URLhaus Database

You are currently viewing the URLhaus database entry for http://majesticeverest.com/webmaster/hYnVFJfDKC4/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1967042
URL: http://majesticeverest.com/webmaster/hYnVFJfDKC4/?i=1
URL Status:Offline
Host: majesticeverest.com
Date added:2022-01-11 12:09:04 UTC
Last online:2022-01-12 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2022-01-11 12:10:10 UTC to abuse{at}hetzner[dot]com)
Takedown time:21 hours, 17 minutes Good (down since 2022-01-12 09:27:33 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1167116319_33916843.xlsmxls a7fe36211a0be63df4c3929830b8fc4e21fc0548b5446377ce9c83b3d1fd9339Virustotal results 20.00%SilentBuilder
2022-01-1193829133_9895.xlsmxls e48f10cc12e08a32f523982c024f49dca076b06c6bd47b5cdf3d43aee5097091Virustotal results 16.67%Heodo
2022-01-111425198_5898.xlsmxls a3977aa3c358df0d9777be64e5c10b4a874fd0eac63183e92837d58038e5c4c1n/a Heodo
2022-01-11831035040182326245.xlsxls 62ec5aff1c6c20ac27c09077ff459dbe375a4d8841b6b47f85c7e51b7d26fd9bVirustotal results 18.33% SilentBuilder
2022-01-11F2374409886N.xlsxls b68760371e947df68d4f69a1f9b43a56de082932df771b0ef088adaae130931cVirustotal results 17.24% SilentBuilder
2022-01-11X639185862564127N.xlsxls 1289c645dc8d8ff1a81ca74c01191f7f2deaa2b0b5337e534dc094a4510fd865n/aSilentBuilder
2022-01-11A286353646856P.xlsxls a6854cf37029a39a9a86de7f468e16d520cc046bef6fcd50290cd7c19843cd74n/aHeodo
2022-01-115714098441618734Z.xlsxls 7955874a069fbde3eb5144ea8420f8b9e80d0c8ccd822c21b54150e53608116cn/aSilentBuilder
2022-01-114782176.xlsxls 0b52372793be51e4313df2cb64a2b43650e47eb55920506fa6ac3f0726da0a89n/aSilentBuilder
2022-01-114370499756106.xlsxls a1713a6e838656d686b56ed5f3822eac423bddd1637b56f9e24b3245ed798d99n/a SilentBuilder
2022-01-11078174675709753.xlsxls 03c7dce022ba5927f0047e1ff4eae1b193016b57a701ea176975290263d7893fn/a SilentBuilder
2022-01-11K43051406425B.xlsxls bd340cd4783cfc7f2e8d3362be0e846c95b1a0f89d28d9df48ed36cbfec86e87n/a Heodo
2022-01-11N6301336029585452054.xlsxls 07ba265b088af587be86368377a4266ac868709decd8fc747c2c4af835eea5edn/a Heodo