URLhaus Database

You are currently viewing the URLhaus database entry for http://3.144.77.67/ew/CKV37742/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1984702
URL: http://3.144.77.67/ew/CKV37742/?i=1
URL Status:Offline
Host: 3.144.77.67
Date added:2022-01-17 22:04:04 UTC
Last online:2022-01-18 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2022-01-17 22:05:09 UTC to abuse{at}amazonaws[dot]com)
Takedown time:16 hours, 40 minutes Good (down since 2022-01-18 14:45:50 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-182943895239050193456.xlsxls 59cb2552a34b231acb92fcee121b13d662ca7f0049a70aae86fe312270f548e5n/a SilentBuilder
2022-01-18179631464098.xlsxls a08e21a9646ed80fd78c00c66e67a24ae0fe62a3b0e7f1f8af0de9e7e5b36fefn/a SilentBuilder
2022-01-188527233180345.xlsxls b463abec1dfc612e1ea59fa20ed07f468fbdc69e8694a5af639fa79435ce4f58n/aHeodo
2022-01-1891385579289508.xlsxls 35be5819e56e15ca1bc78bb61ba08a38d392461405142da722d534c2f87e55f5n/a Heodo
2022-01-188276793738399806.xlsxls 26b4ee804e6a317a802f1c370398c6629f516477378bf94cad94413237e05c34n/a SilentBuilder
2022-01-18927273589449240.xlsxls b4a49e89e7852d569ea4a0d6abbfb489a53b392e38fb16270343b54b2cc34b00n/a SilentBuilder
2022-01-1859319251190385295097.xlsxls a35ccc0277367ef2660f2eb7b2c5702b33e04ecabb9e9dc69f0e089d31b24abfn/a SilentBuilder
2022-01-1864077215214922318043.xlsxls ebe7c1008e98277cac317211c9fb8db1371f256f9c344209fba11039fcfc1576n/a SilentBuilder
2022-01-18361949501994.xlsxls c1a761edd3badd0226e48b8622372de2feddd9d4ced41445685022600816aa7cn/a Heodo
2022-01-1870452014027793.xlsxls 0462fb1b5a8a7784bb9b1dc90185c6b031d6dbc1ca9256bc59a34bab1c87ab49n/a SilentBuilder
2022-01-1871357407235725821474.xlsxls dab9f48f4ae76936b59d34d7be449dbc15e45ba29d6dd1a861eca70b8ab4c6d1n/a Heodo
2022-01-1818291586597.xlsxls 30ec22e5f956439cc697c71a92a8f806335253f5b692b8375cb4acad148b5cd2n/aHeodo
2022-01-1851477239858.xlsxls 14e06e9395a20e63635c321d4e8f23e03da439bfd81766dab0a621ec1c4627aen/a SilentBuilder
2022-01-183158730318.xlsxls 32eaa4ec7dce492883fce25e20778b8c6b36c2d269d3e55f713977f4ab0618b8n/a SilentBuilder
2022-01-18902393284463340763.xlsxls bc1172240f277c311e80e1e9149ebab58d1870bc0a9e94f3bd898a025495be3en/a SilentBuilder
2022-01-1830969358107874323.xlsxls 78edafc9ef5c586ac250ab33c4670eb0777e862160498429f24acbb551b6f3e4n/a Heodo
2022-01-1817387841584325455057.xlsxls e64f53d96cf4624502733103a45f67cc0635e35e624610cbec57ea9844d43203n/a Heodo
2022-01-182790366027.xlsxls 9b0a59dcae7eca85fa1088f429b85a4a491f79207a68cb7cb8925ef9d95f8ba4n/a SilentBuilder
2022-01-18637631199253501082.xlsxls 027a72970eec77e5214269c8f79a87f5f614a1ecee11257b3feac2fbf54740f2n/a SilentBuilder
2022-01-185255907487.xlsxls 6627edac0e7bcc8f7615afe466232eeb380497a02666fed395e330d866dba379n/a SilentBuilder
2022-01-1802899362671.xlsxls ba5cec050921142c70a9666d32ed2689badaae0afbf6105f2c3a570638634d84n/a SilentBuilder
2022-01-18377495310785.xlsxls 853bf53e1de361a8c42c16b3a74dd673f990ca41f7f540ab98004a9a39e60725n/a SilentBuilder
2022-01-181846564262206019560.xlsxls 321d80f76297387803acdb4fd4e6a4dc6073d515955445752390767e95884b67n/a SilentBuilder
2022-01-18061528085632.xlsxls 6e4b969192c1648bf70e8a371d404eb2c612c6d1868141bfcd15ee165bdb0715n/aSilentBuilder
2022-01-179595384197523.xlsxls b5abaa61ee5a2795808e2dc90c87c149ea7927be1431f1595fb1061e045b8657n/a SilentBuilder
2022-01-172146993705506.xlsxls b9cf7499338b7ce6d879b0093cddd093f329e54f080335bc602f3b30f055978an/a SilentBuilder
2022-01-1749569774970964.xlsxls d90276f1e57f91966cccef797f36ba18dfdc19cf92a4505d0f59f2421f4eb2ban/aSilentBuilder
2022-01-178712768533913.xlsxls 5feb30d01fb35d5fde34eb531e533bbfe6870e26612f2b397214636aed65988dn/aHeodo
2022-01-1726449358583.xlsxls 63ca712aa3ded137254262b9946785369c094b3e58b186e4ddaf34ba8b5d9e85n/aHeodo
2022-01-174464384756912370240.xlsxls 60bfb92cf2f86b683b04d1917c4eccb0529dd8c401d77e0aeef0793e82f78717n/aSilentBuilder
2022-01-17L231651.xlsxls 699405e77d9fcfb3817a230b43e7019e165529c7f4e8f6ae63f1314249344e88n/a Heodo
2022-01-17CKV37742.xlsxls 5d238f612e5268535e8d7135c599c9c144d2614962db181e4c96da8b824f7111Virustotal results 20.34% SilentBuilder