URLhaus Database

You are currently viewing the URLhaus database entry for http://demo.avionxpress.com/rbud/yKtIQ6L/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1984754
URL: http://demo.avionxpress.com/rbud/yKtIQ6L/?i=1
URL Status:Offline
Host: demo.avionxpress.com
Date added:2022-01-17 22:34:05 UTC
Last online:2022-02-04 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2022-01-17 22:35:08 UTC to abuse{at}bluehost[dot]com)
Takedown time:17 days, 22 hours, 3 minutes Bad (down since 2022-02-04 20:38:30 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1859599811525.xlsxls 59cb2552a34b231acb92fcee121b13d662ca7f0049a70aae86fe312270f548e5n/a SilentBuilder
2022-01-1898671234515895707.xlsxls a08e21a9646ed80fd78c00c66e67a24ae0fe62a3b0e7f1f8af0de9e7e5b36fefn/a SilentBuilder
2022-01-181068914530635728.xlsxls e07840281d99a1827baecfff9ce0f32ad55dcf66b6bd584aef1d25400ddda547n/a SilentBuilder
2022-01-18697809785745.xlsxls 1c3a042c3ba47bd2e111d7dda2eb13f19f8cc2c5234ab67b6df5a2f9f03cce10Virustotal results 15.00% Heodo
2022-01-18156913502864462.xlsxls ea1b0624aa107219cb1815c23f3672783a7ea8361862cae5825f6d17e85f51abVirustotal results 15.00% Heodo
2022-01-187804334679215404219.xlsxls 8f14a07a593fbfffdfff975658b1ea453ffa5aafe298ec0683eef3c196f05d7an/a SilentBuilder
2022-01-1839874602343874981.xlsxls b196419aadf3452fa9c86578bbea4a49efa5759d4533b7ca253250628ca1ee55n/a SilentBuilder
2022-01-184162755510164644445.xlsxls b3ac21824299048cdffb79d0f9d2f3ee54452ffcd28cc11ad028b5b58d653a0fn/a Heodo
2022-01-186627258932.xlsxls 0376bf121022d77d6ed1356713a921f01e9fd1dfdd0445743d859417c8ea6babn/a Heodo
2022-01-18670096746765458238.xlsxls 9ddf8b254cbc30219e537c2c88b7385f7003a94dcab08cffd5ff664902d800dfn/a SilentBuilder
2022-01-187136596530358007317.xlsxls 027a72970eec77e5214269c8f79a87f5f614a1ecee11257b3feac2fbf54740f2Virustotal results 16.95% SilentBuilder
2022-01-1806240889273168376.xlsxls b813e5c13de684ace488f966ec329256bf932ce8f7c6293147a9b748a12af553n/a SilentBuilder
2022-01-188635121806331510249.xlsxls 299c796c495818b42fc31422e5b11bd88a3921cf202190ad02daa12a7c64d153n/a SilentBuilder
2022-01-180331305396628.xlsxls ee0106462202c5bfd9e469f06d86477e367e5f284d39453531ddc151043263ban/a SilentBuilder
2022-01-18724876556899.xlsxls e58d132831b7f846622d50c83a2146a1722392a8762f80899f43f6fd3596c84en/a SilentBuilder
2022-01-18159571835341148684.xlsxls 39735cfe1d359718a69fd347f5cf5b0c04eadc2858d72f2832ceb7b08d4ec142n/a SilentBuilder
2022-01-18165185751341813987.xlsxls f59bb5c3e8aff9ee229c06f1acee8c1a316b15434341f00328ecd3bf33eea7e4n/a SilentBuilder
2022-01-18339910916848879281.xlsxls d9623dcfc28b7b66de4af11ba9296e091167dbc92a8b6cf0b242daa4f145ab0fn/a SilentBuilder
2022-01-1894182548362982.xlsxls 1bca08940f987a17f56d7de9507fa25cc6fa2b863a954a0658d30cbb26284a0fn/a Heodo
2022-01-1813224780070014604648.xlsxls e91404f2f0023114d75fac9c22b509c457ead8f54865344e0974a495778e8d22n/a SilentBuilder
2022-01-186614686282612583117.xlsxls acbdaf503a907f01629f547a1258ba8bc44e750ce2140a9fd36c6bd81886cfe2n/a SilentBuilder
2022-01-18206638613218392536.xlsxls 92a09b81dd2c81db3615aa1c4d355690173e4c7e66b387f299d4d98fced8d983n/a Heodo
2022-01-18282461639986.xlsxls c38c744cda020cd48a9df0aaf7dc8794f5f9476b7379608ba51bf3b1f758e441n/a SilentBuilder
2022-01-1823538714634483.xlsxls 2455a8aa4b353ef4d347da4f2e0a46cfa8b7bb98a15ea6e472ea68051bc467d4n/a SilentBuilder
2022-01-187507309767086049.xlsxls f3c762131eb450266a4cceae9de12ddcfab2a725d5e2d31f38ebed9bc31838b2n/a Heodo
2022-01-1747386224005712042.xlsxls 175dcff2ed1a8fae2adc9fc0e93696194c51efd846df079d1da43f2e441126c7n/a Heodo
2022-01-17329236221475.xlsxls 41402a3341d4f4df51cc3812b7448eb92f9a509ddb0c79d221b55d2ce594b7den/a SilentBuilder
2022-01-1743850986091.xlsxls 8667c85c711fb03112720f6f7ed2a39ecf51b1b593cc2bd7958710551b397f99Virustotal results 16.95% SilentBuilder
2022-01-1738325340979685016.xlsxls 1bced80b0e57cdd70cc7fa696a148a7c7a7134158c4c4e263ad6199b42a3bb7fn/a Heodo
2022-01-175674131862288335917.xlsxls 4d7280e0373cd5436880ef64523e19c7cddbdea75c321dc25a5e6027c5f1c8cfn/a Heodo
2022-01-1775931925119038.xlsxls e696a6543c9045e742d9201a5f8b722b5be8d1d713fd039d7418b7e58d9717a1n/a SilentBuilder