URLhaus Database

You are currently viewing the URLhaus database entry for http://samishleather.sogoflowers.com/cgi-bin/L1Q4Gpg0kngn6EKDfFnvGxyB/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1994060
URL: http://samishleather.sogoflowers.com/cgi-bin/L1Q4Gpg0kngn6EKDfFnvGxyB/?i=1
URL Status:Offline
Host: samishleather.sogoflowers.com
Date added:2022-01-20 22:39:04 UTC
Last online:2022-01-21 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 22:40:19 UTC to abuse{at}corespace[dot]com)
Takedown time:15 hours, 52 minutes Good (down since 2022-01-21 14:32:40 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-2191604375759364811865.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 36.67%Heodo
2022-01-217678729140921611750.xlsxls 3ca3bcd5771a06938cc8e8c44cd2c85b794376401b469fad7e5d4b513449fa27n/a Heodo
2022-01-2193853687413078992258.xlsxls e59173f043483afd41faf0edf28ff91047d48ddbcabe29efe43bbc7d238c9861Virustotal results 36.67% Heodo
2022-01-21652033568394.xlsxls 5a6ae409ad46c453172d047a1b1d7685cbdcc317653d90c6a968509d1c2229b6n/a Heodo
2022-01-21104764973237618.xlsxls f35abc3dbc3faa333da128234f2b7778969e1ea5f8ef088498cc8ecf325f8a9cVirustotal results 40.00% SilentBuilder
2022-01-214733315842.xlsxls fc79dd33ef2208cbe871b54938ff2ad295a34cb9a720e4995853dfed5761db18n/a SilentBuilder
2022-01-212187968418112735975.xlsxls d1f5ad731dbf6263cbcee95b142ffb0ebc190205ae58d4a4948bb3e5ad09e4bbn/a SilentBuilder
2022-01-210009635183.xlsxls ab4456f73cd0d49bd6c2dc5553a33ff128bc765cb07cd47f8e0619d01735f966Virustotal results 22.03%Heodo
2022-01-215475553296435516483.xlsxls c3496d8e7d2ffbb343cb44911bd859ceb08cbac8eb09ebfc58ce6cb1208f2d8eVirustotal results 28.00% Heodo
2022-01-2162006090453.xlsxls 6027b0c0ed3191c277bd14f9bfca0e7110c5b306dba6bdc3e5bf123d0b31e6aen/a Heodo
2022-01-219960769808.xlsxls 13c3fec523cfe8ac14a7e78a8e2ca86dfd3b8bb8447eb7e733e7b1207de5bea6Virustotal results 33.33%Heodo
2022-01-2142126081761749.xlsxls 6232ba47b182fc60d16bf5b9d41f5dc614f2f348e83414c533df7ccbfb940885Virustotal results 38.98% Heodo
2022-01-212193849954676.xlsxls fe0ea8701f0d1d1b08de951b55324c38441ca10539fdac0274a95e293448f8f3n/a Heodo
2022-01-213092411192360.xlsxls 8b24ef9d0556c1351a46d2e0eb996b21b65638c41dc79cd5b676a79bf0d18a17n/a Heodo
2022-01-21702953390441067810.xlsxls 9ad38c251b929edaf974d16b81d02e8b87ca16da14c4aa4eea44df09aa210c69n/aHeodo
2022-01-21743500987248619770.xlsxls 3b8dc8f1f75a66d545d45ee9f4160ea99cff4e8cc3f5b265ea27736a3eabf381n/a Heodo
2022-01-2194586798418915527154.xlsxls d26fa50d28f1d5fecfbd935c7c439e19ed0336097938d366f8d2cb3e8c039824n/a Heodo
2022-01-2159593910745.xlsxls 9eb1535c5aaefb0a3a2b583a4aad8ef65f55b805294dca339ab2f8e632ebffedn/a Heodo
2022-01-2135452423870.xlsxls baa950d432aeb1593d886ae1afff9dbc40b6be9828af26c7d3c72431f4fdafffn/aSilentBuilder
2022-01-217851865290657806.xlsxls 2cb043937c5838c3f91d3955127cc444ff420b74448d38395ab177b8369753d0n/a Heodo
2022-01-2131298497973760854.xlsxls 4c2ddd629e265246f75b3e606e6bc899afb3c82020fc9a8f440e7793d6fed047n/a Heodo
2022-01-21502013330708.xlsxls c853e3e650463ca03b11d37a51d45c21e90abb85fe410073c435eba0d168d28cn/a Heodo
2022-01-210877868049831099652.xlsxls 132c3baa8263b51b4a2847b2cd87c504be97ca43a01155b688d12d538c8ba7ccn/a Heodo
2022-01-215285827180146727468.xlsxls 1b6134b3db142025a7ebff094a48928647019264965031e089063502561e7ca5n/a Heodo
2022-01-21315101155566562.xlsxls e57baf9289180802e131633ce599fd55a0a67db3423c45d62f4a88fbf94a0874Virustotal results 18.87% Heodo
2022-01-21238715479124558.xlsxls 46e07bbc26b054bd482b53d0528f74edc997f805951abdafb92a26dc38b7bf64n/a Heodo
2022-01-218789561365384143.xlsxls cb72aea24f710a0d9b643de1e759ace18205bc20aa8aa7a91ecf20e556cad41fn/a Heodo
2022-01-21294254476248963057.xlsxls 561f1541d1ce60dd8a10c61c54f99d83e67ed86b0f645a6e564a99baa08f56b3n/a Heodo
2022-01-205008247113339184.xlsxls 2181997083632b17484474d7152e18c8a65175b823c871b164d15d2e20a8ae16Virustotal results 22.03%SilentBuilder
2022-01-202186324695.xlsxls 39123bd1932920eca6749593bee628c405f8bb88114d8647a5d9db8b5914f46cn/a Heodo
2022-01-206421831129441810741.xlsxls 79ab6a611483efd4c9e4394ac5c6a91c458857820c4c4b9bdecf0cab92acf8f2n/a Heodo
2022-01-20692990068068350.xlsxls 1aa1e797bd106f28bc73e4a09bd4d3eb7a13943ef42f06bda76c41fbca54d0beVirustotal results 22.03%Heodo
2022-01-2094200519775.xlsxls a72795a18fa2b90928f307e227b1f1a57590672870b3acc9e8cb0eb4d38bdbffn/a Heodo