URLhaus Database

You are currently viewing the URLhaus database entry for http://focusmedica.in/sunpharma/s8MZd4oczl1YkEP9g/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2117930
URL: http://focusmedica.in/sunpharma/s8MZd4oczl1YkEP9g/?i=1
URL Status:Offline
Host: focusmedica.in
Date added:2022-03-28 21:42:04 UTC
Last online:2022-03-30 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003941579 created on 2022-03-28 21:43:05 UTC)
Takedown time:1 day, 21 hours, 25 minutes Poor (down since 2022-03-30 19:08:37 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-30542464330397684.xlsxls f9fb4d5914f4d35aadbdf779dafd269c3581ca7296e7d927d8acdb38b5bf5a2bn/a Heodo
2022-03-3003531531552.xlsxls ec525c39ad25d59ac4ac1f1de75dca892bfda29514701e4bf109f00894895fa5Virustotal results 26.67%Heodo
2022-03-3091424079529131.xlsxls 86fa5221f4897b379f0dc2cbdfeb1cc230c6fedcf6b9a5dcb290ec1bdc2d73dan/aSilentBuilder
2022-03-3022680706182080954491.xlsxls 4744c844f2ac3fb1a611185968f458b2563a408114caf3d89b7e36f341abc2e9Virustotal results 25.00% Heodo
2022-03-3095645908502340822.xlsxls 9c35fffa92d67bbca9eac86d6fc450530e6a190f08cd5234dda6a159c4b699ccn/a SilentBuilder
2022-03-30795482087927847.xlsxls 48d2c47b01e93706dda133adf355e55dd92bfe38a56ccb83ad69afa8328d241fVirustotal results 27.12%Heodo
2022-03-301997601239160.xlsxls 28c1994bc596421a111c75b795d98b2192edc5aa92b6d1e3adcefd40bd9d0bdfVirustotal results 38.18% SilentBuilder
2022-03-30045252457048.xlsxls d4cfb0c8440f63b52a9a6506210f17aa2cbdeac594081472fa3f4c8440fbbc1dn/a SilentBuilder
2022-03-3037156107918995672.xlsxls d165b715b1c473df33c059be50a8eec754b9dc819ed59230ab9c74e352584753n/a SilentBuilder
2022-03-305554345072785957.xlsxls d589f05195ccab181fc35532443a5d6efd2d98dc867c149f4e32196a24557422n/a SilentBuilder
2022-03-303819080640.xlsxls 73a7d36de3e4f7ddc7f714ff205b0ccd1660020f04898ec79764150268cc31e5n/a SilentBuilder
2022-03-3056556246335595.xlsxls 549da6161eec4420a4332d23036934becf47e85be6387e5bbe24654e53925a8bVirustotal results 26.67% SilentBuilder
2022-03-3033359793552.xlsxls 9822c8d67fc1931f874b2f4e8677a6eb5492d20aa72d677e4d8309f37108668dVirustotal results 25.00% SilentBuilder
2022-03-3062218346870840615.xlsxls fc11990e224dccd621a3e096de9d3ba9ea970ea8434a56a20ff5dbf00ac1bd90Virustotal results 25.00% SilentBuilder
2022-03-3054737352179731504639.xlsxls 905937ee43f2fc5221d18f42e0e1b2514bd1059016ddac70a5fe00c2092cf34an/a SilentBuilder
2022-03-300750270162618641.xlsxls 73951101837c434dbe4bbc311301737e660feee60d02c9ad3ba352056eea6482n/a SilentBuilder
2022-03-305944897466.xlsxls 51a8819534ed48bd71579b6e79307358b76ceaae81aafc73cbb8e8b77e977061n/a SilentBuilder
2022-03-30378636600214235.xlsxls b53e7fd809f9e654c0d9d6d4f0aa797529daadc82b205bcecc3b564b45892ac4n/a SilentBuilder
2022-03-3085281562072288.xlsxls 9df1756d28521e060f7f76cec334a57f2151d5719657a1a9dd3156943ee154aan/a SilentBuilder
2022-03-308697306173156499.xlsxls 6280ad828511d4eb90c7c03d7f193d8f55f363f130e0c4aacc7481220313b846n/a SilentBuilder
2022-03-30745458850135905.xlsxls 795d1cb7302f7f2d226a7a50f9a1dfaca81c320aabc71f47113736bc0712a6a7n/a SilentBuilder
2022-03-3041603627284615187.xlsxls 805ea337e3e761a017b54b6a0dd8dacc8e1e05f20f2b5ae129fa1882c4e2ecf4Virustotal results 23.33% SilentBuilder
2022-03-307418495338176496.xlsxls e0e4aa98ec68e681a19a18f8b6f3204a4aadfc405c6a55c7134ff5574be4631an/a SilentBuilder
2022-03-29406370803851.xlsxls 1504f864ec8ac69db191c8ab3031c129d5da46f972112a592419162818f74655n/a SilentBuilder
2022-03-2920783265523180537.xlsxls d97c0128350e74d1f6eaa63deb4da2dcfc20f1f9d1f8e05a02f32edb9291290dn/a SilentBuilder
2022-03-2975031574558.xlsxls 920579a1174f8cc0b853233208e141ae75e1a36671b63026dabc79fc216f2493Virustotal results 23.33%SilentBuilder
2022-03-292774777509539176.xlsxls 24a1941927cd7d54e343a4d2eeece0639b6502fb458e92b9e9d325cb138842f6Virustotal results 21.67%SilentBuilder
2022-03-291580141992.xlsxls 295e56484dfbaf568bf0515988c02344e0b4e7112b48f6a7e20424da35e3506bn/a SilentBuilder
2022-03-29194479457127.xlsxls 97fe2205849191b3a126c348dba92d5a66dde8e1199e210629ea9a015822e363n/a SilentBuilder
2022-03-296786031443929305.xlsxls 366adc2e4e00c246f9a2a1098ec0a355f457480203eca3a7402695cef7d6bab3n/a Heodo
2022-03-290204325671938.xlsxls 6121550710d668a4b80ca4f056d91829e4a793dc1a04fd52c9ebd937b02fb685Virustotal results 21.67%SilentBuilder
2022-03-297610496440297977732.xlsxls 785f830ec42e6e6de3f29b1037818fa35ba3bf5bdcc06cff94a3bc582927086cVirustotal results 21.67% SilentBuilder
2022-03-2920923645398002269.xlsxls 5bff4b82853506733c25f44c2619c4c6d8c7a828eaa9d5efb088548c4b7ef559n/a SilentBuilder
2022-03-295935833360908056.xlsxls 9575e2971e7e9d0105384f20c77f085a66fe3e95903619289c697f24ab411e42Virustotal results 21.67% SilentBuilder
2022-03-297769897004286106744.xlsxls 16edd2b91e319c859000e5b7f14b093ef09d72a10753d1c7a3452c1a059bf2a6Virustotal results 30.00% Heodo
2022-03-2912070477099.xlsxls 061e17e2d439a3a3345414a01c54208e9ca6e4fb189542b8124668e6dd9659b7Virustotal results 27.59%SilentBuilder
2022-03-2927995113609766242108.xlsxls ea3f0d7883b89443ccdf1f44f62fcfb75923368d586f85aae7fa2aba382473bfVirustotal results 25.42% SilentBuilder
2022-03-2976745124893521.xlsxls 4c815a49ee680d680791d6675b253a0407bee7805e8d7d9a443ea0869df8097en/a SilentBuilder
2022-03-29067500504414401672.xlsxls 2ca432245e7f6a6da92cfd206e8ce83c850e547dd9e4ad200802ef66f4beb5aen/a Heodo
2022-03-29797219245437845.xlsxls 135c9b87b29ac48e7217e75ff57f2a5c3b51abb3231a86c7549dbe994760c8c7n/aSilentBuilder
2022-03-2813880116181.xlsxls 6cfd86adfe720a6432fb65748f6d9c8607f6c15fe412f73e1efd964268152bbaVirustotal results 21.67%SilentBuilder
2022-03-2839370327950914169204.xlsxls 042e7d2194275029badd62a90462947fc20c3506dca5f6074ae76ba38126b841n/a SilentBuilder
2022-03-2872268485304482.xlsxls a1647ede008bdaa0eb65a5cd6698b6d21f9dc586085bb80d33cc107881fdbf00Virustotal results 20.00%Heodo