URLhaus Database

You are currently viewing the URLhaus database entry for http://urgentsecuritygroup.co.uk/xjwn/wlaYOIv6K0I/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1964638
URL: http://urgentsecuritygroup.co.uk/xjwn/wlaYOIv6K0I/?i=1
URL Status:Offline
Host: urgentsecuritygroup.co.uk
Date added:2022-01-11 09:45:04 UTC
Last online:2022-01-12 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 09:46:07 UTC to abuse{at}hetzner[dot]com)
Takedown time:23 hours, 23 minutes Good (down since 2022-01-12 09:09:36 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12VVCQe-826.xlsmxls aa65a34067b0c50e89c1078d0c7ff08de43e5036241404574f846265de6ff6bdn/aHeodo
2022-01-12qdteomj-1968497.xlsmxls 58c5a48579e8499ec3aa409ee960a020592e422516e0aaa2847880ca43f84e90n/aSilentBuilder
2022-01-12AS-35.xlsmxls dd29267f0e261f6e92659d05355be93a6ab0c1e4a43501711cb9cb20d384f04dn/aSilentBuilder
2022-01-12G_742133.xlsmxls e32f0c4a46eb1839845394810bef1e5fa06054e8372e74ad442da3d8b5325475Virustotal results 28.33%SilentBuilder
2022-01-12pwmhl758.xlsmxls aa0e36780912b94ce9abefe196de12d6f4097dbc7fa864d24778638043de4084Virustotal results 30.00% SilentBuilder
2022-01-1200-59651.xlsmxls d7638004f7dc1a884abf073a6c04d5d205ba31f4d66800216ddc303dd3f41249Virustotal results 28.33%SilentBuilder
2022-01-12XWA_008.xlsmxls c468d97804e7a9fa569cfab4952c6fda72685adc622cec8aee02bb9c8f1a79aaVirustotal results 26.67% Heodo
2022-01-12R-0067.xlsmxls 813438ff7ef652ea23e922f8a5e61c7f14ec49b270546d3ce47f66161707cc03n/a SilentBuilder
2022-01-12vjwsbh_0283.xlsmxls ecaa8fa10f2e5726552f68f4c691133bb782d791b23c96e2c26b5c4838a00e68Virustotal results 28.33%SilentBuilder
2022-01-12NM_2347.xlsmxls 894ae1ab382fe85d09096d1997f468b8e5f327326c39e15bd1ba47f4c4d2f14fn/a Heodo
2022-01-12N_0550.xlsmxls fb59d08c1c00da6e08768d759d984922ef2726cade6ed27fe5713a79e7b7022eVirustotal results 23.33%SilentBuilder
2022-01-1249203DCWUTP-60.xlsmxls 1bd3d0d3bef771b182e3de5670d6f9515c73b76cf971203cccba88fb2dd3ddbbn/aSilentBuilder
2022-01-1171988-1.xlsmxls 4e4fed9bc0e99667d6959b4513a5c89a5f76f2437b19ae6b5b8c3ff15ba2b71cn/aSilentBuilder
2022-01-11B-604709.xlsmxls a7fe36211a0be63df4c3929830b8fc4e21fc0548b5446377ce9c83b3d1fd9339Virustotal results 20.00%SilentBuilder
2022-01-11L_6253.xlsmxls 207177c3c5eb0fe56e8614f9107063106f39167ae239ada435312ba0455fe349n/aSilentBuilder
2022-01-11689428_4.xlsmxls 9b3fb2f88edc75661d9aba9ccac4bd15607dbf2fa7542c47be3d533c0db5cbe5n/aSilentBuilder
2022-01-113404_513487936.xlsmxls 14222deeec10d32091a2947e045833bd25c041a662f4090df26e50381cf922c6n/a Heodo
2022-01-110860495338782216697A.xlsxls 7cdaadfceae5a41f40a2981e46f0c03a16496610c54c5a2adc39d51cbe56e535Virustotal results 13.56%SilentBuilder
2022-01-11I9573052373V.xlsxls 170593f29ae9e0eabaf7a2bea5add079c8cf136163cdbbbdc5e791a30006031dn/a Heodo
2022-01-11C433668805842229402589B.xlsxls fd9f32d79ea98273f97ea6c36042a4f43ee66720751a3e650eaa6f3f5e2dcbd1Virustotal results 13.33%SilentBuilder
2022-01-11902753825332Z.xlsxls 7eaad9ed201034aea3621c5ff8a3517046e4136ee73fce516b1bfcfbdd4fdea3n/a Heodo
2022-01-11I827834096941661Q.xlsxls 416e811b6839dbe39092f82dbb62064350da5400ce2e1fd94870f305f5b2b77dn/aSilentBuilder