URLhaus Database

You are currently viewing the URLhaus database entry for http://altai-prop.ru/administrator/sLltV728DcGM/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1967157
URL: http://altai-prop.ru/administrator/sLltV728DcGM/?i=1
URL Status:Offline
Host: altai-prop.ru
Date added:2022-01-11 12:51:05 UTC
Last online:2022-01-20 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2022-01-11 12:52:15 UTC to lir{at}avantel[dot]ru)
Takedown time:8 days, 17 hours, 28 minutes Bad (down since 2022-01-20 06:20:58 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1201356_27758.xlsmxls 05dc48ca9e5d5feb04a32c1ef3a8d18453a2a679e7257ce24856895a5dea268bVirustotal results 25.42%SilentBuilder
2022-01-1114620617-758243.xlsmxls 034eaef52f3dc5154e7a94121703ea759fd19784df604e48c8e73ff4fa06cfdan/aHeodo
2022-01-1100469289-59.xlsmxls 44c675302c6fd62e15e5c9ae9bb98325870093ceed92a30601a13ad1dc2bd4f2Virustotal results 23.33% SilentBuilder
2022-01-1187689ZEOF9.xlsmxls 207177c3c5eb0fe56e8614f9107063106f39167ae239ada435312ba0455fe349Virustotal results 16.67%SilentBuilder
2022-01-11DyZTqf-924627.xlsmxls 9b3fb2f88edc75661d9aba9ccac4bd15607dbf2fa7542c47be3d533c0db5cbe5Virustotal results 18.64%SilentBuilder
2022-01-11kmkba_06.xlsmxls 14222deeec10d32091a2947e045833bd25c041a662f4090df26e50381cf922c6n/a Heodo
2022-01-113266485735431513260R.xlsxls a88137e6086255207269b721d3cdb9d6a67cbb8861ba98d4681f83945fa29299Virustotal results 16.67% SilentBuilder
2022-01-11C249783105773980181D.xlsxls 8ea7ac4cc4dd1576b45451813ade47420f9196a212e173e174aada937cb8f4a7n/a SilentBuilder
2022-01-11U15563860284142568.xlsxls c7cc8c98988b0b5cdbd103db7c61f01a6e92f96f525c36f15bfaae039bb46cd7n/a Heodo
2022-01-11O239821027159155.xlsxls 416e811b6839dbe39092f82dbb62064350da5400ce2e1fd94870f305f5b2b77dVirustotal results 16.95%SilentBuilder
2022-01-11Y42576819501884130524.xlsxls d92b0ebb1f64086c8c4d5b238f3683a3319bcf041cdfc9e6736f742a260a5ce2n/aSilentBuilder
2022-01-11826271310325T.xlsxls 426fda840765e44250686f1102e902242babe0cea36a756beac6c0757a73c28an/a SilentBuilder
2022-01-11644551520120446D.xlsxls c415f6432a14864da8d7cd66dab9263599364b3b1d8b3fd13e4c725d1a0c4562n/aSilentBuilder
2022-01-11Z8079854035.xlsxls 7b273da870150fa002d6651be951c45565ecfb209c9516b78a60d5e6274d4f9cn/a SilentBuilder
2022-01-11U63147374512811879937.xlsxls 18e24e9b03fde05fa41b9d86aa612dbbd5deabcebbe97ee5b3a3b7fa8fb43f51n/aSilentBuilder
2022-01-11W7470018857K.xlsxls a5a1c304ab3b2351a82da736cf9c022ea2ad1cbff6321b64b0a741b575c8a6c4n/a SilentBuilder
2022-01-1162039935545441Y.xlsxls b8600d1365521e1a2f83ae356900d38cf8c44b60594bbe30df2ac04418cd823en/aSilentBuilder
2022-01-11985968192857.xlsxls 1e4e0feb94cf74d61c7557fd8b7883f71b80547083bc339bc808b9703d4c03c1n/aSilentBuilder
2022-01-11I0381342292571704.xlsxls 0c9de24621d73ddfb33b0d2607b84d523a103ff59e318980f134dac1726e11a6n/a SilentBuilder
2022-01-11M995594933979011395220G.xlsxls c5850b16a368ab7c8f2d03cebcc7dd51173a704cdd1d6c105ba43083a40b6063n/aSilentBuilder
2022-01-117797649667987.xlsxls 2709ea59d34478c496b08e82eb77182fba9c9af001b75cfab5aaa44621d359bdn/a Heodo
2022-01-11V8755763134818618E.xlsxls d4ab41fa48cb03ac55da7c05e857ea1b5a88a2b31cde074f3036f6129662a10fn/a SilentBuilder
2022-01-11F27935315V.xlsxls 2b6937e90b3f57eb3f26b8a3f50b86def03b2d4b3bc30d93e1af1c96656bb4dan/aHeodo
2022-01-114376043H.xlsxls 17832170dc965d40f1a4b7b5abf6dd5f8d131468c82c281388bf6f6967b77490Virustotal results 18.33%SilentBuilder
2022-01-112438097304190421325Z.xlsxls d2c48bc93b2b0711be6bafd81a7eeddc944514e110ef2e1014151dac42e8ab62n/a SilentBuilder
2022-01-11P1093044348857148715.xlsxls 89224af568d4e29e7836c2961d33045490b337a9d5d40db852137e1f2dbbfbf9Virustotal results 12.50%SilentBuilder
2022-01-11F49186431608017B.xlsxls 7c1004454dd200c8e01f09e796c996a70ee951164ec546ae10634a41c1eb4d22n/aSilentBuilder
2022-01-11091914413421X.xlsxls 85b88ed279f103f41ae22a4adc9e432be6770a9d241fa124e7a62bf857995c8bVirustotal results 16.67%SilentBuilder
2022-01-11755582059638636D.xlsxls 7550a2a99fe2768446351c653515cda693fc4978cdb437177efcc2133117efbcn/aSilentBuilder
2022-01-11D646721808523.xlsxls c17cf152edefc6ce2ed0a5fa783f3bbfd6348b41a22f0da9cdd2722311ddfd62Virustotal results 13.33% Heodo
2022-01-115805899503328603934J.xlsxls 54517f5914c526589a1b1ad61249c75209d239c1885cd72f638d9924d53983deVirustotal results 13.33%SilentBuilder
2022-01-11599535831347258694.xlsxls 6b28b200163448c423b79b68a70f8d07d925445d48edb48526d9dfdbf68d47c1n/aSilentBuilder