URLhaus Database

You are currently viewing the URLhaus database entry for https://vis-hosting.com/wp-content/R8SXPkjsccTiW2VABllTgZbU4CsgKt6NU7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1919425
URL: https://vis-hosting.com/wp-content/R8SXPkjsccTiW2VABllTgZbU4CsgKt6NU7/
URL Status:Offline
Host: vis-hosting.com
Date added:2021-12-25 07:34:11 UTC
Last online:2021-12-27 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2021-12-25 07:37:14 UTC to abuse{at}ovh[dot]net)
Takedown time:2 days, 10 hours, 3 minutes Poor (down since 2021-12-27 17:40:29 UTC)
Tags:emotet link heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-2541996634788701588.xlsxls ad703c5d173ecc9110d797f3272128d0bd21745acd34d207171021b8f448c5b3n/aHeodo
2021-12-25924991152336363733Q.xlsxls 37029ffaf8784e69ca60e4f34de09623001928c7a7c24e74abe50d5c173da19cVirustotal results 33.90%SilentBuilder
2021-12-258908162819T.xlsxls 93d6ad0b07634345ee9040ca50a7d51c88b2224b8c54481c6378f071479b3fban/a Heodo
2021-12-25M11774558.xlsxls 571372df136c9cfe23cbac165d75e33914ebe3e123c8ee043a56298664002becVirustotal results 27.59% Heodo
2021-12-25P5648563857189886.xlsxls 42815476b642f6a506a48fd364997c7f9cf5d339354767879827196c7cfa5480n/a Heodo
2021-12-2549959124314946I.xlsxls 0e0e7dde98ca923fa945a37f6f8e8059720302df5a7d464138e3d221a1861ff6n/a SilentBuilder
2021-12-25D516327868.xlsxls dd9aeb4e572685c0730d665190460d3f314a19558f77c77687d47204b5966c1bn/a Heodo
2021-12-2519265857286X.xlsxls b065259b68e96859cdcbb55267d6c383f3c2e8d402bec89dbde0140297f0ca9dn/a Heodo
2021-12-25W5576757068272.xlsxls acdf5002ec4be1d844d1d4dbfc55f317f00bddf3f5e1be17a1ff9467fe0368acn/a Heodo
2021-12-25054476004058936954B.xlsxls bd47d239b29d4672ce03908c935d65dd98b77db7c23343a2c2f670eab11e246dn/a Heodo
2021-12-254884350131027673S.xlsxls df7cb4340e87a513ca0d9742b637e094703ced5b4fdf66c1eb55592e4bc5c617n/a Heodo
2021-12-25Y830267728D.xlsxls 34290b3ae2a956806dc148aece513c9725dee43e505a78c16258027559f730b8n/a Heodo
2021-12-251094217594.xlsxls 9d3fc55458fe4118f1acf576a461faba5cba032a2bb068cd241f3b48a3b61656n/a Heodo
2021-12-25460129410586580.xlsxls 7bb635fcdfadb359327d24ba86ad671f7494223586d290228b98ec4d77cafb52n/a Heodo
2021-12-25K28524172R.xlsxls e3be210f600b2f8de1eecf292968405c32eb342697ebd82797347cbea77ec6efn/a Heodo
2021-12-25X8742366442516901931.xlsxls 97754addc84b76136532f1b1a912ac9ae8f7fb55cbefd084ad7fcf927c220bdan/a Heodo
2021-12-25610249656790949022601.xlsxls 2249bc9f16d4188ad33c16bcc91ed318c0c900019a45105f24b9e9a31b289d11n/a Heodo
2021-12-25W89898422581245827259Z.xlsxls 77cf805aedd3258b70f68ecf0ab5dfce204286144a08b17cc55eb0970efabe92n/a Heodo
2021-12-25S111680157724712388433R.xlsxls 6e08b026585827318e5e1de06e2dd2842fdce30cccb981ee85582e91f093e943n/a Heodo
2021-12-2528524770596W.xlsxls 170efb5d02f483bc5cc17668a2e149137cf12a4b560fc9478adcfb4815de1cf1n/a Heodo
2021-12-25Q65027101774A.xlsxls 0014d33e8c71e69c819ad117c82bd13a3eeda011d9323f365e070af2bd9a1ba4n/a Heodo
2021-12-25Y831039750855400549.xlsxls 432a4593dac9c98c78cbeb5bde56c00acb1999fb4520341244c4c9dcd2e59387n/a Heodo
2021-12-25Q379518058559288603.xlsxls 978a5693d26206af73d37fe9c4ed60c4b45462afa41057e18dbe3525830f6864n/a Heodo
2021-12-25V06555416080811152785Q.xlsxls 767312b89f882c00b45884b8901831ec45fdb8c03d73d9be10ce4f6aa2a764d8n/a Heodo
2021-12-25M53073726421027.xlsxls 5c64f527a54e4258592c66c4b6aaba8f428cda106fd2c179b4f480b73cc5a858n/a Heodo
2021-12-25S83284356S.xlsxls 203642f63c7b2d39cc134797070a502a04d76aae58d190c9c6b5437e15774172n/a SilentBuilder