URLhaus Database

You are currently viewing the URLhaus database entry for http://marjukrashed.com/wp/7Cqsmb/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1990665
URL: http://marjukrashed.com/wp/7Cqsmb/?i=1
URL Status:Offline
Host: marjukrashed.com
Date added:2022-01-19 23:17:08 UTC
Last online:2022-02-06 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-19 23:23:22 UTC to abuse{at}multacom[dot]com)
Takedown time:17 days, 15 hours, 43 minutes Bad (down since 2022-02-06 15:07:06 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-205951196172083.xlsxls a1d4e9c497ec94e9c1182741b7096c47396c0057014747c17e618e82538eae72Virustotal results 17.31%Heodo
2022-01-20736759193595642.xlsxls ceafd90b9d8a1fa4ba9b8f81f1c3b138570c8768b75ac1ef0d3bb126cc6d497cn/aHeodo
2022-01-2099917514515674881.xlsxls ef091c8fd3da5e55d7349f328528de0c8efbadff875a3a2f4d07355acc5a98d9n/a Heodo
2022-01-20960478735414212.xlsxls 61e0db5d3009bfb05ae505facda062bbcf4298482ac964e9824673411461907cn/a Heodo
2022-01-20282501711056925.xlsxls 3683dfe7d6ca0aca155aef7febcaf8434fe6545ad7937b3adaa2fdb2ee22fd80Virustotal results 19.30%Heodo
2022-01-20972440949953.xlsxls ef8562b363253996a0a2f5902bafc7d8f345d05e3bef28c3791c48e10d14c78bn/a Heodo
2022-01-202204475881506539.xlsxls ecc7d67a95a0bc100a6eebc60573de7ff556da84c43137adf9b23c6fbd5fb0d7n/a Heodo
2022-01-20116382762164860866.xlsxls 1cf09e78181661d05a2e9e41e578ec23bfc41f6cad88f9cccff741d12df4c570n/a Heodo
2022-01-2065143036431737.xlsxls 93e3c367bda53786b1288bbbcf96770a8865d3b8a3132a90a33d10bc91a31009n/a Heodo
2022-01-204834217150054919.xlsxls cb2fc370e9a47d7a55ef8ba2d4752062d8580c4fa8cae3df35655bb736d041ecn/a Heodo
2022-01-20156140286071.xlsxls f43c7941272a2ffa5252dd03a62fcf67ebcedb4eeefb62b83e282df408cbd899n/a Heodo
2022-01-2070051394932.xlsxls 89ac9846e80ef313bb3b47ec5d39721a42df0322689ec11f3fddf2ade55504ccn/a Heodo
2022-01-209968411525675517.xlsxls e5cbcea06c596c35b817e23de0dd39377dd88d951c16e0ff97d2aea7aa748e38n/a Heodo
2022-01-206064007890279.xlsxls 2543badd28fc1740c4784e313fc2627c75b8ffa4ab59f5e79dd74e37973a72ccVirustotal results 20.69% Heodo
2022-01-20694743755861303.xlsxls 8abb9df7dbb7c37ef4298c320074b668493d97486fa893ed0ef7c33001f20966Virustotal results 18.18% Heodo
2022-01-2012022340443514835886.xlsxls 89919b81f47acb8c9286865537da7538d4c417e7460151d8621e09006cf9c4edn/a Heodo
2022-01-2017434232168737301.xlsxls d715a57325bd00d8e636808ccbde7de3711c27a9277c8daf9063f2aa93ee45den/a Heodo
2022-01-202464106773611.xlsxls 6c8f6e8a3a740de466e6a99291fdacf3f8e16c0b01d1063b83e1f46a57059701n/a Heodo
2022-01-2004367796489.xlsxls 705b278aadff8692a2c128dd1a898d737e72e423aac2878595046d1d72dc9a03n/a Heodo
2022-01-2021052675236.xlsxls e5286287b252f12295efe836725b8d213e3e35a8f0cc9a5d74e2251d43305908n/a Heodo
2022-01-20046211193015222549.xlsxls 166c9583cee5c1a75b37bee67af093b43a0016a26e9af41cad9029914cf2a672n/a SilentBuilder
2022-01-200332213957019648690.xlsxls 76f8c0c2b92b7b85aa7ef66bd57dc746f07630eb13fbea8ec29b5115701d68d0n/a SilentBuilder
2022-01-2065307383548485433671.xlsxls 43a573dc9dd0dc79dcf228467e8e6820f4a4f8bf344660ea43eb11bb7b3c93f7Virustotal results 21.43%Heodo
2022-01-2007006524254043.xlsxls bdc735ff6181cafca367001ce29ddc5389cfdfd6c2f12957415231a74215f525n/a Heodo
2022-01-199313543235792.xlsxls 71218d4b13d7c5ab1cd1583b1646b4e495f88b8acedb0376a89e02a11354d674n/a Heodo
2022-01-19990894063362065.xlsxls 6b3e355a49db68b7601915ef40cd22d3647bf8316e43a2ec51ee375fce85339en/a Heodo
2022-01-191826906501379991.xlsxls 1b56b512e143bf588017e0ef26bea37c85688b638e6b4aa2ca0d7a443ecf95ben/a Heodo