URLhaus Database

You are currently viewing the URLhaus database entry for http://demo10.platsandgo.com/wp-includes/xGSGa40m/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1967185
URL: http://demo10.platsandgo.com/wp-includes/xGSGa40m/?i=1
URL Status:Offline
Host: demo10.platsandgo.com
Date added:2022-01-11 13:00:05 UTC
Last online:2022-01-12 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2022-01-11 13:01:11 UTC to abuse{at}ovh[dot]net)
Takedown time:18 hours, 5 minutes Good (down since 2022-01-12 07:06:42 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1249166314_869.xlsmxls 8642a84875b30eeae2bec0b16db37715f4a2ff15caf6e5185a4012107ec1e87bVirustotal results 26.67%SilentBuilder
2022-01-1222471_750945.xlsmxls 532105c51f0f4b68350191b68f17d6226112e97f273af215511a517604a1770eVirustotal results 25.42%SilentBuilder
2022-01-1291155_6562.xlsmxls 1b7581c8be4bf9197005067c42e581bcc1c41b10d6d9768daa8c4642f6e3ef7bn/a SilentBuilder
2022-01-12BohCP_38617673.xlsmxls f9cbf3cdfa7ed91bca677fd8d8e1f0f53c193323abfbbb1ce4d7c6d2f1b9feean/a SilentBuilder
2022-01-12nQk0049.xlsmxls 59f00806db4a68a10acb6aa0f9ea1d21c2e8527ff2b82d0ab36196ba0bda9183n/aSilentBuilder
2022-01-11RU_3387503.xlsmxls 034eaef52f3dc5154e7a94121703ea759fd19784df604e48c8e73ff4fa06cfdan/aHeodo
2022-01-111512373_28.xlsmxls bfe1c65501eb9a22ea914fe380d24127cdf99ce17fc20683f99a7b1e0ccc06f8n/aSilentBuilder
2022-01-1145624723_69.xlsmxls 207177c3c5eb0fe56e8614f9107063106f39167ae239ada435312ba0455fe349n/aSilentBuilder
2022-01-11AS3381.xlsmxls 9b3fb2f88edc75661d9aba9ccac4bd15607dbf2fa7542c47be3d533c0db5cbe5n/aSilentBuilder
2022-01-1159672410322.xlsmxls 4732ca576ac4a1b57726b01684356326dabe72f56f1f90308801953e421ce1dfVirustotal results 18.64% Heodo
2022-01-11779460640208J.xlsxls 446d074d88398efd9a59c8bdabf3f4909ae1bc5c12c418b98c3f185459844fafn/a SilentBuilder
2022-01-1171703477239N.xlsxls 8ea7ac4cc4dd1576b45451813ade47420f9196a212e173e174aada937cb8f4a7n/a SilentBuilder
2022-01-11G8344143M.xlsxls c7cc8c98988b0b5cdbd103db7c61f01a6e92f96f525c36f15bfaae039bb46cd7n/a Heodo
2022-01-115957403907.xlsxls 416e811b6839dbe39092f82dbb62064350da5400ce2e1fd94870f305f5b2b77dVirustotal results 16.95%SilentBuilder
2022-01-11039406652090801F.xlsxls d92b0ebb1f64086c8c4d5b238f3683a3319bcf041cdfc9e6736f742a260a5ce2n/aSilentBuilder
2022-01-11R296890523952544361.xlsxls 426fda840765e44250686f1102e902242babe0cea36a756beac6c0757a73c28an/a SilentBuilder
2022-01-11287154561B.xlsxls 60a3cac5d9b0a0245018aa7be50050668c8568d31ae1d65fc827d087b22f6160n/a Heodo
2022-01-11736518150Z.xlsxls 7b273da870150fa002d6651be951c45565ecfb209c9516b78a60d5e6274d4f9cn/a SilentBuilder
2022-01-1191450526745300.xlsxls 18e24e9b03fde05fa41b9d86aa612dbbd5deabcebbe97ee5b3a3b7fa8fb43f51n/aSilentBuilder
2022-01-11763510415951471.xlsxls 5567612a01ddde62a81334d73dc09a4e0f78d8e552d2686d44eb3e3910ecf13dVirustotal results 18.33%SilentBuilder
2022-01-1140715981713.xlsxls c8da70757266ad16673f097707b187bd2c74ea9019322fd777382c943124bfdfn/a SilentBuilder
2022-01-11M336284628420570656017.xlsxls 1e4e0feb94cf74d61c7557fd8b7883f71b80547083bc339bc808b9703d4c03c1n/aSilentBuilder
2022-01-1179419260445150300.xlsxls 0c9de24621d73ddfb33b0d2607b84d523a103ff59e318980f134dac1726e11a6Virustotal results 16.67% SilentBuilder
2022-01-11394164669654720949N.xlsxls 0237b96acc934eba1b920d0b6fa654c22128101417298a9f940ca2e53c85dab9Virustotal results 15.52%Heodo
2022-01-110797479554J.xlsxls b68760371e947df68d4f69a1f9b43a56de082932df771b0ef088adaae130931cn/a SilentBuilder
2022-01-119027840883254730.xlsxls a6854cf37029a39a9a86de7f468e16d520cc046bef6fcd50290cd7c19843cd74Virustotal results 15.52%Heodo
2022-01-117088035027496113875.xlsxls 2f80ecbe8f3eb45c354fb36640dc4be6b13064be8550f2d49e41090e5c113b72n/aHeodo
2022-01-1153444128174376W.xlsxls dda6bd51ff45aa0e3b4e72d47460f7a78c5bb0bc0f1c43d09a20c88b01b6f851Virustotal results 16.67%SilentBuilder
2022-01-116088599299924517E.xlsxls bdb3e9a556bc850867023c8e1c5ea1e20cda48c72bd0396ef667d3352b14d65fn/aSilentBuilder
2022-01-114046089.xlsxls bcd9548679c87026f7119b2a46f731fa2d1c20fdd1ba546f5e20281b30ade8e9n/a Heodo
2022-01-11I516663006717534346372V.xlsxls 2b3edf1dce5ad17220c402308e28a5f2ca0032703557b04aa816d53bb30bb97cn/a SilentBuilder
2022-01-11N8508500071389.xlsxls 361e7457bfd87680419fd11b82e2c11ba668205e8421b38cfcb7e879e5267ddan/aSilentBuilder
2022-01-11Z5405145257608.xlsxls 474cb0554cd5fb8976244c74a115a07164b25952cbbe6e7868a99045b435f535n/a SilentBuilder
2022-01-11W657233076501892646667P.xlsxls 5471bc0d0b81c3ee5e169546f5eb63613253af486bc28e14da70e43ba2acbdf7n/aSilentBuilder
2022-01-11A12096723392801008.xlsxls f0ca4bbe2594076644e5f27040111f3f422d61a3268078140077095c40d8dd6bn/a Heodo
2022-01-113185967515671955.xlsxls be0b11916ecb4101f05770478b70375165650d7ea4330c4e9c98c407058de722n/a SilentBuilder