URLhaus Database

You are currently viewing the URLhaus database entry for http://demo.abmauto.kg/wp-admin/FQQ26zjQ4a7YxsZR8BdZNVaU/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1992835
URL: http://demo.abmauto.kg/wp-admin/FQQ26zjQ4a7YxsZR8BdZNVaU/?i=1
URL Status:Offline
Host: demo.abmauto.kg
Date added:2022-01-20 14:45:11 UTC
Last online:2022-01-21 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 14:46:13 UTC to adm{at}infotel[dot]kg)
Takedown time:9 hours, 38 minutes Good (down since 2022-01-21 00:24:52 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-214507859360.xlsxls af86124d12773c861ad103419ab9f04ada33b95ff6919a1a9f9c4dfe2d49131fn/aHeodo
2022-01-2030255223711306247024.xlsxls 88c13197081731462e05ef64b1c9abbdc1b85e0e573437506270137fb7b735d8Virustotal results 22.03%Heodo
2022-01-20467363577759093.xlsxls b0e176129f7c1c4ae1d31d420d8ecacaceb6c4682002848a769d98e4b0f21399n/a Heodo
2022-01-200679645217165.xlsxls 79ab6a611483efd4c9e4394ac5c6a91c458857820c4c4b9bdecf0cab92acf8f2n/a Heodo
2022-01-209654567679.xlsxls c3782f393e6dca8cbded5a7bbb73789792cd1bf807f4f71cd863b12992beda95n/aHeodo
2022-01-2085105718739269359777.xlsxls 3e36c6f45c9f9361f6c28f811cd2048a727e022281815b02c021811cab7ed01en/a Heodo
2022-01-20685593287063279448.xlsxls afc76f4aa05482102ea34e10b3d2397db55857510ce6ae3dcfe05e29cc92bde3n/a Heodo
2022-01-2060161796504197524.xlsxls 0aa692cc9abe6360ac72502a9f27fb0e3d401153dfe067524c82c56b7e5f8625n/aHeodo
2022-01-201760140872775.xlsxls 48fee052f0fa5361ddc892d4768321a00e5c80adabc60654488ea8fc1ffa135fn/aHeodo
2022-01-20782647721557.xlsxls 02beb553bb2d04182e73cf34f42a9dc4c52f84b4278e97f9fbce8f111af576d3n/a Heodo
2022-01-20059769131663.xlsxls 8a07b30e84df7c4db85691e055e4f39fb78621392b7a282b3b64d13a675e14b1n/a Heodo
2022-01-20879095262972509286.xlsxls 67d5e8d2c3fcf5a17f0c7aad1b6f8963102dd00bdb62a3179605c3cdf659ab3cn/a Heodo
2022-01-20797508635192.xlsxls ab4456f73cd0d49bd6c2dc5553a33ff128bc765cb07cd47f8e0619d01735f966n/aHeodo
2022-01-2027056169505658904809.xlsxls caa57a0d7208775ee50b80b88384a83804e8b132229162b88db9a3a57abb7acbn/aHeodo
2022-01-20025125241838970003.xlsxls 856971479f118377817bebf83dd614799d320e1383604c67315508314529512fn/aHeodo
2022-01-204619980583.xlsxls b12e86184ea506fa554f7e29ee00586c73545c1af7f451eb98f49a2ba215b604Virustotal results 35.59% Heodo
2022-01-20667686064540.xlsxls 71218d4b13d7c5ab1cd1583b1646b4e495f88b8acedb0376a89e02a11354d674Virustotal results 24.53% Heodo
2022-01-20021915725177261410.xlsxls c1ee05cc88f49b09c9ca3620a75b0f1ca127afa63af57cc6c989d1023f30177bn/a Heodo
2022-01-2094937757006857180312.xlsxls e2f274d79ed0c5888801e6ec32ac82d1a083ee48fa511968a3fc435c1b5034den/a Heodo
2022-01-20654145791065119.xlsxls ad511015e8c542a03954c1be8721ddcce85dbe997f7b2048bc6e1b35823c5ffcn/aHeodo
2022-01-20970161811679059.xlsxls f3d56badbb8685d9a7485effcbe74ace69fc166424a4b4d7968578bee0572c1cn/a Heodo
2022-01-20828027340643.xlsxls a871770ef1ba329147828026ab5d7d1d0edf83ea93fca2bb2d0faada51cf48e1n/a Heodo
2022-01-2066945603307670910867.xlsxls d0e970149a72b878303b425cbeb058aac6d74f1b94b2c3e150e40ea7da2e9072Virustotal results 22.22% Heodo
2022-01-20844102091542284840.xlsxls 4627d88cb27d885555625326c40717630dbfc7708869fdde4d0064f2d59e5bb4n/aHeodo
2022-01-205453421256762.xlsxls e202d02eeb40c6b2bfd8da52e0297679c1a7df39592bba24d12079257a8bdf8an/aHeodo
2022-01-206906823156016159.xlsxls e19b762e560008e23a2bd5ff0e0ed710b52c528edfe995fbecb484af29f68b7bn/a SilentBuilder
2022-01-2021175415943892.xlsxls b7c12da037688c432bf94d80c88811b29b1a4d379a84ff3d6e6ac95eecf15680Virustotal results 25.86%Heodo
2022-01-2020986327645311.xlsxls a409b149beecde15bef1b05142a79f0f15a7c621cde14d9d6a5a1fb69190e01en/a Heodo
2022-01-2042407813950391835940.xlsxls 13ea178da0d9c3b5062b17551a00ac15f16a39ba4163a3be0125ad1b513d14ban/a Heodo
2022-01-204052006225507518728.xlsxls 272964689382f82969853fc649eb2e2605c2ed6922ef36baf0551f7c01f6a6e7Virustotal results 22.03%Heodo
2022-01-2005169972379792962.xlsxls 67ded9d43aaf229f196c781c89724f196e14ad0cd7aefa70ecbefa2723408560Virustotal results 45.76%Heodo
2022-01-20294530484573610383.xlsxls a33d856fbda8f1d751e05c87b2cb8fbc6cf242aec375be4393c97f1c924d40aen/a Heodo
2022-01-207257928906818.xlsxls 2bc45370dd6eed0f3059fe82bd82d8aeca954819c9ad8ea823d36a8e01c7e92cVirustotal results 37.93%Heodo
2022-01-2099294663892451.xlsxls bfb6705f630bdd22900dbc04de2805a63b70dd5b36a8985087a1d4be51308fd9n/a SilentBuilder
2022-01-2091196031556022081.xlsxls 1db2ec499c11b096c4a468a878a9e6bb791183ca2156eb2e8c233fd7b172b607n/aHeodo