URLhaus Database

You are currently viewing the URLhaus database entry for http://www.glendbank.com/wp-admin/PLzGxmErGttll0s/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1965312
URL: http://www.glendbank.com/wp-admin/PLzGxmErGttll0s/?i=1
URL Status:Offline
Host: www.glendbank.com
Date added:2022-01-11 11:08:12 UTC
Last online:2022-01-24 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 11:09:07 UTC to abuse{at}24shells[dot]net)
Takedown time:13 days, 0 hours, 5 minutes Bad (down since 2022-01-24 11:14:51 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12PN_18.xlsmxls aa65a34067b0c50e89c1078d0c7ff08de43e5036241404574f846265de6ff6bdVirustotal results 28.33%Heodo
2022-01-12IDNog1233.xlsmxls 66f5a05e98200743eb34cad5877b89dd359fbc2c8f4ced8da536851e0ac44689Virustotal results 28.33%SilentBuilder
2022-01-12365947_29740521.xlsmxls 228b8793653662088991f7cfa3b368bce32931a7516a2f8c7188a437eb03a856Virustotal results 29.31%SilentBuilder
2022-01-1294385.xlsmxls 48d83d3b6c7ddfcbf30ed8ebe2feb9bc8b5c97dbec16fdbbec64d120181f94a3n/a SilentBuilder
2022-01-12039592_74715844.xlsmxls aa0e36780912b94ce9abefe196de12d6f4097dbc7fa864d24778638043de4084n/a SilentBuilder
2022-01-12997851_39.xlsmxls 046d125d4eaf4ae30ad4a794405fd7c905b58db18824dfbe24dff1cd4cfd13b6n/a SilentBuilder
2022-01-12BJFC3.xlsmxls c468d97804e7a9fa569cfab4952c6fda72685adc622cec8aee02bb9c8f1a79aan/a Heodo
2022-01-120035_93578.xlsmxls 8642a84875b30eeae2bec0b16db37715f4a2ff15caf6e5185a4012107ec1e87bn/aSilentBuilder
2022-01-12hy-07819909.xlsmxls 926c822e2c4d78b252f788d3fa75a77bfed1380ad50cdacf21f3efddf15b0b26n/aSilentBuilder
2022-01-1283077RIZL-971441.xlsmxls 1b7581c8be4bf9197005067c42e581bcc1c41b10d6d9768daa8c4642f6e3ef7bn/a SilentBuilder
2022-01-1297890-70.xlsmxls 9e0c891bd4b687d10b5c7d8082a2d4c7d24a0c9ea90b1d0aa09dafa6dee22047Virustotal results 23.33%SilentBuilder
2022-01-1234852213_1.xlsmxls 05dc48ca9e5d5feb04a32c1ef3a8d18453a2a679e7257ce24856895a5dea268bn/aSilentBuilder
2022-01-11n_2.xlsmxls 66f5d61a2c4246c3bc39141c46e41bdc84c3f12a7db0b2ec3090eace070392d6Virustotal results 22.03% SilentBuilder
2022-01-11D_1636887.xlsmxls bfe1c65501eb9a22ea914fe380d24127cdf99ce17fc20683f99a7b1e0ccc06f8Virustotal results 18.33%SilentBuilder
2022-01-11hmd_209136.xlsmxls 207177c3c5eb0fe56e8614f9107063106f39167ae239ada435312ba0455fe349n/aSilentBuilder
2022-01-11fqyrqj-82.xlsmxls 9b3fb2f88edc75661d9aba9ccac4bd15607dbf2fa7542c47be3d533c0db5cbe5n/aSilentBuilder
2022-01-11DVI670516005.xlsmxls f062c2a1622bb6bbddf6250cae210e3c341320104c09b649e9748bb7ad87c232Virustotal results 18.33% SilentBuilder
2022-01-11J7621282644B.xlsxls 4c7d6ecc64662c61351cf50dafc4647c4d5f39b8efb3b097e5c1ab937e120c37n/a SilentBuilder
2022-01-11D171381027277096U.xlsxls c630d761d951cbb2a45247adbe0361f1311dbc9c9dd2e90447ef752f3927a4fcVirustotal results 16.67% Heodo
2022-01-119670794707657943243B.xlsxls 2057afa974ff72e5f28439f4cdef17396772fe0edde04405fbcf8c5cb5a47888n/a Heodo
2022-01-113167693746623495471.xlsxls dd5655dd2bb0e1d2dec7b8b92b7795dd64bae918b46c32fa5144129822729d56n/a SilentBuilder
2022-01-113476333127868466240S.xlsxls 067076b82d8006677b674411e2ac9d00f6b68e93ff460cb2f113d9150e73a88cn/a SilentBuilder
2022-01-11A9053634453418.xlsxls 24160ff88a8c4ee8d12c4cad09dbd7e744c2bf1bfd24b636cb436cb047d3324dVirustotal results 22.03%SilentBuilder
2022-01-11M65099214787659T.xlsxls afe04f54612c86612a56bf8a3a228a2aeae275f4730552228f8a4bb6f71c292en/aSilentBuilder
2022-01-11H046565313.xlsxls fbc4a5db3ab48741c10a226dae4e2b64d924110962224bef57910478251cf3c7n/aSilentBuilder
2022-01-1147953449534007145799B.xlsxls 60fdf680c8e0272784588bf87ead2814df683a2fcb697522ddd4ef323166440an/a SilentBuilder
2022-01-112383055M.xlsxls f9dc6d359581da286cc014340d248cea2acedf09a9dc0cf9280641f3393fba35n/aSilentBuilder
2022-01-118196388439923267098O.xlsxls e7133e75c8b62eae0ca8dceffad7785b809365feb928a7181deab88f8c30df16n/a SilentBuilder
2022-01-111577988175685347922.xlsxls e99c27037595f4931d753f7e372cbad60953e56c327d9ea2a2c3042db0f5f4e4Virustotal results 18.64%SilentBuilder
2022-01-11T17288746171774756W.xlsxls 659c21119c192bd5c4c698d0e9c0ef6c5d0ed38bf40907318ccbc4dece45ec76n/aSilentBuilder
2022-01-11C27493569211801581488.xlsxls 1cdf6133fd1d4138849b8f2b29f199d90ccce54c369b74a88a14e8329e1051c3n/aHeodo
2022-01-1173690672.xlsxls 2709ea59d34478c496b08e82eb77182fba9c9af001b75cfab5aaa44621d359bdn/a Heodo
2022-01-11961026627911228289498W.xlsxls 071d6c9a40d6721f41c7064edb52f46d766703ea2e9bbe033939b6d60f24604bVirustotal results 16.67%Heodo
2022-01-111462120060.xlsxls 5b8d0b12d4a393432ef70e1832915b20c0a39b948c524ac301e3ae5f9794b84dn/aSilentBuilder
2022-01-11316147187927.xlsxls bdb3e9a556bc850867023c8e1c5ea1e20cda48c72bd0396ef667d3352b14d65fn/aSilentBuilder
2022-01-1166430495.xlsxls bcd9548679c87026f7119b2a46f731fa2d1c20fdd1ba546f5e20281b30ade8e9Virustotal results 16.67% Heodo
2022-01-11H52700906.xlsxls 12db004e136ba9f8fd95d9d6e3a08d5b3cfde159c0ca3f99a75df8922fbdcd85n/a SilentBuilder
2022-01-11257124044116163B.xlsxls bd70c3c5fc66e6e16f357179f6a76273bfd128d8f203716b035864ca4a4806een/a SilentBuilder
2022-01-113333819.xlsxls 474cb0554cd5fb8976244c74a115a07164b25952cbbe6e7868a99045b435f535n/a SilentBuilder
2022-01-11I7770055436822670.xlsxls b6695d0c24ee697dc9605c2f66c2f6c0688b9546bb2957505b238040001a1acbn/aSilentBuilder
2022-01-11Q95019066200772695.xlsxls 619a36bb106284a941479a0f0c4ec11dded72ed93a1e9c0909eaf2ebc84a69d4Virustotal results 12.07% SilentBuilder
2022-01-11Y0184164395839.xlsxls a8085602b4f2d9fa12e7cdc848185b57baef023cbe353df862fac4ff279cf3f4n/aSilentBuilder
2022-01-11N068804891.xlsxls 03c7dce022ba5927f0047e1ff4eae1b193016b57a701ea176975290263d7893fn/a SilentBuilder
2022-01-11T1238207830357694F.xlsxls bd340cd4783cfc7f2e8d3362be0e846c95b1a0f89d28d9df48ed36cbfec86e87n/a Heodo
2022-01-11D48288327O.xlsxls d78c9ad266c4e93e0c97fe9cc3bd593afa995a93f59aba16c1bb63c421d6a9dcn/a SilentBuilder
2022-01-1115293312123450.xlsxls a2e296ce454120b7c7bd67add90fc0de4f7c805c6fd66471a1ef2ce19a7de34eVirustotal results 15.00% SilentBuilder
2022-01-11K019818210372268.xlsxls 7398cc356f34763ebb74209f98d07a50292965967c7650dad6f061987df0494dn/a SilentBuilder