URLhaus Database

You are currently viewing the URLhaus database entry for https://endpointwellness.com/wp-content/evXQyoa/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1989997
URL: https://endpointwellness.com/wp-content/evXQyoa/?i=1
URL Status:Offline
Host: endpointwellness.com
Date added:2022-01-19 17:31:04 UTC
Last online:2022-06-17 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-17 00:46:07 UTC to support{at}brownrice[dot]com)
Takedown time:4 months, 28 days, 7 hours, 24 minutes Bad (down since 2022-06-17 00:56:59 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-2075886483292612008921.xlsxls cb2fc370e9a47d7a55ef8ba2d4752062d8580c4fa8cae3df35655bb736d041ecVirustotal results 34.48% Heodo
2022-01-2014000753083.xlsxls ea8beb95497e04ecad5f678a9d939ed58200e80b1f79c702d777008f524a0045n/a Heodo
2022-01-208631909109.xlsxls 8abb9df7dbb7c37ef4298c320074b668493d97486fa893ed0ef7c33001f20966Virustotal results 18.18% Heodo
2022-01-208354024194326849832.xlsxls a41576e3153839b2430ea832ae6776de757113dd61ed18e873963eadb0271b5fn/a Heodo
2022-01-200489514816.xlsxls 9bfb1eee6403e410637b319fbb601585ac6858b5c169467e0cf07488ff642845n/aSilentBuilder
2022-01-19252817073924.xlsxls 23dc54d35406a09e9c7ebc21aed24c81434f62784b5a94ff6b762b39008d3a05Virustotal results 17.24%Heodo
2022-01-1979004079323441.xlsxls 9d1fb84bbcd977c6ff6a873b6485cf44af7d6562fa046b0b751dd1f6bfb2d31aVirustotal results 22.03%SilentBuilder
2022-01-1962412241362079406693.xlsxls c48a780e4664704fea5ddb053288a405a134644cd21cf1b2a21050df56d28d94Virustotal results 17.86% Heodo
2022-01-1917875892014785028.xlsxls 9395907b748740960ac38d3ba4faeb6248b7953da69f834daff192bb2ff1fff6Virustotal results 16.95%Heodo
2022-01-194017838160302.xlsxls f2c355bbcb6f7940c16e851115e7c448c06ef3e384bf0990357cca533f551973n/a Heodo
2022-01-1920754440119.xlsxls 8ba78df1fe338c2106e12977b6752294b9416a346ad1a232da92456af2997b23n/aSilentBuilder
2022-01-194399839347382032.xlsxls b7c12da037688c432bf94d80c88811b29b1a4d379a84ff3d6e6ac95eecf15680n/aHeodo
2022-01-193003658887407206466.xlsxls 80012b38504f24a7e222c6ce764cf9d1592149c95c1fe56244a3a9aed92da2a4n/a Heodo
2022-01-197175636442193402.xlsxls 851622311b069bcc58b1c69e34b1472c05e2c18ee4e0057446b4b055aeb077c2n/a Heodo
2022-01-1999034127524789.xlsxls 272964689382f82969853fc649eb2e2605c2ed6922ef36baf0551f7c01f6a6e7n/aHeodo
2022-01-194002922666062304.xlsxls 377518e1b3571bb1fc3882db72ccda8373067c31f64b66af6de824cc741e8820n/a Heodo
2022-01-1957374391952155581778.xlsxls dbb17e696e6cab92c31a2e8e002262e5381c211d44af8d6c9ee5fea7f6f3386dn/a Heodo
2022-01-19506230246261.xlsxls 5fbbbdbf225e6c32c27d238e642658cf450ec8c6ccf614005666b3b2bdc5db6cn/a SilentBuilder
2022-01-190523237967970033509.xlsxls 9d5d0556d9deed253f2b65fc3564578f14916269d9c53359fc4110c8ab1219bbVirustotal results 18.64% Heodo