URLhaus Database

You are currently viewing the URLhaus database entry for https://magertoshopping.com/wp-admin/Z3CtBL/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1967707
URL: https://magertoshopping.com/wp-admin/Z3CtBL/?i=1
URL Status:Offline
Host: magertoshopping.com
Date added:2022-01-11 16:25:05 UTC
Last online:2022-01-11 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2022-01-11 16:26:09 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 hour, 57 minutes Good (down since 2022-01-11 18:23:12 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-112198256124M.xlsxls e540aa4c8a0a7eb9acf80aa3e76a804c5f492a69e052e33584c0ce432b33de75n/a SilentBuilder
2022-01-1126660966840740.xlsxls 1e4e0feb94cf74d61c7557fd8b7883f71b80547083bc339bc808b9703d4c03c1n/aSilentBuilder
2022-01-11795754074C.xlsxls 0c9de24621d73ddfb33b0d2607b84d523a103ff59e318980f134dac1726e11a6n/a SilentBuilder
2022-01-11F3121509476076286K.xlsxls c5850b16a368ab7c8f2d03cebcc7dd51173a704cdd1d6c105ba43083a40b6063n/aSilentBuilder
2022-01-1197655598955907.xlsxls 3d349cfaac69f883e7538584bf43d45307da7e0e04c37f970836d3326feb2948n/aHeodo
2022-01-11L941425383656829574061.xlsxls ee82a155abd6811049d69a344bdb5542470ed1d02196249c9ab27e980b0b74bbn/a SilentBuilder