URLhaus Database

You are currently viewing the URLhaus database entry for http://mail.shahnazsiddiqa.com/wp-admin/ZGNOqgXX6l/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1992904
URL: http://mail.shahnazsiddiqa.com/wp-admin/ZGNOqgXX6l/?i=1
URL Status:Offline
Host: mail.shahnazsiddiqa.com
Date added:2022-01-20 15:07:04 UTC
Last online:2022-01-22 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 15:08:11 UTC to abuse{at}cloudflare[dot]com)
Takedown time:8 days, 7 hours, 42 minutes Bad (down since 2022-01-28 22:50:40 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-2154622573768040006788.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5n/aHeodo
2022-01-2180464938383.xlsxls aba8e5024172cc0cd240eda2c379e91825cb922f0c5d56d82a560dcb15eef097n/a Heodo
2022-01-2143055843011339875478.xlsxls e59173f043483afd41faf0edf28ff91047d48ddbcabe29efe43bbc7d238c9861n/a Heodo
2022-01-214582497090800097.xlsxls f35abc3dbc3faa333da128234f2b7778969e1ea5f8ef088498cc8ecf325f8a9cVirustotal results 40.00% SilentBuilder
2022-01-2104368995070990563465.xlsxls fc79dd33ef2208cbe871b54938ff2ad295a34cb9a720e4995853dfed5761db18n/a SilentBuilder
2022-01-2155087816717959731.xlsxls 29111d8e5e8306e76660db292e7232ab39e901955014eede21e912c931a09b5fVirustotal results 35.00%Heodo
2022-01-210740648936320170740.xlsxls c3496d8e7d2ffbb343cb44911bd859ceb08cbac8eb09ebfc58ce6cb1208f2d8eVirustotal results 28.00% Heodo
2022-01-21037553448967.xlsxls a3d7cb606d8f77987119021ad7d89fac7d02668d86ff90db65c87e54a15e73fbn/a Heodo
2022-01-219561851802771047.xlsxls e06d794800a6c8e29eaee2ec0e2ccd9f60b00c7d6c9b4a80ce605a4c156f9982n/aHeodo
2022-01-21451132826875767.xlsxls 6232ba47b182fc60d16bf5b9d41f5dc614f2f348e83414c533df7ccbfb940885Virustotal results 38.98% Heodo
2022-01-215995850108738344468.xlsxls fe0ea8701f0d1d1b08de951b55324c38441ca10539fdac0274a95e293448f8f3n/a Heodo
2022-01-210118862215155.xlsxls 539a3855a176457a29262e61d738250050450a8a6adb2b1e9c8961a40a6cad57n/a Heodo
2022-01-21035627631645893409.xlsxls 9ad38c251b929edaf974d16b81d02e8b87ca16da14c4aa4eea44df09aa210c69n/aHeodo
2022-01-2155482532416407568498.xlsxls 3b8dc8f1f75a66d545d45ee9f4160ea99cff4e8cc3f5b265ea27736a3eabf381n/a Heodo
2022-01-2164860329458107.xlsxls 2847438e4b48ee5f630b8d0a3d5361bf4071aa308d8999a69cba995fa548add5n/aSilentBuilder
2022-01-21132737413931957.xlsxls 9eb1535c5aaefb0a3a2b583a4aad8ef65f55b805294dca339ab2f8e632ebffedn/a Heodo
2022-01-2157523253284917517155.xlsxls baa950d432aeb1593d886ae1afff9dbc40b6be9828af26c7d3c72431f4fdafffn/aSilentBuilder
2022-01-211803062315881638838.xlsxls 2cb043937c5838c3f91d3955127cc444ff420b74448d38395ab177b8369753d0n/a Heodo
2022-01-212913612768405.xlsxls 4c2ddd629e265246f75b3e606e6bc899afb3c82020fc9a8f440e7793d6fed047n/a Heodo
2022-01-213986295266.xlsxls c853e3e650463ca03b11d37a51d45c21e90abb85fe410073c435eba0d168d28cn/a Heodo
2022-01-2168469692593522529.xlsxls 4520398e8aeabb1aed9cd4899a2ac014545d9ad9383959288cf2470f9c1c4731n/aHeodo
2022-01-214004870171454681466.xlsxls bf377a8c8ae5170949a1ea2d2f8fb6d63a24839276a2fd63bc2a4525f1839a59Virustotal results 24.56% Heodo
2022-01-2110160093244.xlsxls e57baf9289180802e131633ce599fd55a0a67db3423c45d62f4a88fbf94a0874Virustotal results 18.87% Heodo
2022-01-218895086777657781600.xlsxls 01bab18ffb7052e8d67dc6447267ec775667a721592e609cf62dd08649d7a807n/a SilentBuilder
2022-01-2188187899901.xlsxls cb72aea24f710a0d9b643de1e759ace18205bc20aa8aa7a91ecf20e556cad41fVirustotal results 22.03% Heodo
2022-01-21690350456020378666.xlsxls 2d259bd946fb388d1a7d75d28ba591aca3377e0ca8b49e0add414fe82b76f483Virustotal results 20.34%SilentBuilder
2022-01-208565707065130652062.xlsxls 88c13197081731462e05ef64b1c9abbdc1b85e0e573437506270137fb7b735d8Virustotal results 22.03%Heodo
2022-01-20681405992853766.xlsxls b0e176129f7c1c4ae1d31d420d8ecacaceb6c4682002848a769d98e4b0f21399n/a Heodo
2022-01-203161691691003214.xlsxls 345965e8a8dc6b64c4fad5c48851aa3a2efb483d409eb259fb2ceaaec1f01dbcn/a Heodo
2022-01-207549157436321118.xlsxls 3e36c6f45c9f9361f6c28f811cd2048a727e022281815b02c021811cab7ed01en/a Heodo
2022-01-208437527665625.xlsxls 514af468cf8a54d3ba4fd08208de3119721d9a9b5e4d2c96373add4d3dd7688dn/a Heodo
2022-01-20494122788853926.xlsxls 7758c1ef7b05f4e4e7e283eda2aba34801589c1ed656610c149a5b1a1a0b7fc3Virustotal results 22.03% Heodo
2022-01-2036549459798690349220.xlsxls afc76f4aa05482102ea34e10b3d2397db55857510ce6ae3dcfe05e29cc92bde3n/a Heodo
2022-01-2052631091020332.xlsxls 48fee052f0fa5361ddc892d4768321a00e5c80adabc60654488ea8fc1ffa135fn/aHeodo
2022-01-20771853114476672086.xlsxls 26abe8e8297849c2a5721808548030b0abb405538a62e4a4d7bc0bf2a6279476n/a SilentBuilder
2022-01-206807017377321.xlsxls 6f95d343a882d6e800379be638a48804dfc956537ffcc06361e1f57fa2938808Virustotal results 22.03%Heodo
2022-01-206984288515.xlsxls ab4456f73cd0d49bd6c2dc5553a33ff128bc765cb07cd47f8e0619d01735f966Virustotal results 22.03%Heodo
2022-01-20187138438403.xlsxls e33811b4dab432d10d50a8357ec88ab255590ac412e6a386ae3cee55c40df20en/a Heodo
2022-01-2064874182418166.xlsxls caa57a0d7208775ee50b80b88384a83804e8b132229162b88db9a3a57abb7acbn/aHeodo
2022-01-205789712677169401.xlsxls b1ee7aa00b7884ed02a3f5ddc07419b6e8dd6e7382269d8cc5511f06431d5eafVirustotal results 28.81%Heodo
2022-01-20803009119897.xlsxls 4102ee23d580a34ad9a1790ea81e7d9739cae27b843165e0daa30b9450585db4Virustotal results 23.73% Heodo
2022-01-207429017546816816.xlsxls b9da67f07dffac92070453903df7e7b7ba55f0535b5c64111357c3f70d836787Virustotal results 17.24% Heodo
2022-01-208148661279371.xlsxls 23dc54d35406a09e9c7ebc21aed24c81434f62784b5a94ff6b762b39008d3a05Virustotal results 17.24%Heodo
2022-01-20071577084849823.xlsxls db6061f8252704ee6f243e9d5792be120e6743cd366b4ae8f3b56d12b00866ffn/a Heodo
2022-01-2093062409524191.xlsxls f3d56badbb8685d9a7485effcbe74ace69fc166424a4b4d7968578bee0572c1cn/a Heodo
2022-01-20690411591943393.xlsxls 40dd74fb1fba55980387dff7f457cfee8778be09fd503bc397f747bd97d82ffcn/aHeodo
2022-01-2009597821128836441.xlsxls de3619e7da8c2b8e8ac00a4de35718d5bc5b618410c3b8948c24ee2f3cbcd593Virustotal results 45.00% Heodo
2022-01-2044494970414064889.xlsxls 909664581c9c1270d91b217c94841e2f6035a12c5f15725c384b2fa746b0b3ddVirustotal results 27.12%Heodo
2022-01-209852025357.xlsxls 1406e7176ae6fb7aba0fb00e8658291ffeb38c2c9d844bdb47a8131c697342a5n/a Heodo
2022-01-20005207775137572323.xlsxls 88f602cd8f6b66886acb349720da52c3f5fdb367fe8a72f76812af27347cf32eVirustotal results 22.03%Heodo
2022-01-208717718364.xlsxls 06be4ce3aeae146a062b983ce21dd42b08cba908a69958729e758bc41836735cVirustotal results 27.12%SilentBuilder
2022-01-2097853885757679019670.xlsxls 687e234c7b54e2590520375221eec756b91e6e03b05bbb313e8765457906c707n/aHeodo
2022-01-2052644404412566837.xlsxls b7c12da037688c432bf94d80c88811b29b1a4d379a84ff3d6e6ac95eecf15680Virustotal results 25.86%Heodo
2022-01-20904240772215948.xlsxls 053c0755d6a308ffbc4afb3c5a5d38f54f8ce27e09cbdd58c8a262fd078e38f3Virustotal results 43.86% Heodo
2022-01-208853311213385259434.xlsxls 7f47c50d92a3da634e5e5810bf1d27d35cd110242f9148c1506e2da375a056e8Virustotal results 41.67% Heodo
2022-01-208260793679237283318.xlsxls d6e424ec874813f6c75832799639f11a04331f74219a8278f5a26d58282089f3Virustotal results 13.04% Heodo
2022-01-2096602886811057.xlsxls 167d9ba9d50caf33f2e4e83958b809b81e5a3f9bd5e259d2e233ab5c299afecfVirustotal results 34.48% Heodo
2022-01-20044356047430096148.xlsxls 34315a97decc512b1ee8e3f26e5f2ff6ea20bf03d6e8524b970df14e18ecfcb7Virustotal results 46.55%Heodo
2022-01-2069287062771205123509.xlsxls 6b65f37d876f38bcc12bc144f25a9674a7461b5500953b5ff8bf02186d82b3b8Virustotal results 19.30%Heodo