URLhaus Database

You are currently viewing the URLhaus database entry for http://www.dzshswkj.com/wp-includes/Ochtwmy2PdcthVMR2Ls1/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1987416
URL: http://www.dzshswkj.com/wp-includes/Ochtwmy2PdcthVMR2Ls1/?i=1
URL Status:Offline
Host: www.dzshswkj.com
Date added:2022-01-18 20:41:07 UTC
Last online:2022-01-22 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-18 20:42:07 UTC to adrianlampowerline{at}gmail[dot]com)
Takedown time:3 days, 12 hours, 15 minutes Bad (down since 2022-01-22 08:57:34 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-193140385150805.xlsxls 4f48ef3036b8e2b724cbf9ec618f35baf7cb5e2017dc5fae4825659a28b58e68n/aSilentBuilder
2022-01-19547030476089097.xlsxls f364484e6d3e00f20019e36759be54c6c36fab26ca0d5dbe5819354754423a1cn/a Heodo
2022-01-19865537745092833865.xlsxls 2af6631e3481f468b1b17c3008374c23eff67a9f139e56ecc0bb9a0a34016048n/a Heodo
2022-01-1905376862187.xlsxls 0bced3cd2e9c1e23162ba0e5e2ccc316b26f399a22c93a5d2b026017790db3fen/a Heodo
2022-01-192884175239489.xlsxls a5d921070dd610f17b5c5922595511d63385bd7b99623f64f8ac7a0e457ab651n/a Heodo
2022-01-192131929809295.xlsxls fa118d305bad13e6c33a570a4bcd6159971ca1c5c3cf06eb7c8a5612e0d42aafn/a Heodo
2022-01-1939933790722458647307.xlsxls cff13f579e3598d9be5b751b75baf9fe837772239567fd22224bce3c6e99e1d0n/a Heodo
2022-01-1928766168420556853.xlsxls 54c4606892b1fede80e10591041b980262e6a780b2017de3ce6779d96d862a44n/aSilentBuilder
2022-01-19794277392769898578.xlsxls ed228873fb44f8cc68edada7c0687dfda287a3ae45fb0c0cb6cf8a58bb2487fcn/a Heodo
2022-01-194165655799.xlsxls 5c8cb7136b7f89772e79c0a2f6ead69434dbd7cd66ed030ca620de279c9b20a2Virustotal results 18.64%Heodo
2022-01-1938995999271155684.xlsxls d26f4a2809e92686fcb04d7e6662638fb1da0e2e7d7dd7057ef7931d1c36f4d3n/aHeodo
2022-01-19638808341180931856.xlsxls fa264c33403e70b02a4aa9feedf6328187ad3e3ff96e4b6d3f60dda60f5658f1n/a Heodo
2022-01-194802484046900162647.xlsxls 2973cc99c73795a2e3a00ef11ea792c3800f933fc073fe670d2907261f6c965cVirustotal results 18.64% Heodo
2022-01-197999938236083734.xlsxls 14817a3b02e6cb0a22fd6b251c612d2f21ba516c03224741e3ddc24755c424deVirustotal results 17.24%Heodo
2022-01-1997944253100389352.xlsxls 536fe29b4002bc97dbdb4f89a409168dd8f4166ef7a9d857252fd6e82be07950n/a Heodo
2022-01-199010846745821441.xlsxls c90e7d5d7b914e154dba5a9acde682aea9d957f777039a2eb165926dae35ac35n/a Heodo
2022-01-1908476394497089377439.xlsxls 44da779f7768dcf98274fb702fc93b89b7c674a2de24c2547f3a765663092d4cn/a Heodo
2022-01-19045431564013692002.xlsxls b8e79d6d4ce2e23e9b126c3397150be331952bae520caad6039e7dfd048c83f3n/a Heodo
2022-01-19770823960807246.xlsxls 06f81a0439de4a88bddf3371586a0d0594bfb213bb35e9b00f300d012e4e2691n/a Heodo
2022-01-1915948915640.xlsxls 2ead439d10213f8992ba0fa9c5a4ad9ef3fa50bf9b2ba0b7aa2ddd01a4e8306fn/a Heodo
2022-01-19215121939470148.xlsxls 4ea8a2a5f986391336015695a1f48749ea0956a8874d8ffe17cc4b6c0865c9fan/a Heodo
2022-01-1968103277783088.xlsxls 08326159f288918480978f4ca2d0a705037a18c23e58f779f9bb3bd9fdde6d75n/a SilentBuilder
2022-01-197084909315568707175.xlsxls e65457b2422f5bf91f36b2f1a6d12469325b7b580d3d07262777b764230414f0n/a Heodo
2022-01-196252873711.xlsxls 45436614d9baa751a6da8b87c9736389801dd8daab1a8f82d73aa96f644da316n/a Heodo
2022-01-197488275193872132560.xlsxls 4cd7a9573d00e7cf41a66b48f93031073ed5751a546dd851d52e805248aa3972Virustotal results 20.34%Heodo
2022-01-1919569647959.xlsxls b5ca16a64ab14a0b55fc7b71a1591ecbf68a94fa5a2c2d623ee21eb29091df25n/a Heodo
2022-01-1984186559026467219739.xlsxls 3340c74a1202b3e5f9516584a312c057b828436c35a06bbd7c3d0916e9a85289n/a Heodo
2022-01-197495138354563.xlsxls f019fca804432459a70c27b9361be7db78f4dcb3754485872c11fdfb1da20e8an/a Heodo
2022-01-1937348647122183807.xlsxls 76faa078d1f1713f316cf3d152958b0db77d8e9255dd084d902b460fb3ea97cbn/aHeodo
2022-01-19586416655633692241.xlsxls 0c4b8e3f9f33c533fb5f6f6aff0802f3fe3f9c0eaeb8bdbf82687c98c999e3ben/a SilentBuilder
2022-01-1980864883382.xlsxls 80eee1c94351d2cf598dc0b19d25ae8ce3898e3420bbb20c67a6e2e09a4a740bVirustotal results 18.97% Heodo
2022-01-18253230596340911.xlsxls 95141c557c2da97c647844e7c27133e0f8ba49907e167088ad774ed57e950294Virustotal results 15.52%SilentBuilder
2022-01-181443792481789.xlsxls 42548ded9ad20eeaa75c1c3c3f1ac4785bc4f7047e5d96d5a020db062f55605cn/a Heodo