URLhaus Database

You are currently viewing the URLhaus database entry for http://restructionhrroom.com/cgi-bin/QEk/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1967012
URL: http://restructionhrroom.com/cgi-bin/QEk/?i=1
URL Status:Offline
Host: restructionhrroom.com
Date added:2022-01-11 12:02:05 UTC
Last online:2023-01-21 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2023-01-21 05:03:07 UTC to allcomm{at}shore[dot]net)
Takedown time:1 year, 0 month, 14 days, 17 hours, 58 minutes Bad (down since 2023-01-21 06:02:15 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1296547-3.xlsmxls aa65a34067b0c50e89c1078d0c7ff08de43e5036241404574f846265de6ff6bdVirustotal results 28.33%Heodo
2022-01-12273570762_2247.xlsmxls 1e8ed8d61ad3f66e9acac149db12bf6f3db13cef81cbedc8bf9602c391450c43Virustotal results 29.31%SilentBuilder
2022-01-124157484146.xlsmxls 228b8793653662088991f7cfa3b368bce32931a7516a2f8c7188a437eb03a856n/aSilentBuilder
2022-01-12YKQGB_5123468.xlsmxls fea0e3dc5015a4f0d14555e51520aed1594e9b0a3310bac2598db38f11e311c7Virustotal results 30.51%SilentBuilder
2022-01-12AO79720.xlsmxls aa0e36780912b94ce9abefe196de12d6f4097dbc7fa864d24778638043de4084Virustotal results 30.00% SilentBuilder
2022-01-12ndqhqv-604353.xlsmxls 5c2972a5491e6d8209aa42964c99ad4f8621686005fbc5e1836b4b18d165a888Virustotal results 26.67%SilentBuilder
2022-01-1293512886_49471.xlsmxls d3d61558116adba228714e7e660ef421ae85b439fd2224a440e617fdeae70987Virustotal results 27.12%SilentBuilder
2022-01-122670607_65109251.xlsmxls 8642a84875b30eeae2bec0b16db37715f4a2ff15caf6e5185a4012107ec1e87bn/aSilentBuilder
2022-01-1284185451QXJD_751.xlsmxls 532105c51f0f4b68350191b68f17d6226112e97f273af215511a517604a1770eVirustotal results 25.42%SilentBuilder
2022-01-12VWO-064.xlsmxls 1b7581c8be4bf9197005067c42e581bcc1c41b10d6d9768daa8c4642f6e3ef7bn/a SilentBuilder
2022-01-12dkyyaks_6083207.xlsmxls f7d338277f13461262faa21c960479146f4261acc6efe564964f5cd0370afd6en/a SilentBuilder
2022-01-12wh_6.xlsmxls 59f00806db4a68a10acb6aa0f9ea1d21c2e8527ff2b82d0ab36196ba0bda9183n/aSilentBuilder
2022-01-11275655938.xlsmxls 034eaef52f3dc5154e7a94121703ea759fd19784df604e48c8e73ff4fa06cfdan/aHeodo
2022-01-11j5229505.xlsmxls 44c675302c6fd62e15e5c9ae9bb98325870093ceed92a30601a13ad1dc2bd4f2Virustotal results 16.67% SilentBuilder
2022-01-11UINU_79.xlsmxls d616af039b685a1e393e85dfd6d3558a0a062fc2cd776bfdbfd55dd1cca9e55en/a SilentBuilder
2022-01-1119662778OLWDYU_0787840.xlsmxls f326b9b9af87bd43878455ac75b4e61fadd71bdfcebf5b4508525cbbb4e8038bVirustotal results 16.95% Heodo
2022-01-11crrm_507765.xlsmxls 12e3064b327fef718bd5c25b6d26ad24846b3612bfff59eb566107d957b9f854n/a SilentBuilder
2022-01-1100801835762391.xlsxls a88137e6086255207269b721d3cdb9d6a67cbb8861ba98d4681f83945fa29299n/a SilentBuilder
2022-01-11435509908.xlsxls dc1a568534305e8dd82443bd62f3fefe364de2073558c8237bbe099593714259Virustotal results 16.67%SilentBuilder
2022-01-11I388292011.xlsxls 1db259b0063d26f9af684e7246d336250e289514a4e900eab1337ee9981a866bVirustotal results 21.67% Heodo
2022-01-1130454343551193521318I.xlsxls 416e811b6839dbe39092f82dbb62064350da5400ce2e1fd94870f305f5b2b77dVirustotal results 16.95%SilentBuilder
2022-01-11N79664224932778578503K.xlsxls f9e789531cb031e9e6767f54a780f6ee8b53a417acb2b2012dbfaf1579aee55fn/a SilentBuilder
2022-01-113707541953776337V.xlsxls fe48432635e691df0782c8195559f80acd38518a812ec1ea5fc96957d94f6642Virustotal results 23.73%SilentBuilder
2022-01-11U91296533560081.xlsxls 3d2ad015f60956cee32029cb7d6fee846f34a91d0f6dae2b68cfde31c99b4a77n/aHeodo
2022-01-11N9346870261168682M.xlsxls afe04f54612c86612a56bf8a3a228a2aeae275f4730552228f8a4bb6f71c292eVirustotal results 20.69%SilentBuilder
2022-01-11T6636973588066428342.xlsxls 18e24e9b03fde05fa41b9d86aa612dbbd5deabcebbe97ee5b3a3b7fa8fb43f51n/aSilentBuilder
2022-01-113659101761041.xlsxls 5567612a01ddde62a81334d73dc09a4e0f78d8e552d2686d44eb3e3910ecf13dVirustotal results 18.64%SilentBuilder
2022-01-11X49408287354.xlsxls e540aa4c8a0a7eb9acf80aa3e76a804c5f492a69e052e33584c0ce432b33de75n/a SilentBuilder
2022-01-116320692O.xlsxls 1e4e0feb94cf74d61c7557fd8b7883f71b80547083bc339bc808b9703d4c03c1n/aSilentBuilder
2022-01-11049779996838344578136N.xlsxls 0c9de24621d73ddfb33b0d2607b84d523a103ff59e318980f134dac1726e11a6n/a SilentBuilder
2022-01-119944026436694043230.xlsxls 0237b96acc934eba1b920d0b6fa654c22128101417298a9f940ca2e53c85dab9n/aHeodo
2022-01-1191959136537462170420B.xlsxls b68760371e947df68d4f69a1f9b43a56de082932df771b0ef088adaae130931cn/a SilentBuilder
2022-01-11R9656023757940B.xlsxls 7955874a069fbde3eb5144ea8420f8b9e80d0c8ccd822c21b54150e53608116cn/aSilentBuilder
2022-01-118877442.xlsxls 2f80ecbe8f3eb45c354fb36640dc4be6b13064be8550f2d49e41090e5c113b72n/aHeodo
2022-01-1158610441712832825035.xlsxls 445e137304a2c43b06f0c98f4655f6fc4d69db7ae73ddf9094295c48f0701047n/a SilentBuilder
2022-01-11397794495.xlsxls d71f960574a42f577d5397574467ba2f556d0be9bec55b99c58946fab29ee994n/a Heodo
2022-01-11T52116711639139B.xlsxls d2c48bc93b2b0711be6bafd81a7eeddc944514e110ef2e1014151dac42e8ab62n/a SilentBuilder
2022-01-11E3959823141073984.xlsxls 89224af568d4e29e7836c2961d33045490b337a9d5d40db852137e1f2dbbfbf9n/aSilentBuilder
2022-01-11M1493546.xlsxls 7c1004454dd200c8e01f09e796c996a70ee951164ec546ae10634a41c1eb4d22n/aSilentBuilder
2022-01-11G6070629.xlsxls 85b88ed279f103f41ae22a4adc9e432be6770a9d241fa124e7a62bf857995c8bVirustotal results 16.67%SilentBuilder
2022-01-11D6743876K.xlsxls 7550a2a99fe2768446351c653515cda693fc4978cdb437177efcc2133117efbcVirustotal results 16.67%SilentBuilder
2022-01-11V41181515505U.xlsxls c17cf152edefc6ce2ed0a5fa783f3bbfd6348b41a22f0da9cdd2722311ddfd62Virustotal results 13.33% Heodo
2022-01-11867787582023348P.xlsxls 54517f5914c526589a1b1ad61249c75209d239c1885cd72f638d9924d53983den/aSilentBuilder
2022-01-11O379490733.xlsxls 6b28b200163448c423b79b68a70f8d07d925445d48edb48526d9dfdbf68d47c1n/aSilentBuilder
2022-01-11240999795759851368407L.xlsxls 25a3e55a8c505687b78fb62ff041db36ed577b17dbd1b9ebf4e8628b9cf7b18en/a SilentBuilder
2022-01-11V789416717875285.xlsxls 2827fc31c04aa752a7efbf7c6951ef6ef08c381a1c01feb379dfde0b9f5874f7n/a SilentBuilder