URLhaus Database

You are currently viewing the URLhaus database entry for https://vlogingcamerareview.xyz/wp-includes/css/0aW/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1964782
URL: https://vlogingcamerareview.xyz/wp-includes/css/0aW/?i=1
URL Status:Offline
Host: vlogingcamerareview.xyz
Date added:2022-01-11 10:35:06 UTC
Last online:2022-01-13 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 10:36:13 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 6 hours, 49 minutes Poor (down since 2022-01-13 17:25:30 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12XBIC_779.xlsmxls aa65a34067b0c50e89c1078d0c7ff08de43e5036241404574f846265de6ff6bdVirustotal results 28.33%Heodo
2022-01-1208178_887615.xlsmxls ab506a8e25b64558a0069af7f78035c4ae3848d8873a5ddd3542d01d2e195565Virustotal results 29.31%Heodo
2022-01-12210813912-35.xlsmxls e58cd1fc646d37b9fd8040d9f7f4110bb07cbdadb1f5dd4a55413acacd33807dVirustotal results 30.00%SilentBuilder
2022-01-124839OBGBULQ171459.xlsmxls 48d83d3b6c7ddfcbf30ed8ebe2feb9bc8b5c97dbec16fdbbec64d120181f94a3n/a SilentBuilder
2022-01-12866139-6046030.xlsmxls 3f4b1c98cb91608ce0ef51a77efb1ba624e38ff17e01567f9d61747a5e49421dVirustotal results 26.67%Heodo
2022-01-12BUU941393.xlsmxls d7638004f7dc1a884abf073a6c04d5d205ba31f4d66800216ddc303dd3f41249Virustotal results 28.33%SilentBuilder
2022-01-12TQMWG-649820.xlsmxls 769ecd4d91e53cc734ede1b06a3935096e838020e44061032964dd769dda3968Virustotal results 28.81%SilentBuilder
2022-01-1211966653_73490540.xlsmxls 8642a84875b30eeae2bec0b16db37715f4a2ff15caf6e5185a4012107ec1e87bn/aSilentBuilder
2022-01-12LYJ-27.xlsmxls 926c822e2c4d78b252f788d3fa75a77bfed1380ad50cdacf21f3efddf15b0b26n/aSilentBuilder
2022-01-1244178838.xlsmxls 9d277bf6e9b937c6b9d79db16b78f65ef5346b79c5c68fd3fda71a4e18171fe7n/a SilentBuilder
2022-01-12CX2501271.xlsmxls f9cbf3cdfa7ed91bca677fd8d8e1f0f53c193323abfbbb1ce4d7c6d2f1b9feean/a SilentBuilder
2022-01-12490_22519.xlsmxls 05dc48ca9e5d5feb04a32c1ef3a8d18453a2a679e7257ce24856895a5dea268bn/aSilentBuilder
2022-01-11185_859.xlsmxls 66f5d61a2c4246c3bc39141c46e41bdc84c3f12a7db0b2ec3090eace070392d6Virustotal results 23.73% SilentBuilder
2022-01-1192LJYPTXVZN-01676.xlsmxls bfe1c65501eb9a22ea914fe380d24127cdf99ce17fc20683f99a7b1e0ccc06f8n/aSilentBuilder
2022-01-11214671094_52450493.xlsmxls a7fe36211a0be63df4c3929830b8fc4e21fc0548b5446377ce9c83b3d1fd9339Virustotal results 20.00%SilentBuilder
2022-01-1197_069202479.xlsmxls 0174c6534f42113ca8854a6ae91e267fb1915bb32b5760b52bbb551aa1580da2n/a Heodo
2022-01-111420-8979.xlsmxls 4732ca576ac4a1b57726b01684356326dabe72f56f1f90308801953e421ce1dfVirustotal results 18.64% Heodo
2022-01-11P03580517388961U.xlsmxls 22a6627b4fdbfe7fd3bf73f4dbed682b4b450d18908aea0b23642c11996e75ccn/a Heodo
2022-01-11Z2196112391835.xlsxls 73a93604b31a5b4b301dad4849b63d5e6e48ef8d946f6fbff48b485b1bce7a37n/a Heodo
2022-01-119308900848829F.xlsxls 47d359db574e7e651cbf4e0b4d24fe1a2eb3f7b0e3170dbd84c2caae8c0d0a2aVirustotal results 16.95% SilentBuilder
2022-01-11T10418603N.xlsxls 2057afa974ff72e5f28439f4cdef17396772fe0edde04405fbcf8c5cb5a47888n/a Heodo
2022-01-11M3290716755T.xlsxls dd5655dd2bb0e1d2dec7b8b92b7795dd64bae918b46c32fa5144129822729d56n/a SilentBuilder
2022-01-1163601715025.xlsxls 3f4ddde39dc20ae5a2558fe48b7341187c1bba0dbd1c95a32644b14592a38653n/a SilentBuilder
2022-01-11W1295086507926448M.xlsxls 3d2ad015f60956cee32029cb7d6fee846f34a91d0f6dae2b68cfde31c99b4a77n/aHeodo
2022-01-11B338055853490.xlsxls afe04f54612c86612a56bf8a3a228a2aeae275f4730552228f8a4bb6f71c292en/aSilentBuilder
2022-01-1102034445473095302061G.xlsxls fbc4a5db3ab48741c10a226dae4e2b64d924110962224bef57910478251cf3c7n/aSilentBuilder
2022-01-11127542826042268553626.xlsxls 60fdf680c8e0272784588bf87ead2814df683a2fcb697522ddd4ef323166440an/a SilentBuilder
2022-01-11U9599988805H.xlsxls f9dc6d359581da286cc014340d248cea2acedf09a9dc0cf9280641f3393fba35n/aSilentBuilder
2022-01-114494955217685.xlsxls 26356d230c56228215ac800ef5e4b0341a653d88d8ebb1c162ccd53a51a94c35n/a SilentBuilder
2022-01-11D30507600.xlsxls e99c27037595f4931d753f7e372cbad60953e56c327d9ea2a2c3042db0f5f4e4Virustotal results 18.64%SilentBuilder
2022-01-119369670782442.xlsxls c5850b16a368ab7c8f2d03cebcc7dd51173a704cdd1d6c105ba43083a40b6063n/aSilentBuilder
2022-01-1149750556247468J.xlsxls 1cdf6133fd1d4138849b8f2b29f199d90ccce54c369b74a88a14e8329e1051c3n/aHeodo
2022-01-11Y54381819379C.xlsxls b4f4e361680cbe98e26106393beca73acc80418fdae4ab118917b7e8bd9fc917n/a Heodo
2022-01-115090314Q.xlsxls 2b6937e90b3f57eb3f26b8a3f50b86def03b2d4b3bc30d93e1af1c96656bb4dan/aHeodo
2022-01-110350947134Q.xlsxls 17832170dc965d40f1a4b7b5abf6dd5f8d131468c82c281388bf6f6967b77490n/aSilentBuilder
2022-01-11037832260284394012.xlsxls b53a3f09073ba4c63f1634b32bc6328f22d9965ebc1384797a886d07959313fan/aSilentBuilder
2022-01-113672810106777.xlsxls 045946e253af3bae2e2ae5be021b6a2032c8fd4df027ced949a3a9a09310928fVirustotal results 13.33% Heodo
2022-01-11550294265965S.xlsxls 7c1004454dd200c8e01f09e796c996a70ee951164ec546ae10634a41c1eb4d22Virustotal results 13.33%SilentBuilder
2022-01-1101161922T.xlsxls 06b383970ed4fab68a430bc021dd0744b77518ec82ef09f6d167c8edbf50fd53n/a SilentBuilder
2022-01-11R18393365594449185.xlsxls a672f734a98a5b287eb96d134893701f055f20573dd9f9d778b1e7953b00a944n/aSilentBuilder
2022-01-11094314869257183380727Y.xlsxls ffd39f522cb9bcdb3dac93c34aa136be3cdc6cc6f6b878cf756a5a53443546fen/a Heodo
2022-01-1157764470275164809101.xlsxls 6b28b200163448c423b79b68a70f8d07d925445d48edb48526d9dfdbf68d47c1n/aSilentBuilder
2022-01-11R8795491661199999261.xlsxls f218c6867a0a060d313d1592c39f606f2193f4d587a404b4372971a6344d0f16Virustotal results 16.67% SilentBuilder
2022-01-11411876578136421215.xlsxls 25a3e55a8c505687b78fb62ff041db36ed577b17dbd1b9ebf4e8628b9cf7b18en/a SilentBuilder
2022-01-1166230701941995.xlsxls 244e38598a1d03f533889b35b310f7e2a83cbf5b57b93c116b57a73482176a22n/a SilentBuilder
2022-01-11X6129290383763249A.xlsxls e16adb6f1a775a983cf7e36a35ac0200ae5fa21bbb48325bf9af0e86d7b96be9n/a Heodo
2022-01-11W5822690V.xlsxls 803ba1efe4554351d3b7b7768773cdc8c3e3fd66286c993520c86cea7a4fe01en/a SilentBuilder
2022-01-11A8609679626376Y.xlsxls fc53b9dd37388b4869d1405aabf048daff959a1b37f15dd6919e8f513591d922n/a Heodo
2022-01-11290111386059158457920K.xlsxls 170593f29ae9e0eabaf7a2bea5add079c8cf136163cdbbbdc5e791a30006031dn/a Heodo