URLhaus Database

You are currently viewing the URLhaus database entry for http://senior.tims.se/-/6s/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1986118
URL: http://senior.tims.se/-/6s/?i=1
URL Status:Offline
Host: senior.tims.se
Date added:2022-01-18 10:54:04 UTC
Last online:2023-02-12 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-18 10:55:11 UTC to abuse{at}glesys[dot]se)
Takedown time:1 year, 1 month, 0 days, 12 hours, 6 minutes Bad (down since 2023-02-12 23:02:05 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1860342958323219763255.xlsxls 95141c557c2da97c647844e7c27133e0f8ba49907e167088ad774ed57e950294n/aSilentBuilder
2022-01-188620971581.xlsxls e944c07dcd112199b08ae1650f64104edba74b93d20e88a5b51e9869c5d43419n/a Heodo
2022-01-187115435618753347246.xlsxls ab1cfc5403e7fd780f3dade25696cc27faeb1bee71ec075940c364687c539e68n/aHeodo
2022-01-1879537377436733606079.xlsxls 8524d24ea83c0c48cc594f6b89dd199bbcb2b779386e8c574215517d08fea129Virustotal results 15.25%Heodo
2022-01-184676431343.xlsxls 81160f192650a9729f0015a0c97d664f747f4bd3b7c6bea6aab0b80d768f547aVirustotal results 15.25% Heodo
2022-01-182398080417527698826.xlsxls db3cdb2ac31dead6ed8c92e15387433f9d1f1e22bced252500894becaf2f2cb5n/a Heodo
2022-01-18533160182801209940.xlsxls 33c979f1db0c6fc341c654586b28b011a8b600a9804b0911fabd3b42efff8e0bVirustotal results 13.56% Heodo
2022-01-1876308265565003.xlsxls 72c86aa317ab7faa997935b084336233629d3bfd686c0d3b187d9b3817db2219n/a Heodo
2022-01-180845750342268800.xlsxls 6978c9aa20b2ed1411f6ca8336985dd7d75f115d5eabe77ffdb0be327b87c034Virustotal results 15.25%Heodo
2022-01-1819060930529041643130.xlsxls 1367eec432b15db18f5f4befa4afeea747701953763371f44fe7a0d8da18c1f4n/a Heodo
2022-01-1895204482860161219.xlsxls a0e643b5d8b85b2c75c6e3b3bdbaf33851b2fa58c6453ed5dbb436bc52b18ae9n/a Heodo
2022-01-183201776602064.xlsxls e6a55d3065b29b2634244c18d442d767860dde8b31b384e78ffa5a532f690a08n/aSilentBuilder
2022-01-183104564045458455.xlsxls 3b6d5b3f8680c389e78dea888c87cf29f4575d4ede83f4e6477c9f2d53ef9489n/aSilentBuilder
2022-01-183885458636968.xlsxls 8cf0d4b6f46140310d23a11ccea9f0432cba82e2a5f06e26dc351a849e043c53n/a SilentBuilder
2022-01-186314487927565085054.xlsxls 909fa02d99ac427b473c865825430122f3490041e04462449f8eca6d8c618798n/a Heodo
2022-01-181689620241.xlsxls b25d3be4ec17b97b858100d070469e007850b623fb60d8b27b27d214772142can/a Heodo
2022-01-1857665939196836500.xlsxls ec527c59ba416c8eda361c7069ac38bf84ee678c4b0b0c60588711a172a8d8ccVirustotal results 37.29%SilentBuilder
2022-01-1850960645028033.xlsxls b9810a3ef7017dc112cfcc5135ce71644e58ec3b5dbd596f2110d2dfb339502en/a Heodo
2022-01-18332667081163224.xlsxls 4a1f0312b2fd859957bda97b5cd2cb465ef5f9fea28798450bef3186cb1a8439n/a Heodo
2022-01-187064203796.xlsxls 722ded1cbcabef90968fdf9be67676481bac9dd847289d7f23e7625a66087723Virustotal results 27.59%SilentBuilder
2022-01-18441792909373.xlsxls 8808bca9d3fe1c1b081455e20513352831ddfbe9b65a42171b8754c2d8931e97n/a Heodo
2022-01-1808243610463589466.xlsxls 895e52ebe7c38eec3e599f404e671b1821baab608ba0050d1883f77fc229cc69n/a Heodo
2022-01-18238660453252.xlsxls ba596de99ed6b24a02b4755dbc52b034706424b3b1259ae8513c254e6afbb8ceVirustotal results 34.48% SilentBuilder
2022-01-1893276584349.xlsxls 36d5f93b026798502e5c20145292d7e369ab57aae0ec4d90f1bfb6e8141cdf7en/a SilentBuilder
2022-01-182083931310876.xlsxls 94214a74bb0158fd575aef28c69f335fd6c001fc1d1e015437e278387ef5470dn/a SilentBuilder
2022-01-186121979951538244.xlsxls ae53d5b866d7e49a50c7620025cf11206801dc9d981011954214750e10867083n/a SilentBuilder
2022-01-18880009146310134.xlsxls cef1611e425ccba10f308525ec2de771c18c7aac31a584676ad804905bacebddn/aHeodo
2022-01-18647404373154898.xlsxls 21750a942c925484d6e4e5fa44b8e8d795dcda94557066150d3f6a03e567d98en/aHeodo
2022-01-18099182351245192.xlsxls e937c306221aa2f26d68b1362e3891fcef1172812e38975ede658e723de9b631n/a Heodo
2022-01-1874789411869.xlsxls 14584a4907e1d5ffe9c5af416ba27019f14c9e19cc678b988b940a8f644e5f76n/a Heodo
2022-01-18794226988793423449.xlsxls ec6598c3ce18e5a26c6455730f05ad506f69950eb70e28f35b212b60cf071f6cVirustotal results 25.00%SilentBuilder
2022-01-189386136810174935260.xlsxls 51809fe19d5d3ab7bcd07255eabccd915611c8844b6e551c24b76fa06999664cn/aSilentBuilder
2022-01-18930631302735549870.xlsxls bee20d617796e06c9a94f62ed4d4423e7d3201bc0adf34140d198f3711dc8224n/a Heodo
2022-01-188034398513.xlsxls acdbc087b71fdb996f7a6c0121246d43150549dd914ace90e60e7b9825c7e396n/a SilentBuilder