URLhaus Database

You are currently viewing the URLhaus database entry for http://cfgtactical.marketgriddev.co/assets/iiuQNNKS15ep88MK/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1967313
URL: http://cfgtactical.marketgriddev.co/assets/iiuQNNKS15ep88MK/?i=1
URL Status:Offline
Host: cfgtactical.marketgriddev.co
Date added:2022-01-11 13:42:11 UTC
Last online:2022-01-12 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2022-01-11 13:43:08 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 day, 5 hours, 52 minutes Poor (down since 2022-01-12 19:35:42 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12EC_86603.xlsmxls 662f993ddf616adf7550191c5036d719e0cb02c2c5e1fb9b0e87d51598b71190Virustotal results 25.42%SilentBuilder
2022-01-12U-7186532.xlsmxls 894ae1ab382fe85d09096d1997f468b8e5f327326c39e15bd1ba47f4c4d2f14fn/a Heodo
2022-01-12660_5606866.xlsmxls a196a7f762ccc713b4c96a96ad4d8d50c3a27964758730b87741f65f609c91abn/a SilentBuilder
2022-01-12235172_84.xlsmxls 1c5ad6e4718ec14f2180c8f047a7867ba5ce9f4498024dd2a4f66974ca1cdfcen/aSilentBuilder
2022-01-1106741HGQ_346779.xlsmxls 66f5d61a2c4246c3bc39141c46e41bdc84c3f12a7db0b2ec3090eace070392d6n/a SilentBuilder
2022-01-11aZ_078.xlsmxls bb32c9472ef2faeae273e266c7fd2dd749d5b200affe3e0e3d3cbacd4cf6e904Virustotal results 23.33%SilentBuilder
2022-01-1179_20.xlsmxls 207177c3c5eb0fe56e8614f9107063106f39167ae239ada435312ba0455fe349n/aSilentBuilder
2022-01-11G_536.xlsmxls 71520c6b61c641945ab1d47dd755be9ecb8dfd171fa5daf9773a99459cb45efbn/aSilentBuilder
2022-01-11IU-945.xlsmxls 14222deeec10d32091a2947e045833bd25c041a662f4090df26e50381cf922c6n/a Heodo
2022-01-11Q46924291370107545523W.xlsxls a88137e6086255207269b721d3cdb9d6a67cbb8861ba98d4681f83945fa29299n/a SilentBuilder
2022-01-1182920101671O.xlsxls dc1a568534305e8dd82443bd62f3fefe364de2073558c8237bbe099593714259Virustotal results 16.67%SilentBuilder
2022-01-11H19919181.xlsxls c7cc8c98988b0b5cdbd103db7c61f01a6e92f96f525c36f15bfaae039bb46cd7Virustotal results 16.67% Heodo
2022-01-11848645555796967L.xlsxls 315dd45566ca97fd4266848666711fa05631dc30b00721506b62bf5dfd247dc6Virustotal results 10.34% Heodo
2022-01-119964250.xlsxls b3a64afe3a1360279c7354909eb0733a15870549ca068a851cb8dc7b672ee168Virustotal results 23.33% SilentBuilder
2022-01-11172600019431869776681R.xlsxls 1ee39644692931c717336eb3e00db7e82c9a27e987a8931e45d3eca7abd009c1n/a Heodo
2022-01-1179579601919220310106.xlsxls a43e422bf49682cd2dd5c53f5e3c8b8712c76cd9f082309e92decc55f0f8f92en/aHeodo
2022-01-11H320623037148.xlsxls afe04f54612c86612a56bf8a3a228a2aeae275f4730552228f8a4bb6f71c292eVirustotal results 20.69%SilentBuilder
2022-01-1151151344865641645Z.xlsxls 18e24e9b03fde05fa41b9d86aa612dbbd5deabcebbe97ee5b3a3b7fa8fb43f51n/aSilentBuilder
2022-01-119611319823288.xlsxls a5a1c304ab3b2351a82da736cf9c022ea2ad1cbff6321b64b0a741b575c8a6c4n/a SilentBuilder
2022-01-11561226017690593.xlsxls e540aa4c8a0a7eb9acf80aa3e76a804c5f492a69e052e33584c0ce432b33de75n/a SilentBuilder
2022-01-11273109809828Y.xlsxls 1e4e0feb94cf74d61c7557fd8b7883f71b80547083bc339bc808b9703d4c03c1n/aSilentBuilder
2022-01-11P53626764669229401942.xlsxls 0c9de24621d73ddfb33b0d2607b84d523a103ff59e318980f134dac1726e11a6n/a SilentBuilder
2022-01-11H7356440763621.xlsxls 659c21119c192bd5c4c698d0e9c0ef6c5d0ed38bf40907318ccbc4dece45ec76n/aSilentBuilder
2022-01-11F545638184537545.xlsxls 788a3d46892b3580cf799d66bb7348a0d50ad1543027c036530fc0fe5135bac5n/a SilentBuilder
2022-01-11T49293797637135P.xlsxls 9e3e47f20134301b475d2d5477000f2ff061b7e2ccf7c02aa892d300c3da3b36Virustotal results 17.24% SilentBuilder
2022-01-11P289395449147439836074I.xlsxls 071d6c9a40d6721f41c7064edb52f46d766703ea2e9bbe033939b6d60f24604bVirustotal results 16.67%Heodo
2022-01-1170233972863Q.xlsxls 5b8d0b12d4a393432ef70e1832915b20c0a39b948c524ac301e3ae5f9794b84dVirustotal results 13.33%SilentBuilder
2022-01-11Z083361438374206421314.xlsxls 17832170dc965d40f1a4b7b5abf6dd5f8d131468c82c281388bf6f6967b77490Virustotal results 18.33%SilentBuilder
2022-01-1191265269965M.xlsxls b53a3f09073ba4c63f1634b32bc6328f22d9965ebc1384797a886d07959313fan/aSilentBuilder
2022-01-1153632426323D.xlsxls 89224af568d4e29e7836c2961d33045490b337a9d5d40db852137e1f2dbbfbf9n/aSilentBuilder
2022-01-11J3373734465763580888.xlsxls 645258c3eec8a24b056403664b65d66c43f78566a0f33270723a6edc4d0c7ed8n/a SilentBuilder
2022-01-114638727372266021838J.xlsxls 85b88ed279f103f41ae22a4adc9e432be6770a9d241fa124e7a62bf857995c8bVirustotal results 16.67%SilentBuilder
2022-01-11F79143085.xlsxls 7550a2a99fe2768446351c653515cda693fc4978cdb437177efcc2133117efbcn/aSilentBuilder