URLhaus Database

You are currently viewing the URLhaus database entry for http://avionxpress.com/lp/w/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1967257
URL: http://avionxpress.com/lp/w/?i=1
URL Status:Offline
Host: avionxpress.com
Date added:2022-01-11 13:21:05 UTC
Last online:2022-02-04 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 13:22:08 UTC to abuse{at}bluehost[dot]com)
Takedown time:24 days, 7 hours, 11 minutes Bad (down since 2022-02-04 20:33:34 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-128404211.xlsxls 37e872cc3b4e9e0f9e1472f6865ac985496582ef138fd1646fe13bd14bb92c0fVirustotal results 16.95% Heodo
2022-01-11O578002289.xlsxls 1289c645dc8d8ff1a81ca74c01191f7f2deaa2b0b5337e534dc094a4510fd865n/aSilentBuilder
2022-01-11907878812405860105748.xlsxls a6854cf37029a39a9a86de7f468e16d520cc046bef6fcd50290cd7c19843cd74n/aHeodo
2022-01-11O4262873371927X.xlsxls 2f80ecbe8f3eb45c354fb36640dc4be6b13064be8550f2d49e41090e5c113b72n/aHeodo
2022-01-11074063763D.xlsxls 445e137304a2c43b06f0c98f4655f6fc4d69db7ae73ddf9094295c48f0701047n/a SilentBuilder
2022-01-11Y53986632107581586.xlsxls bdb3e9a556bc850867023c8e1c5ea1e20cda48c72bd0396ef667d3352b14d65fn/aSilentBuilder
2022-01-11G464412409401037Y.xlsxls 125d84a3e35c42f4464704bc17b835fd488c8116476a7c61d170e47def200dd6Virustotal results 15.25% Heodo
2022-01-116252391C.xlsxls 89224af568d4e29e7836c2961d33045490b337a9d5d40db852137e1f2dbbfbf9n/aSilentBuilder
2022-01-11B33088145774690897176K.xlsxls 645258c3eec8a24b056403664b65d66c43f78566a0f33270723a6edc4d0c7ed8n/a SilentBuilder
2022-01-11M760804756044G.xlsxls 4aefb5b1abc024bebde146e63d3af9ed1881561eb9dab40f53da736661654b49n/a Heodo
2022-01-118963768714366250P.xlsxls a672f734a98a5b287eb96d134893701f055f20573dd9f9d778b1e7953b00a944n/aSilentBuilder
2022-01-11100810156956D.xlsxls ffd39f522cb9bcdb3dac93c34aa136be3cdc6cc6f6b878cf756a5a53443546fen/a Heodo