URLhaus Database

You are currently viewing the URLhaus database entry for https://erizo.webarrive.com/cgi-bin/pIbTx7kT7iuoZup/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1916008
URL: https://erizo.webarrive.com/cgi-bin/pIbTx7kT7iuoZup/
URL Status:Offline
Host: erizo.webarrive.com
Date added:2021-12-24 03:55:11 UTC
Last online:2022-01-11 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2021-12-24 03:57:57 UTC to abuse{at}1and1[dot]com)
Takedown time:18 days, 1 hours, 21 minutes Bad (down since 2022-01-11 05:19:00 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-03Y5243444417496594674.xlsxls f9ebb3b7f652ca818c4394874d8bab531f34bb748fe010497e53c79f62962bd5Virustotal results 45.76% Heodo
2021-12-24B685075834319039.xlsxls 9afe0d18d810c8fbaa22348768bfe239fdac878416074fc9620d87183fa7efe5n/a Heodo
2021-12-24I46136939.xlsxls dfd7779828492c51dbf83bfe709e2b29ae854940801beea6a77ad5734a9bd1eeVirustotal results 11.86% Heodo
2021-12-24M46272618.xlsxls e754117820a70be1a00013810fa78c756fe289c50291ff1458133281383174a6n/a Heodo
2021-12-24V502557125840139475.xlsxls 6d649fd080ae3dfb67788bdc4efa4229c0e9b1e7e41fefc1a8847fedf2a696e2n/a Heodo
2021-12-24N441369320494.xlsxls 581c75719d64705c1e00f73d4b5d5b66dae6d2d5b0e706a869171428d38dcd9en/a Heodo
2021-12-24Q14404624990530613767.xlsxls 0025281e2d7b2e9dcae35af0057d43c7df04c734f2c3dcb25d9ea15702ec89f2n/a SilentBuilder
2021-12-24N93360415673355962568.xlsxls c9490df1109506f3d5e3abbf07bd321a5ab8ffe37ce04cc05930412bf539337fn/a SilentBuilder
2021-12-24R96288604781242.xlsxls 44f64a39ae4ada2c738b6193b6d59084a99e57475e0c6902ff370f21b4cbc984n/a Heodo
2021-12-24D935637577687530.xlsxls dbb59e212807591e49b982a7c52e78c6b4ad1656c660bde5816e124b39e51734n/a SilentBuilder
2021-12-24U268554925.xlsxls 3c8d49a046157a3efca16ecd5e1786f4e1a169c2937572c322165f0048c34ed8n/aHeodo
2021-12-24N521451394254698282752.xlsxls 5dd5d028f230eebf3fce6cc37b76fd84532db7511e0567336b92bc563a5370can/a Heodo
2021-12-24Q132392953.xlsxls 0413d6940fddbdff88dba28ef5dc49dfac3e6cdad305279dbb33b0c21346f692Virustotal results 18.33% Heodo
2021-12-24C9495621.xlsxls a84e754252e4a6e668881039eecad1adcb502f398d91a36ed0c2eaa6ba808a3fVirustotal results 23.73%Heodo
2021-12-24I00334194663853036608.xlsxls 937c9d543a0c229736fb7fae77224fede4b05c74042ffdf3ac7f8224b5f1a236Virustotal results 26.67% Heodo
2021-12-24F7039354273712179.xlsxls b162f10f8147c6dfe4d058b3b753572f71897b6df59a67216468d0754e54891dn/aHeodo