URLhaus Database

You are currently viewing the URLhaus database entry for https://extractjob.com/0/WFuSM7F/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1985294
URL: https://extractjob.com/0/WFuSM7F/?i=1
URL Status:Offline
Host: extractjob.com
Date added:2022-01-18 04:01:09 UTC
Last online:2022-03-10 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-09 23:43:06 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 21 days, 10 hours, 28 minutes Bad (down since 2022-03-10 14:30:38 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1806662109389237.xlsxls 59cb2552a34b231acb92fcee121b13d662ca7f0049a70aae86fe312270f548e5n/a SilentBuilder
2022-01-1881020967724.xlsxls a08e21a9646ed80fd78c00c66e67a24ae0fe62a3b0e7f1f8af0de9e7e5b36fefn/a SilentBuilder
2022-01-181076625043.xlsxls e07840281d99a1827baecfff9ce0f32ad55dcf66b6bd584aef1d25400ddda547n/a SilentBuilder
2022-01-1863836474736069537574.xlsxls f992f21f03b86aefe34db46f747ad9c063feebaac70cc1eff8cb76806aed499dVirustotal results 15.52% SilentBuilder
2022-01-18557237536741.xlsxls 31e8c4a17ca7f35d0e2dbc2338d62e37859ec3b9932adf9091291faa814faad4n/a SilentBuilder
2022-01-18386809790579986.xlsxls c7b4b5f6a73a0c848b5b4de00e7255bbedd45ccfc1daad5a1a8b93cc659d4760n/a SilentBuilder
2022-01-1809444496057.xlsxls b30294b97d5518697c472c32f54448380c692fa91020b8c374e7efd91713c144n/a SilentBuilder
2022-01-188529945661676797487.xlsxls ff5e2514e41d37faf55fdda5378d9c7c9a90a30a64220771314577d1118eded9n/a SilentBuilder
2022-01-1855562986617411839067.xlsxls dab9f48f4ae76936b59d34d7be449dbc15e45ba29d6dd1a861eca70b8ab4c6d1Virustotal results 18.64% Heodo
2022-01-1893971735888259.xlsxls acbb0762700e69784c824fbdc9deb5523c234e211c001eddb2a2b5e76ef5535dn/a Heodo