URLhaus Database

You are currently viewing the URLhaus database entry for http://liladevelopers.in/js/qTt4eaAvhkiJatRiVyuLfQHCJjv/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1992353
URL: http://liladevelopers.in/js/qTt4eaAvhkiJatRiVyuLfQHCJjv/?i=1
URL Status:Offline
Host: liladevelopers.in
Date added:2022-01-20 12:03:05 UTC
Last online:2022-01-28 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 12:05:28 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:7 days, 17 hours, 36 minutes Bad (down since 2022-01-28 05:42:22 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-21032267400590148083.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5n/aHeodo
2022-01-219621744810981.xlsxls aba8e5024172cc0cd240eda2c379e91825cb922f0c5d56d82a560dcb15eef097n/a Heodo
2022-01-21105181344786950001.xlsxls b8fef9073b247386d53e1eba4723994cf6300b257f2b637cb1eccead6b68904cVirustotal results 40.68% Heodo
2022-01-21597428188192067931.xlsxls f35abc3dbc3faa333da128234f2b7778969e1ea5f8ef088498cc8ecf325f8a9cn/a SilentBuilder
2022-01-21009704165068611.xlsxls fc79dd33ef2208cbe871b54938ff2ad295a34cb9a720e4995853dfed5761db18n/a SilentBuilder
2022-01-2197337012837155.xlsxls 29111d8e5e8306e76660db292e7232ab39e901955014eede21e912c931a09b5fVirustotal results 35.00%Heodo
2022-01-204487018278518.xlsxls afc76f4aa05482102ea34e10b3d2397db55857510ce6ae3dcfe05e29cc92bde3Virustotal results 21.05% Heodo
2022-01-2029204454326656159.xlsxls 48fee052f0fa5361ddc892d4768321a00e5c80adabc60654488ea8fc1ffa135fVirustotal results 22.03%Heodo
2022-01-207275637073234.xlsxls 0450c09d5fe3db81273bb016f057664f805ea0dde2c1c53ad512324c191ac2a5n/a Heodo
2022-01-20830562032363262.xlsxls ab4456f73cd0d49bd6c2dc5553a33ff128bc765cb07cd47f8e0619d01735f966Virustotal results 22.03%Heodo
2022-01-2077351300977.xlsxls e33811b4dab432d10d50a8357ec88ab255590ac412e6a386ae3cee55c40df20en/a Heodo
2022-01-200455290773994885.xlsxls a36bd9b3119403daabdb28c67733184fa3071008c807a35b8bb29e76152a2cb1n/a Heodo
2022-01-202077624089317944470.xlsxls 32e843c35f0b39a4ff9d669a80da88322cdd4206caa24710e7fbe60db710597fVirustotal results 16.95% Heodo
2022-01-2048472886071724.xlsxls 22948141e8f020d01dbd92abd0eeacb3eb1d69fcf145fee4b65cdc395d309a57n/aHeodo
2022-01-20249266072259696975.xlsxls fcf5fda3ac792863157c2b73fae2d1cd422d34220bd7ad41dcf76d7102cb93d8n/a Heodo
2022-01-20387799066668.xlsxls 4a4ee3f8e96ff14a83d4f61b0c94a52dab1ed3a0bcd3d588cfc52606df19d1d4n/aHeodo
2022-01-201557184915.xlsxls 54afab7495df32a4992bbf3b49a156d0701358881ff8c996345fa6788a80d789n/a Heodo