URLhaus Database

You are currently viewing the URLhaus database entry for http://mmhminhaj.xyz/Fox-SS/1fBlJw/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1964841
URL: http://mmhminhaj.xyz/Fox-SS/1fBlJw/?i=1
URL Status:Offline
Host: mmhminhaj.xyz
Date added:2022-01-11 10:56:05 UTC
Last online:2022-01-11 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 10:57:07 UTC to abuse{at}ovh[dot]net)
Takedown time:4 hours, 50 minutes Good (down since 2022-01-11 15:47:10 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-11Y79830490111720026469H.xlsxls 3a3a5f5444557caa3c86b58560956c0a0452818a2349ef7328bb8c948e36d465n/a Heodo
2022-01-1131771316988.xlsxls d2c48bc93b2b0711be6bafd81a7eeddc944514e110ef2e1014151dac42e8ab62n/a SilentBuilder
2022-01-11M4205121655714146B.xlsxls 89224af568d4e29e7836c2961d33045490b337a9d5d40db852137e1f2dbbfbf9Virustotal results 12.50%SilentBuilder
2022-01-11771213528470132A.xlsxls 645258c3eec8a24b056403664b65d66c43f78566a0f33270723a6edc4d0c7ed8n/a SilentBuilder
2022-01-11Q983476934.xlsxls 06b383970ed4fab68a430bc021dd0744b77518ec82ef09f6d167c8edbf50fd53n/a SilentBuilder
2022-01-1126654939306758464845R.xlsxls 7550a2a99fe2768446351c653515cda693fc4978cdb437177efcc2133117efbcVirustotal results 16.67%SilentBuilder
2022-01-1199833939449.xlsxls c17cf152edefc6ce2ed0a5fa783f3bbfd6348b41a22f0da9cdd2722311ddfd62Virustotal results 13.33% Heodo
2022-01-11I79156508U.xlsxls 54517f5914c526589a1b1ad61249c75209d239c1885cd72f638d9924d53983den/aSilentBuilder
2022-01-112283404333441898.xlsxls f218c6867a0a060d313d1592c39f606f2193f4d587a404b4372971a6344d0f16Virustotal results 16.67% SilentBuilder
2022-01-11P136690777037881S.xlsxls c26e7bcb1137bc26303dc119131a3e3e229acc32c7ed38d1792aa7a620c7ae8aVirustotal results 16.67%SilentBuilder
2022-01-11Z91108396815675203922.xlsxls 5d5960ceec11681300fcf26d61f3e8c614aa21a0eeec555c70a63c4049587756Virustotal results 11.86% Heodo
2022-01-11R8852224870583272012.xlsxls 8154d03c9e2276ffa60e6a0cff77239d34b2be27f0728bfbec2a37e59562551fn/a Heodo
2022-01-11P446095341261656.xlsxls 014fc0f35570524af821c5eba7c6efd66e8b973be290e6aefcc2b4ba1d56870an/a SilentBuilder
2022-01-11M66296781194177G.xlsxls 8d553f79df6c325e23d3dbf5395971d1e0e1132eb66d882f365a931e848a6556n/aSilentBuilder