URLhaus Database

You are currently viewing the URLhaus database entry for https://foryou22.xyz/wp-includes/R83mgKWecvfYBiJhRJ/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1964810
URL: https://foryou22.xyz/wp-includes/R83mgKWecvfYBiJhRJ/?i=1
URL Status:Offline
Host: foryou22.xyz
Date added:2022-01-11 10:44:04 UTC
Last online:2022-01-13 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 10:45:07 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 6 hours, 43 minutes Poor (down since 2022-01-13 17:28:53 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-125250-70408868.xlsmxls aa65a34067b0c50e89c1078d0c7ff08de43e5036241404574f846265de6ff6bdVirustotal results 28.33%Heodo
2022-01-12083302459_879.xlsmxls 1e8ed8d61ad3f66e9acac149db12bf6f3db13cef81cbedc8bf9602c391450c43Virustotal results 29.31%SilentBuilder
2022-01-12OO_809595.xlsmxls 788c6ae40bf00e27769846c7ab03bfee240d5ee52f765f498918a0333498eb82n/a SilentBuilder
2022-01-1218318835-33130101.xlsmxls 48d83d3b6c7ddfcbf30ed8ebe2feb9bc8b5c97dbec16fdbbec64d120181f94a3n/a SilentBuilder
2022-01-121674_50192513.xlsmxls 3f4b1c98cb91608ce0ef51a77efb1ba624e38ff17e01567f9d61747a5e49421dVirustotal results 26.67%Heodo
2022-01-1256341890434.xlsmxls 046d125d4eaf4ae30ad4a794405fd7c905b58db18824dfbe24dff1cd4cfd13b6Virustotal results 30.51% SilentBuilder
2022-01-12MT18379.xlsmxls 769ecd4d91e53cc734ede1b06a3935096e838020e44061032964dd769dda3968Virustotal results 28.81%SilentBuilder
2022-01-12957344011.xlsmxls 8642a84875b30eeae2bec0b16db37715f4a2ff15caf6e5185a4012107ec1e87bn/aSilentBuilder
2022-01-1224028.xlsmxls 926c822e2c4d78b252f788d3fa75a77bfed1380ad50cdacf21f3efddf15b0b26Virustotal results 26.67%SilentBuilder
2022-01-12Xf3685.xlsmxls 1b7581c8be4bf9197005067c42e581bcc1c41b10d6d9768daa8c4642f6e3ef7bn/a SilentBuilder
2022-01-12slrpcq-1795614.xlsmxls f9cbf3cdfa7ed91bca677fd8d8e1f0f53c193323abfbbb1ce4d7c6d2f1b9feeaVirustotal results 25.00% SilentBuilder
2022-01-1267847_181335.xlsmxls 05dc48ca9e5d5feb04a32c1ef3a8d18453a2a679e7257ce24856895a5dea268bn/aSilentBuilder
2022-01-110068807_18.xlsmxls 66f5d61a2c4246c3bc39141c46e41bdc84c3f12a7db0b2ec3090eace070392d6n/a SilentBuilder
2022-01-11197606511-20534760.xlsmxls bfe1c65501eb9a22ea914fe380d24127cdf99ce17fc20683f99a7b1e0ccc06f8Virustotal results 18.33%SilentBuilder
2022-01-11T_70967023.xlsmxls a7fe36211a0be63df4c3929830b8fc4e21fc0548b5446377ce9c83b3d1fd9339Virustotal results 20.00%SilentBuilder
2022-01-1124-75.xlsmxls f326b9b9af87bd43878455ac75b4e61fadd71bdfcebf5b4508525cbbb4e8038bVirustotal results 16.95% Heodo
2022-01-1192_9807.xlsmxls 4732ca576ac4a1b57726b01684356326dabe72f56f1f90308801953e421ce1dfVirustotal results 18.64% Heodo
2022-01-1158842679088055.xlsxls e7065618e785e98792d570656fd412ecf695c45ec5a8123d04cf4ee302d225bfVirustotal results 18.64%SilentBuilder
2022-01-11N757143626982441562.xlsxls 73a93604b31a5b4b301dad4849b63d5e6e48ef8d946f6fbff48b485b1bce7a37n/a Heodo
2022-01-11T3285897239136B.xlsxls 47d359db574e7e651cbf4e0b4d24fe1a2eb3f7b0e3170dbd84c2caae8c0d0a2an/a SilentBuilder
2022-01-11P44719080844659.xlsxls 416e811b6839dbe39092f82dbb62064350da5400ce2e1fd94870f305f5b2b77dVirustotal results 16.95%SilentBuilder
2022-01-11S3076581171561C.xlsxls dd5655dd2bb0e1d2dec7b8b92b7795dd64bae918b46c32fa5144129822729d56n/a SilentBuilder
2022-01-11126860764.xlsxls 3f4ddde39dc20ae5a2558fe48b7341187c1bba0dbd1c95a32644b14592a38653n/a SilentBuilder
2022-01-11700908297212057612054U.xlsxls 3d2ad015f60956cee32029cb7d6fee846f34a91d0f6dae2b68cfde31c99b4a77n/aHeodo
2022-01-115336215282681959953F.xlsxls e9a7a09bdacc562bedc71638c17bacb72b445281366d192033d7c8c85f83ce7fVirustotal results 20.00% SilentBuilder
2022-01-11664799887185821382U.xlsxls 18e24e9b03fde05fa41b9d86aa612dbbd5deabcebbe97ee5b3a3b7fa8fb43f51n/aSilentBuilder
2022-01-11A306957396246727902683.xlsxls 60fdf680c8e0272784588bf87ead2814df683a2fcb697522ddd4ef323166440aVirustotal results 15.52% SilentBuilder
2022-01-11925509738784.xlsxls 6808535f95480e34f3c2c575420e072a74fa57f20d5c69a99b7bc614f19d7b1an/a SilentBuilder
2022-01-11J53486872481469317Y.xlsxls 26356d230c56228215ac800ef5e4b0341a653d88d8ebb1c162ccd53a51a94c35n/a SilentBuilder
2022-01-11A9934406.xlsxls 0237b96acc934eba1b920d0b6fa654c22128101417298a9f940ca2e53c85dab9Virustotal results 15.52%Heodo
2022-01-11597127552208395.xlsxls b68760371e947df68d4f69a1f9b43a56de082932df771b0ef088adaae130931cn/a SilentBuilder
2022-01-11C5931518909769278.xlsxls 7955874a069fbde3eb5144ea8420f8b9e80d0c8ccd822c21b54150e53608116cn/aSilentBuilder
2022-01-116155801P.xlsxls 7dcde20dd26c5388d734d658830ebb48bf5c1170cf9ec39a3e084d8e728715e8Virustotal results 16.67%Heodo
2022-01-1167480132263003D.xlsxls 445e137304a2c43b06f0c98f4655f6fc4d69db7ae73ddf9094295c48f0701047n/a SilentBuilder
2022-01-110459407434260079X.xlsxls 0a0fe064ed83d5fb4be5577a78d4659be6d7fec5ee345f01edda10c2e6221868n/aHeodo
2022-01-11A15255384654437936690.xlsxls 3dbfb9a583de71af6ce19cbfb294476ab7d6fcfd2fe42c9bf38886ace35c58fbn/aSilentBuilder
2022-01-11G579663133693200971321.xlsxls 12db004e136ba9f8fd95d9d6e3a08d5b3cfde159c0ca3f99a75df8922fbdcd85n/a SilentBuilder
2022-01-11P42806481009964085H.xlsxls a7635ff25c0d0846f9f7aeadba12afdfae8f6efcec04fdfe2b7fecf6610dcbe3n/a SilentBuilder
2022-01-11A339825294668743819E.xlsxls cab722a553d0e662a2c4e18e2300d30338fa957f7b0ade2c8f4450bd375bb8f9Virustotal results 16.67%SilentBuilder
2022-01-111827172924621H.xlsxls 5471bc0d0b81c3ee5e169546f5eb63613253af486bc28e14da70e43ba2acbdf7n/aSilentBuilder
2022-01-11248012190779602C.xlsxls 52db13aa7bc2edb863fa5408d28bd9929e8bce4c5c4bef4e71395a4679083396n/a Heodo
2022-01-1154666401K.xlsxls a8085602b4f2d9fa12e7cdc848185b57baef023cbe353df862fac4ff279cf3f4n/aSilentBuilder
2022-01-1138777878873249D.xlsxls 03c7dce022ba5927f0047e1ff4eae1b193016b57a701ea176975290263d7893fn/a SilentBuilder
2022-01-11J177657890666754111560V.xlsxls 14242004bc97b6ca2b2b40e09b270a056e3d87aa4b37251f79709b26eeec3a5cVirustotal results 13.33%SilentBuilder
2022-01-11L21829358658.xlsxls d78c9ad266c4e93e0c97fe9cc3bd593afa995a93f59aba16c1bb63c421d6a9dcn/a SilentBuilder
2022-01-118472723249255415.xlsxls a2e296ce454120b7c7bd67add90fc0de4f7c805c6fd66471a1ef2ce19a7de34eVirustotal results 15.00% SilentBuilder
2022-01-118383188791490873.xlsxls 7398cc356f34763ebb74209f98d07a50292965967c7650dad6f061987df0494dn/a SilentBuilder
2022-01-1128353008531538S.xlsxls 456900ec830e21c666d5781482e05a30af7337d1db2a51d26a2351981860640bn/a Heodo
2022-01-1156610729834965521J.xlsxls 4610c672d0f3d33869cee18140e01de3ec4aaf900143743f378f05697b08ea4cn/a Heodo