URLhaus Database

You are currently viewing the URLhaus database entry for https://onebet.co.ug/wp-content/42398854OCM_1903954/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1984727
URL: https://onebet.co.ug/wp-content/42398854OCM_1903954/?i=1
URL Status:Offline
Host: onebet.co.ug
Date added:2022-01-17 22:17:06 UTC
Last online:2022-06-29 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2022-01-17 22:18:08 UTC to abuse{at}alibaba-inc[dot]com,intl-abuse{at}list[dot]alibaba-inc[dot]com)
Takedown time:5 months, 12 days, 9 hours, 38 minutes Bad (down since 2022-06-29 07:56:11 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1897514400482462.xlsxls 2bf7a9b12869b6f85ff0f29c8500d06494577586d332fc7b32f8c12f218a1da8n/a SilentBuilder
2022-01-185979858138349.xlsxls 2113509ff71a6a0676367c8b50e39e52b82b6639a88afe1ec06942389993c44bn/a SilentBuilder
2022-01-184272189320793.xlsxls d572ba5baf8c120807fbced6c72b7da32fe4570963874f2f04fdabc560caeb2en/a SilentBuilder
2022-01-1841786777936.xlsxls 37dbee696ec38e589581d1b748765702ff2c7c810a2e5e244e3607a7e80993a0n/a SilentBuilder
2022-01-182235733904071.xlsxls ebe7c1008e98277cac317211c9fb8db1371f256f9c344209fba11039fcfc1576Virustotal results 16.95% SilentBuilder
2022-01-1878815123297727419.xlsxls 36b7b1b95cc85317f49f5a0f4b636e977a0a7534a330be0bd317d2f86edf23e3n/a SilentBuilder
2022-01-1841839339481084.xlsxls b383f0d5f5b73ff5916fa1f95a60374c30be3dded207d8fb5abf9e4d547f316dn/a Heodo
2022-01-18214325735128874.xlsxls 10d3cb55e800fbd099d09514ccfa2eb757d1d4523ce78508696052e7c5cf6d24n/a SilentBuilder
2022-01-18053631527586.xlsxls d6343441527c5d54f075865a30ee2741e2990408e8f3040de90ffe2fbda8d6dbn/a SilentBuilder
2022-01-188168071179.xlsxls e91404f2f0023114d75fac9c22b509c457ead8f54865344e0974a495778e8d22Virustotal results 18.33% SilentBuilder
2022-01-185116561058331413109.xlsxls 6d624915e5462bc3ab2100be22ddc87a74530d9fe8a151d28170ceeb6564da90n/a Heodo
2022-01-189992991019633.xlsxls 7f1401025e5fb7eff13fd2ceb9805323ac67f183a06fd97481516a01438dc8d6n/a SilentBuilder
2022-01-185877604360.xlsxls 4e59c5e250a49a3e1b4ab0856c1ffcdfe541d7533ae31d22aed84ea3e4aa5c6cn/a SilentBuilder
2022-01-186511367044084.xlsxls c61718c0dc7f0d5c5f66455826fd222262b081893085b7a528d3217b0bc6316dn/a SilentBuilder
2022-01-18120789426683209041.xlsxls 909cae6e044629c7d0356bc96ced029549d3a1572031da350ee6b96489664f31n/a SilentBuilder
2022-01-1880744998183579674.xlsxls 7c92ba7d9752e651b0bf808e5bddbc3f107ccf9ef6ee0c272339621eb8908e04n/a Heodo
2022-01-18546028533273.xlsxls e07cb07d8a2b296d0f506a805e5721233820e0f8d4c9d552940f71fca7be7a8cn/a SilentBuilder
2022-01-18465161743960944.xlsxls e64f53d96cf4624502733103a45f67cc0635e35e624610cbec57ea9844d43203n/a Heodo
2022-01-18176246574757.xlsxls 9b0a59dcae7eca85fa1088f429b85a4a491f79207a68cb7cb8925ef9d95f8ba4n/a SilentBuilder
2022-01-183280489388417358.xlsxls e83230dd5995b3cb0477ab358fc13505cbe4ef8a103ee5eafc8763545ed64d8en/a Heodo
2022-01-1836875369303029063287.xlsxls 92bf6d722708e0e9428275c7d0789a52e3fefca383f020e0b8a9cf32e01fb954Virustotal results 16.95%Heodo
2022-01-18307308648169852307.xlsxls ba5cec050921142c70a9666d32ed2689badaae0afbf6105f2c3a570638634d84n/a SilentBuilder
2022-01-18325437708333491.xlsxls 853bf53e1de361a8c42c16b3a74dd673f990ca41f7f540ab98004a9a39e60725n/a SilentBuilder
2022-01-18923543032026467501.xlsxls ee8b7476fa35280678b3b70ee6f8142bb7945783f64da2a541c0a42e0e804506n/a Heodo
2022-01-1829279896665.xlsxls 321d80f76297387803acdb4fd4e6a4dc6073d515955445752390767e95884b67n/a SilentBuilder
2022-01-18495928233920350.xlsxls 6d894e2cd1eaad5f13a55f94de79b6dc01a1f37c48b884d488e46003c054eb8bn/a Heodo
2022-01-1764302674066473.xlsxls b5abaa61ee5a2795808e2dc90c87c149ea7927be1431f1595fb1061e045b8657n/a SilentBuilder
2022-01-1798340021163551351.xlsxls d90276f1e57f91966cccef797f36ba18dfdc19cf92a4505d0f59f2421f4eb2ban/aSilentBuilder
2022-01-1721664335687625310410.xlsxls 6c45d08768b929c1e9e51c06e8e11e0f679c9a66a33415a427417ee1a3391ee0n/a Heodo
2022-01-17238860568741144581.xlsxls 24c794c4bff6d31e618de4a6fab59f41d7f55dc7cfaaf520728bdaa54cd4c0d3n/a SilentBuilder
2022-01-1797379768297006.xlsxls 01476eaa4b0f7bdde2a764be2f017d11e0a9743bdf0447c63288607ef7437ac1n/aHeodo
2022-01-1728054520096278975.xlsxls f6c6e2de6c48ffc623320a3b19ef24f8dc009d55b9d388b58847ef5008962cc3Virustotal results 16.67%SilentBuilder
2022-01-1742398854OCM_1903954.xlsxls d9aa91dbe35dc3237e8ae898bcea021fc060c2dd41ae62ab1044eb4c47d0a1e8n/a SilentBuilder