URLhaus Database

You are currently viewing the URLhaus database entry for http://shahnazsiddiqa.com/wp-admin/oFWNIWvM2ysjaoLP8bTv9a2R5GK/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1990726
URL: http://shahnazsiddiqa.com/wp-admin/oFWNIWvM2ysjaoLP8bTv9a2R5GK/?i=1
URL Status:Offline
Host: shahnazsiddiqa.com
Date added:2022-01-19 23:38:09 UTC
Last online:2022-01-22 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-19 23:40:35 UTC to abuse{at}cloudflare[dot]com)
Takedown time:8 days, 23 hours, 5 minutes Bad (down since 2022-01-28 22:46:18 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-2088442096362484287075.xlsxls a1d4e9c497ec94e9c1182741b7096c47396c0057014747c17e618e82538eae72Virustotal results 17.31%Heodo
2022-01-205655626729.xlsxls ceafd90b9d8a1fa4ba9b8f81f1c3b138570c8768b75ac1ef0d3bb126cc6d497cn/aHeodo
2022-01-2076330120681.xlsxls 6802d962671c5de15753c1ed53a75e0993691d66b44426226d8c24ad5b667664n/a Heodo
2022-01-200875317780025.xlsxls 61e0db5d3009bfb05ae505facda062bbcf4298482ac964e9824673411461907cn/a Heodo
2022-01-2087648532011379.xlsxls 5a1489af62963b07c39a536bcd6d0912b6e83fe7c5f14f9335660d0ec8e655ccn/a Heodo
2022-01-202926583881716.xlsxls 3683dfe7d6ca0aca155aef7febcaf8434fe6545ad7937b3adaa2fdb2ee22fd80Virustotal results 19.30%Heodo
2022-01-2093714737964784196727.xlsxls 042d4b59153d75848595e19536f77437dcb1a52e851dfa507596159c99c74adcn/a Heodo
2022-01-2079679919537116.xlsxls 7a7a59440f9c5bb479634e84bd8b2226662e847bf2e87c1d11f476fe6ac55ca2n/a Heodo
2022-01-20327230974692750871.xlsxls 93e3c367bda53786b1288bbbcf96770a8865d3b8a3132a90a33d10bc91a31009n/a Heodo
2022-01-2051942018903703460.xlsxls 1a19e1b7b3ea831480dc76486dc3692a3231826c231f08c81898d6aeb508ff71n/a Heodo
2022-01-20432759831313355.xlsxls f43c7941272a2ffa5252dd03a62fcf67ebcedb4eeefb62b83e282df408cbd899n/a Heodo
2022-01-20031402008242205193.xlsxls 5ec87a479b9e5146659d31735fb5623b0228ae859bb32ea019a465d85aa76950n/a Heodo
2022-01-20315308002616.xlsxls 980229215a4a60f739f9ef51f351e1ccdd055d509f62df8354277db46af45319n/a Heodo
2022-01-205960963373067.xlsxls 2543badd28fc1740c4784e313fc2627c75b8ffa4ab59f5e79dd74e37973a72ccVirustotal results 20.69% Heodo
2022-01-20408716852728.xlsxls f0e3c55ec4382d23917bb1166f8ee92b8bf2e9f8f07081506b47de8c14fd36b3n/a Heodo
2022-01-204660083703893329.xlsxls 89919b81f47acb8c9286865537da7538d4c417e7460151d8621e09006cf9c4edn/a Heodo
2022-01-2075355052040028136002.xlsxls d715a57325bd00d8e636808ccbde7de3711c27a9277c8daf9063f2aa93ee45den/a Heodo
2022-01-20010129022436438.xlsxls 5f02e2bb6304106673957714bf9129df79438f98759757524997f8908add231an/a SilentBuilder
2022-01-205428961912286.xlsxls e5286287b252f12295efe836725b8d213e3e35a8f0cc9a5d74e2251d43305908n/a Heodo
2022-01-206853547542932807970.xlsxls 4c3f80d1187f8c8ed466219a7ad4ff851a00a00b84dc6582253fba6415c6f97aVirustotal results 33.90%Heodo
2022-01-200327514499586.xlsxls 5d4e5e94d71f8cd829e79c8b158960ddbb53203dcb8d5228373a924964985fc2n/a SilentBuilder
2022-01-20603795644459214168.xlsxls 8bcff8d42cea9f71c7dce1e7769d1baa18cdf736b6d25c7979bc896bfce25cb5n/a Heodo
2022-01-2064949921822584280745.xlsxls 06be4ce3aeae146a062b983ce21dd42b08cba908a69958729e758bc41836735cVirustotal results 27.12%SilentBuilder
2022-01-207661169210089304.xlsxls 68fb42f41dbb58a2101bbba91af61351ddec67cbd223b8f04f4e4d6ed3cc19a9n/a Heodo
2022-01-1927891322229881.xlsxls 32f3361f02ae4615ff51402361d271dfb7aa3984755728c5aa6c854979f0e551n/aHeodo
2022-01-199837973601214102.xlsxls 40fb5cedfc1c691653fb7b94289410f9c491ddeb42ec99531aac33279bb72f50n/a Heodo