304695702238057079.xlsxls 1877211be5c8aab1a2548c48de3e59ae0c82e2519d6cf0e867b1c96ae170dea7n/a Heodo
2021-12-24C903129515410109.xlsxls 0413d6940fddbdff88dba28ef5dc49dfac3e6cdad305279dbb33b0c21346f692Virustotal results 18.33% Heodo
2021-12-24C40361284217551396746.xlsxls a84e754252e4a6e668881039eecad1adcb502f398d91a36ed0c2eaa6ba808a3fVirustotal results 23.73%Heodo
2021-12-24V75879462666735.xlsxls 4dc9d24fff7faa3e0e09d10a9dbdbc88a9899281fc1aca774fb83cae789b3636n/a Heodo
2021-12-24R53975845419526149319.xlsxls b162f10f8147c6dfe4d058b3b753572f71897b6df59a67216468d0754e54891dn/aHeodo
2021-12-24V1260605895381.xlsxls c3098005faa23973cedc16ee25aaff04634d6b211d93c4e21c56103be71bf63en/aSilentBuilder
2021-12-24B6300555273100356.xlsxls dca58e5ce77ad26c0176379b00930639237457987584d5a3fb4a55c282a887a4n/a Heodo
2021-12-24F3794462188236293.xlsxls 3fcc643de96cc8f42515929e84f68cfb36f28537b37a1fa152bab2898d161a0fn/aHeodo
2021-12-24V384354193217094341335.xlsxls 7bce37caacbfe25d1ba03da401bd65e492e9768ff8fc861a397a39559f358562n/a Heodo
2021-12-24L415943892303.xlsxls bb274620d0053935159c24bf4b4a2e4a9b951f88ef5d373fe6b19871ac86221cn/a Heodo
2021-12-24W093330239655938.xlsxls e478bf06425093646e5874168e6225479faf3454f86c6a498417d35a72a32369n/a Heodo
2021-12-24I329907782830080840.xlsxls 33a09ba2d556496351897d49c9be8fa91fd79633b3f97d7ba3fa28e6b616cd82n/a Heodo
2021-12-24Z7223138696401.xlsxls 07391062a0f4ebb801cfe12d5200067df6734aa5aa811d1eda66209522c1cb29n/a Heodo
2021-12-24Q90207420808301829.xlsxls caacd61c13d59a29eaafe6c68a3cb369cf1d56956b654b7d8750395dfc21e5a9n/a SilentBuilder
2021-12-24E05696046465026081846.xlsxls 1021e737ea0b00ec78ed49efc4e8b58fbbd66a68d67c889f0992c4b13250ae0an/a Heodo
2021-12-24D087288352928667013.xlsxls 7859496c99048f59656e296bed199b8e52ff3d9d5cee44a2794e52858caf19d4n/a Heodo
2021-12-24L804786362282739588891.xlsxls 287a7ef27eed8371f56478d165928ae0ea26a650a32d3d461220b20dc696a43fn/a Heodo
2021-12-23T5449989453.xlsxls b2af5bbfd6076126cdf53ebd3d6a7f2ab27479ff5157a841a6a41bda99aec50fn/a Heodo
2021-12-23L3912846994545.xlsxls d5331f0c434a89782a897b2bd88b87f3dfa377564cd387bd5d5afe0cbea9831dn/a Heodo
2021-12-23E1659756255859350.xlsxls 628a776b5829225e5319136b0e13ea89227f738a2380117ad1a2dc58657d168an/a Heodo
2021-12-23S34918410191518029.xlsxls 5bb626d65f16f3befd6929af097b9f8513a435662959c67645414a795777208an/aSilentBuilder