URLhaus Database

You are currently viewing the URLhaus database entry for http://vintres.com.br/wp-includes/0692BRJRSSUYSM_31152/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1984643
URL: http://vintres.com.br/wp-includes/0692BRJRSSUYSM_31152/?i=1
URL Status:Offline
Host: vintres.com.br
Date added:2022-01-17 21:40:04 UTC
Last online:2022-01-26 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-17 21:41:08 UTC to abuse{at}ovh[dot]net)
Takedown time:8 days, 16 hours, 33 minutes Bad (down since 2022-01-26 14:14:23 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-189338466808584.xlsxls 59cb2552a34b231acb92fcee121b13d662ca7f0049a70aae86fe312270f548e5Virustotal results 15.25% SilentBuilder
2022-01-181988368443495412.xlsxls 32151a8459b973e9f407a6baf3722a9a1eb6fb27a7db9f9693fc033b64e30219n/a Heodo
2022-01-1829501020834685.xlsxls b463abec1dfc612e1ea59fa20ed07f468fbdc69e8694a5af639fa79435ce4f58n/aHeodo
2022-01-18444772560036309940.xlsxls 6cff0fc7ee4e1c70b0fb94ffc68d8939a2c5afc238ecaf0dc9e2a829baa2aaa9n/a SilentBuilder
2022-01-1806874735445663.xlsxls b4a49e89e7852d569ea4a0d6abbfb489a53b392e38fb16270343b54b2cc34b00n/a SilentBuilder
2022-01-1803006438276.xlsxls 96fb18491f6cf868e63171c4ba461b95b4b74d39b1ce4ea5e4e96373f97dde26n/a Heodo
2022-01-188555216181926.xlsxls 35da04ff2a62f8c0275a0e10151c69d9cfd7fd35dfc2ef154105492a517023d3n/a Heodo
2022-01-186143489672089467.xlsxls c1a761edd3badd0226e48b8622372de2feddd9d4ced41445685022600816aa7cn/a Heodo
2022-01-18207102806016.xlsxls 0462fb1b5a8a7784bb9b1dc90185c6b031d6dbc1ca9256bc59a34bab1c87ab49n/a SilentBuilder
2022-01-185323624085.xlsxls fef50521b3110b6efcd1210d87cffcc0912c24b496de185199e0ccd5b5a5c88en/a SilentBuilder
2022-01-1816642086362999443.xlsxls 272eb969b7ec9701081101f3a3cc5c1f30907a1b1c46700c2bca288edc9dc15cn/a SilentBuilder
2022-01-1836194176036246160.xlsxls 14e06e9395a20e63635c321d4e8f23e03da439bfd81766dab0a621ec1c4627aen/a SilentBuilder
2022-01-18317896700403593935.xlsxls 32eaa4ec7dce492883fce25e20778b8c6b36c2d269d3e55f713977f4ab0618b8n/a SilentBuilder
2022-01-1861444146039.xlsxls 909cae6e044629c7d0356bc96ced029549d3a1572031da350ee6b96489664f31n/a SilentBuilder
2022-01-18960805723592186148.xlsxls e07cb07d8a2b296d0f506a805e5721233820e0f8d4c9d552940f71fca7be7a8cn/a SilentBuilder
2022-01-1895714818298.xlsxls 78edafc9ef5c586ac250ab33c4670eb0777e862160498429f24acbb551b6f3e4n/a Heodo
2022-01-1877806363621.xlsxls eb7193559a0f423ea0f4c9d50884ff6e053a6cd4b1a81563ac619e72595779ecn/a SilentBuilder
2022-01-186505576461365840960.xlsxls cce8350caeca1753a8904e4cbaaf763ceb8eac0445b3235b74a9635727d39118n/a SilentBuilder
2022-01-18315584146082828.xlsxls 6627edac0e7bcc8f7615afe466232eeb380497a02666fed395e330d866dba379n/a SilentBuilder
2022-01-1819903249450.xlsxls 92bf6d722708e0e9428275c7d0789a52e3fefca383f020e0b8a9cf32e01fb954Virustotal results 16.95%Heodo
2022-01-1861334904212119303.xlsxls 853bf53e1de361a8c42c16b3a74dd673f990ca41f7f540ab98004a9a39e60725n/a SilentBuilder
2022-01-186071854130564093407.xlsxls 321d80f76297387803acdb4fd4e6a4dc6073d515955445752390767e95884b67n/a SilentBuilder
2022-01-185114924231044937.xlsxls b933c6fc1ce4b9df0d65fae6724a3053c183cbdf921053873252181bf50ed7a0n/aSilentBuilder
2022-01-186041869071827610244.xlsxls 6d894e2cd1eaad5f13a55f94de79b6dc01a1f37c48b884d488e46003c054eb8bn/a Heodo
2022-01-17275198731500383926.xlsxls b9cf7499338b7ce6d879b0093cddd093f329e54f080335bc602f3b30f055978an/a SilentBuilder
2022-01-17536248581404.xlsxls d90276f1e57f91966cccef797f36ba18dfdc19cf92a4505d0f59f2421f4eb2ban/aSilentBuilder
2022-01-1748213865477.xlsxls 6c45d08768b929c1e9e51c06e8e11e0f679c9a66a33415a427417ee1a3391ee0n/a Heodo
2022-01-17250366631654.xlsxls 24c794c4bff6d31e618de4a6fab59f41d7f55dc7cfaaf520728bdaa54cd4c0d3n/a SilentBuilder
2022-01-1705879853987.xlsxls 63ca712aa3ded137254262b9946785369c094b3e58b186e4ddaf34ba8b5d9e85n/aHeodo
2022-01-1736150417397919381398.xlsxls 60bfb92cf2f86b683b04d1917c4eccb0529dd8c401d77e0aeef0793e82f78717n/aSilentBuilder
2022-01-1797_972343.xlsxls dbb52b7d676d81751c83f7d43e59bd1e90425b2c2abc11cd6af1dd99199ed27dVirustotal results 20.34% Heodo
2022-01-17383263-68013088.xlsxls 517f2f449191f150f1ec1c0a79f2a34522586643b087148b5066451744bf20c5Virustotal results 18.97% SilentBuilder
2022-01-171630-32.xlsxls 38e5a716ce7bad027b111da8a3c279340203016b07bea370d80a20554eb18930n/a SilentBuilder
2022-01-170692BRJRSSUYSM_31152.xlsxls 79898684a6ed1b1f8c85e4e22f8b69099e0db3e80f1776656b5cc9d6d2022317n/a Heodo