URLhaus Database

You are currently viewing the URLhaus database entry for https://wordpress05.aftershipdemo.com/w4gfdi/F6xWA3/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1989868
URL: https://wordpress05.aftershipdemo.com/w4gfdi/F6xWA3/?i=1
URL Status:Offline
Host: wordpress05.aftershipdemo.com
Date added:2022-01-19 16:34:05 UTC
Last online:2023-01-21 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-19 16:35:48 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:1 year, 0 month, 6 days, 17 hours, 38 minutes Bad (down since 2023-01-21 10:13:52 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-207206196647010622105.xlsxls a1d4e9c497ec94e9c1182741b7096c47396c0057014747c17e618e82538eae72Virustotal results 17.31%Heodo
2022-01-201197975495246467.xlsxls ceafd90b9d8a1fa4ba9b8f81f1c3b138570c8768b75ac1ef0d3bb126cc6d497cn/aHeodo
2022-01-2011389942948185.xlsxls ef091c8fd3da5e55d7349f328528de0c8efbadff875a3a2f4d07355acc5a98d9n/a Heodo
2022-01-20018475409569504856.xlsxls 5a1489af62963b07c39a536bcd6d0912b6e83fe7c5f14f9335660d0ec8e655ccn/a Heodo
2022-01-2039172877083.xlsxls 6b85f542b57e575c08c896ad4d70f32c8d93ed21af22407cf95e7db3005d5b60n/a Heodo
2022-01-2086435069246046276685.xlsxls ecc7d67a95a0bc100a6eebc60573de7ff556da84c43137adf9b23c6fbd5fb0d7n/a Heodo
2022-01-20667754034187.xlsxls 3a62645fb0fa509d7ef475480849b1ae216c24ae4868b71e0a9b4cb2e9deaac6n/a Heodo
2022-01-205135926554757009.xlsxls 93e3c367bda53786b1288bbbcf96770a8865d3b8a3132a90a33d10bc91a31009n/a Heodo
2022-01-209607362363547321.xlsxls 1bf2fd1660e48510cf19cfb1f9211d2af3aa71753d2e3d7dd047de4296a7f678n/a Heodo
2022-01-2002048058193554594970.xlsxls ea8beb95497e04ecad5f678a9d939ed58200e80b1f79c702d777008f524a0045n/a Heodo
2022-01-20613661686896.xlsxls 5ec87a479b9e5146659d31735fb5623b0228ae859bb32ea019a465d85aa76950n/a Heodo
2022-01-20638879409740272659.xlsxls ea79275a76b6aae0dd672f7b56b4df776d7a1aecb5304d84f2c4aafa490159a4n/a Heodo
2022-01-20105062999154619.xlsxls 2543badd28fc1740c4784e313fc2627c75b8ffa4ab59f5e79dd74e37973a72ccVirustotal results 20.69% Heodo
2022-01-2009833290591984.xlsxls 8abb9df7dbb7c37ef4298c320074b668493d97486fa893ed0ef7c33001f20966Virustotal results 18.18% Heodo
2022-01-205240457297466.xlsxls 6870a3234a064d132910bd9014704b328efd30ac8acdfda2eb5f7d8b2670674dn/a Heodo
2022-01-2014162985004838.xlsxls d715a57325bd00d8e636808ccbde7de3711c27a9277c8daf9063f2aa93ee45den/a Heodo
2022-01-2089839831956754032.xlsxls 5f02e2bb6304106673957714bf9129df79438f98759757524997f8908add231an/a SilentBuilder
2022-01-2086470448101.xlsxls e5286287b252f12295efe836725b8d213e3e35a8f0cc9a5d74e2251d43305908n/a Heodo
2022-01-2025664806723.xlsxls 5d4e5e94d71f8cd829e79c8b158960ddbb53203dcb8d5228373a924964985fc2n/a SilentBuilder
2022-01-20220942540022.xlsxls 76f8c0c2b92b7b85aa7ef66bd57dc746f07630eb13fbea8ec29b5115701d68d0n/a SilentBuilder
2022-01-2098244201944987046.xlsxls 43a573dc9dd0dc79dcf228467e8e6820f4a4f8bf344660ea43eb11bb7b3c93f7n/aHeodo
2022-01-2085949032083596671.xlsxls bdc735ff6181cafca367001ce29ddc5389cfdfd6c2f12957415231a74215f525n/a Heodo
2022-01-197469690585433402197.xlsxls 909664581c9c1270d91b217c94841e2f6035a12c5f15725c384b2fa746b0b3ddVirustotal results 27.12%Heodo
2022-01-1928361969222076795.xlsxls 4e012706695112b7e19ba7cb073f14b4858bbe382890106a21cadf220bcd050fVirustotal results 29.82%Heodo
2022-01-1957109967462279264236.xlsxls d7eb6f673e1dfe379598ee10ef05a32e82152bfe1a49aecc0cf808108cb08202Virustotal results 20.34%SilentBuilder
2022-01-195098666146.xlsxls 931c80255eb9df794e3bcf120d96baaf081417df4dbfc06a843d3999c9da8df9n/a Heodo
2022-01-19648252266125651.xlsxls 9713bd6e70b57a5f98a05f4c674192803b49850ec2f298546fc6fa8e5b473d5en/aHeodo
2022-01-193434878946673226.xlsxls 2aa03ee42002bd26f6c97cec14cf00d8f22ebafd17eb5a631214206d1d33f640n/a Heodo
2022-01-19501544879215240698.xlsxls f364484e6d3e00f20019e36759be54c6c36fab26ca0d5dbe5819354754423a1cn/a Heodo
2022-01-1916756170419.xlsxls b24ab935f6d7ae64a036e919f70a63590db56ebd6dea1660d89827851be32e93n/a Heodo
2022-01-197933383957.xlsxls 8d8968f7c211ff540748a27df1f5561032db2d36e6cda2b8b45747aa79d0c36cn/a Heodo
2022-01-1984776541913737.xlsxls a5d921070dd610f17b5c5922595511d63385bd7b99623f64f8ac7a0e457ab651n/a Heodo
2022-01-19886713291533.xlsxls 4eaee0177f19e07e0c5e154847006790075bcf4f19b2c02ff58e5c3f64d022c7n/a Heodo
2022-01-1901039066454522.xlsxls fa118d305bad13e6c33a570a4bcd6159971ca1c5c3cf06eb7c8a5612e0d42aafn/a Heodo
2022-01-19061729962931606050.xlsxls df9d56fff17a1794b513358377fb433bc923a80bd90821696c276f1c0dc65795Virustotal results 18.64%SilentBuilder
2022-01-19156497679528113294.xlsxls 87282766839abff07098024789f18516dd558d44b54c0489163de87ca8f7a3efn/a Heodo
2022-01-191704640112.xlsxls 8d98ecd0f1108c3306f1be597968a3f9de1e00779b42b1447a58ca2dfe62753cn/a Heodo
2022-01-195646297347.xlsxls 60c25a5867273c0dd739df5c10f6807d4fbfeb7db9b8ffeb4aac58a2da169010n/aHeodo
2022-01-1962460221780374.xlsxls 6bb86a3777655a3f89ff2ad3305dfb6633f42f0f51aa815e6a7b0dc96abd6b07n/a Heodo
2022-01-196763736993.xlsxls 2e1ea41b40eda483558b5bb13f493c45a97d3c19214d9b1f11198ef25976d4f4n/aHeodo
2022-01-19165580794521613750.xlsxls b0610f43f2e9d1f158eb4dec68ce85c03890d71a428176472644163dcbf79bd6n/a Heodo
2022-01-1922874406418629.xlsxls 3683dfe7d6ca0aca155aef7febcaf8434fe6545ad7937b3adaa2fdb2ee22fd80Virustotal results 19.30%Heodo
2022-01-1943084441185104.xlsxls 32e843c35f0b39a4ff9d669a80da88322cdd4206caa24710e7fbe60db710597fn/a Heodo
2022-01-1944267726821599394858.xlsxls 86a50b1d6ea067f1e265d0c18cc987b36f191540aa23ae58f6d6678adc83c809Virustotal results 20.34% Heodo
2022-01-191741405888016.xlsxls 0d495c0696722d948b9985d4c46f507557711c4993886294d85df04a7f16d82fn/a Heodo