URLhaus Database

You are currently viewing the URLhaus database entry for http://phatthalung.drr.go.th/content/YBG_98151568/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1984651
URL: http://phatthalung.drr.go.th/content/YBG_98151568/?i=1
URL Status:Offline
Host: phatthalung.drr.go.th
Date added:2022-01-17 21:46:06 UTC
Last online:2022-01-24 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-17 21:47:08 UTC to nip{at}symphony[dot]net[dot]th)
Takedown time:6 days, 11 hours, 29 minutes Bad (down since 2022-01-24 09:16:46 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-181028144111635.xlsxls 59cb2552a34b231acb92fcee121b13d662ca7f0049a70aae86fe312270f548e5n/a SilentBuilder
2022-01-18085938947481507201.xlsxls 42086786392d71f57268416d14275638e2955c797babcbd5ec21b7eed6703652n/a Heodo
2022-01-182460068738700775479.xlsxls b463abec1dfc612e1ea59fa20ed07f468fbdc69e8694a5af639fa79435ce4f58n/aHeodo
2022-01-183112671422.xlsxls 35be5819e56e15ca1bc78bb61ba08a38d392461405142da722d534c2f87e55f5n/a Heodo
2022-01-1867813151044.xlsxls 26b4ee804e6a317a802f1c370398c6629f516477378bf94cad94413237e05c34n/a SilentBuilder
2022-01-18488320044384.xlsxls ef7820c85bc6c3df2447132bbed914ed101aeb7baf6e6edf25026375f9df3980n/a Heodo
2022-01-1861220776703533151.xlsxls 96fb18491f6cf868e63171c4ba461b95b4b74d39b1ce4ea5e4e96373f97dde26n/a Heodo
2022-01-1844569884282902170.xlsxls ebe7c1008e98277cac317211c9fb8db1371f256f9c344209fba11039fcfc1576n/a SilentBuilder
2022-01-1869151910739.xlsxls c1a761edd3badd0226e48b8622372de2feddd9d4ced41445685022600816aa7cn/a Heodo
2022-01-18541470811652.xlsxls f992f21f03b86aefe34db46f747ad9c063feebaac70cc1eff8cb76806aed499dn/a SilentBuilder
2022-01-18839669659204.xlsxls 0971b78a1fa100002ec0c3cd1d18af109e56369c4a52b4445f10c30ea8ade7fcn/a SilentBuilder
2022-01-180168671489529106899.xlsxls 30ec22e5f956439cc697c71a92a8f806335253f5b692b8375cb4acad148b5cd2Virustotal results 16.67%Heodo
2022-01-1886643632190.xlsxls 4ad545641ce10800bcd2a75f03ae32b78d9fce1feb504c5353da50438959e3b0n/a SilentBuilder
2022-01-18166554031085.xlsxls 14e06e9395a20e63635c321d4e8f23e03da439bfd81766dab0a621ec1c4627aen/a SilentBuilder
2022-01-18414856489531414.xlsxls 909cae6e044629c7d0356bc96ced029549d3a1572031da350ee6b96489664f31n/a SilentBuilder
2022-01-18015085880913202355.xlsxls bc1172240f277c311e80e1e9149ebab58d1870bc0a9e94f3bd898a025495be3en/a SilentBuilder
2022-01-18759667564871812.xlsxls e07cb07d8a2b296d0f506a805e5721233820e0f8d4c9d552940f71fca7be7a8cn/a SilentBuilder
2022-01-189905775153005964909.xlsxls 78edafc9ef5c586ac250ab33c4670eb0777e862160498429f24acbb551b6f3e4n/a Heodo
2022-01-183276666567797671.xlsxls eb7193559a0f423ea0f4c9d50884ff6e053a6cd4b1a81563ac619e72595779ecn/a SilentBuilder
2022-01-1835812007781715676782.xlsxls cce8350caeca1753a8904e4cbaaf763ceb8eac0445b3235b74a9635727d39118n/a SilentBuilder
2022-01-1884834272610723.xlsxls 027a72970eec77e5214269c8f79a87f5f614a1ecee11257b3feac2fbf54740f2n/a SilentBuilder
2022-01-183325924432999943636.xlsxls ba5cec050921142c70a9666d32ed2689badaae0afbf6105f2c3a570638634d84n/a SilentBuilder
2022-01-18789609306973360.xlsxls 5255b0788b382c41d46027fda6dc4e3c717a4cbc46469614299d184bf77037dfn/a SilentBuilder
2022-01-1886577874973.xlsxls 321d80f76297387803acdb4fd4e6a4dc6073d515955445752390767e95884b67n/a SilentBuilder
2022-01-18609438914549.xlsxls b933c6fc1ce4b9df0d65fae6724a3053c183cbdf921053873252181bf50ed7a0n/aSilentBuilder
2022-01-18860100153635066724.xlsxls 6d894e2cd1eaad5f13a55f94de79b6dc01a1f37c48b884d488e46003c054eb8bn/a Heodo
2022-01-1726261393624679331592.xlsxls 6c42a94654de5ebe226d285c0ad13e26b01ba97ec5f8faf8e2fb9411a2fc1380n/a Heodo
2022-01-1747561049733.xlsxls d90276f1e57f91966cccef797f36ba18dfdc19cf92a4505d0f59f2421f4eb2ban/aSilentBuilder
2022-01-1764791725423.xlsxls 6c45d08768b929c1e9e51c06e8e11e0f679c9a66a33415a427417ee1a3391ee0n/a Heodo
2022-01-1787223506547897.xlsxls 63ca712aa3ded137254262b9946785369c094b3e58b186e4ddaf34ba8b5d9e85n/aHeodo
2022-01-1703881226862.xlsxls f6c6e2de6c48ffc623320a3b19ef24f8dc009d55b9d388b58847ef5008962cc3Virustotal results 16.67%SilentBuilder
2022-01-17BGK_679493.xlsxls 9d3854a143ef21ea2f229b04928a70a0bb2f546162e2eae563243d867e00d1cen/a SilentBuilder
2022-01-1714298631-67236.xlsxls 8ec79669414afa81c586c25f9508a0e51e77a474b567e19fbc426d33f324d1edVirustotal results 20.69%SilentBuilder
2022-01-17YBG_98151568.xlsxls 8976395bbc9ade87e7ecaf509860c9a460299dba5418b0c536818a7d14d5941fVirustotal results 20.34% SilentBuilder