URLhaus Database

You are currently viewing the URLhaus database entry for http://eles-tech.com/css/qkqeXqE6lo4AOVDGmqIQu5i4JKB/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2118032
URL: http://eles-tech.com/css/qkqeXqE6lo4AOVDGmqIQu5i4JKB/?i=1
URL Status:Offline
Host: eles-tech.com
Date added:2022-03-28 23:21:04 UTC
Last online:2022-04-04 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-28 23:22:07 UTC to info{at}atakteknoloji[dot]com)
Takedown time:6 days, 11 hours, 57 minutes Bad (down since 2022-04-04 11:19:54 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-30EXO-808520946.xlsmxlsm 0f0f7b2909d785721bac9e084861e0e82096d63f5a895e6b4cd3c02b490dbc9aVirustotal results 34.92% Heodo
2022-03-30XP-748962047020.xlsmxlsm 08e64e582d9d42f5f3a21eaff52bcb72b4a3abfc761561ff28f40bf937dedb2cVirustotal results 35.48% Heodo
2022-03-30POF-33944658911.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51n/a Heodo
2022-03-30CW-601467351565028.xlsxls 2fb5d6b4684b1f180fd682f92fc346420c16376d64b8b8ec6b0564247000dc58n/a SilentBuilder
2022-03-30XSJ-237653747693.xlsxls 7813b5f2ba1876b183aec911e5a55402903c7b4702fef4c3c0055557490ef04an/aSilentBuilder
2022-03-3088893622201326217.xlsxls 6edf2bbc238af34d4d9a013d6ae99ec1a1df41d15caa4bf4e90ec5fd50ac19eeVirustotal results 28.33%SilentBuilder
2022-03-300120644947785640875.xlsxls afab90f284e5f643a8fa8a6eafd154175a22394254db310f0dcddc607a5ed468Virustotal results 28.33% Heodo
2022-03-30725896598463013429.xlsxls cbe967409fa0442df555f0fbff61695f558354b193886923b01f29a6617cd9dcn/a SilentBuilder
2022-03-3075961158346951684744.xlsxls 8a6effb1430c591fa0e6e8ac6f84b1991bf8cc18f70a432ae63e6bda131914c6Virustotal results 28.33% Heodo
2022-03-303663033230854552580.xlsxls b7591b7a18cb144c1108bb4bf93c5fccf323fb6d211e1875fedca3717fdc59d9n/aHeodo
2022-03-30849478530225551375.xlsxls b2565c24c9c72461d71c25df5d6ea291c53cd27725217f8c6585653cbdf72648Virustotal results 25.00%Heodo
2022-03-3044249577183367316.xlsxls 82dd13809bbcd68f4c4cb0b98c2c979c8275fd86dfaaeb01eb3c1e17d6a3d990Virustotal results 21.67%Heodo
2022-03-30202279214982039.xlsxls 48d2c47b01e93706dda133adf355e55dd92bfe38a56ccb83ad69afa8328d241fn/aHeodo
2022-03-3031008841174474825.xlsxls fafb5b78b4090ec62a5226d6f23c69288afa050ae47b4d77365b863b0b65f704n/a Heodo
2022-03-30694158586504015006.xlsxls d2bbd8120515b265d888b7a8f53e83db7a6b22e79a65a720d69198d989b07a34n/a SilentBuilder
2022-03-3063394485077676.xlsxls d165b715b1c473df33c059be50a8eec754b9dc819ed59230ab9c74e352584753n/a SilentBuilder
2022-03-3073762314862547410576.xlsxls ead83de1e59469537742bc196a815d261330e012b2864dd56cb91f93de66a3baVirustotal results 25.00% SilentBuilder
2022-03-304263205964.xlsxls 15b8f817ad756bd04cd33d34f0a4670b25afa33c7ab59f37b322284809532d05n/a SilentBuilder
2022-03-303180814507.xlsxls 553da5e4c71464540693e53e16cdb2c9285cfe93168bcc63cddabadaef5504e5n/a SilentBuilder
2022-03-3042575641812.xlsxls 5e42f72b6f48384d2369d13cce199bc20da44c757705ba69765152d0d1d02f96n/a SilentBuilder
2022-03-3097732345422759928074.xlsxls 17ecc742902925465369b5dc8bb6c8c87d9e16a1cdde0c38c3b4264f73029cd6n/a SilentBuilder
2022-03-30113152774500436.xlsxls 905937ee43f2fc5221d18f42e0e1b2514bd1059016ddac70a5fe00c2092cf34an/a SilentBuilder
2022-03-3052847013214511.xlsxls 7597defb4baf2b0e2bac5b71f4f2cce4b215b9269a11b07be5dd44e5a750956dn/aSilentBuilder
2022-03-3020894636667570431.xlsxls 562cb8922d82b50caf2e7452a6db106849432c9577c62aca3f1fd5fe90cd5308n/a SilentBuilder
2022-03-303229773619593.xlsxls 810ab94aefd1a5dc68f1df21a77fa2a83f96cc60bb42d7887fae6c365713f2e5n/a SilentBuilder
2022-03-3003233787269113170.xlsxls 44d5403251abf78bcc06490d12cef37dfb9c334dea049aedafa5e6a86bbfb235n/a SilentBuilder
2022-03-30523133212134107915.xlsxls de1dce37963bd312b3353cd23393b5c9603ab5a2c969ac420447e9183ad18a47Virustotal results 21.67% SilentBuilder
2022-03-30036212147520439890.xlsxls d85257ca0a2f223bcc90abd52ac068212254a99602477b162b091d5a04f2d588n/a SilentBuilder
2022-03-3020877660601685.xlsxls e2e11b7c2865a2aed4a388d9144668fab90d56b091cee3cca497139a109f9c24n/a SilentBuilder
2022-03-301261698715657313.xlsxls a86068c11ddc91fe81492d31c721514cb80c6bb1948c7cf126fe733af7205e52Virustotal results 21.67% SilentBuilder
2022-03-299014000548734258460.xlsxls 5945c872c336b1839e2d24e8ade8c28cd4bfda3b45281798c978e0989334a219n/a Heodo
2022-03-296499575738036593.xlsxls 4db12a7472a2427ea88cb16a24494b46824688abd29824abffa27f9366e46f30n/a SilentBuilder
2022-03-2978429126711577.xlsxls 82fc4fee02805ea0fbd6578b5e33d809165c90f10143c644566ea6991cecc4a8Virustotal results 20.69%SilentBuilder
2022-03-29637929203469.xlsxls 6ddbab092ea3334218e1a42e8c21dacd63db67a4c382a78095e0712c06d9a667n/a SilentBuilder
2022-03-2929107816843.xlsxls d2d3ee44f59528659d087d1782d7d4f6c95c2c5e22fcdeb342fbfd95014f3869Virustotal results 23.33% Heodo
2022-03-2956451645249144839.xlsxls c52e93e91b5d59d300c8514569b22a800531880de8cf3da12f3bf4166ebb3781Virustotal results 23.73%Heodo
2022-03-295357949436088854366.xlsxls b5e1171cc46588b6ee855ab2c57f90f2889b34542621c1a7d65c5bddb449f679n/a SilentBuilder
2022-03-29979489140415650.xlsxls de0451fa84d12094775843b0424bfcc18832943128c01ba088acae9c80a402e3n/a SilentBuilder
2022-03-2917268196378553780.xlsxls d88413ed8bb6c8e22c93bbeeedcdbadc2ec6f0a39dfa83b931dd065eac775edeVirustotal results 23.33% SilentBuilder
2022-03-2903798665349645152877.xlsxls 409d6cb4ec67f0e74ec6a09036063b8203e6ecfc95d24e2518701779773b82b5n/a Heodo
2022-03-2920076960759617065.xlsxls 16edd2b91e319c859000e5b7f14b093ef09d72a10753d1c7a3452c1a059bf2a6Virustotal results 30.00% Heodo
2022-03-295587250774758635787.xlsxls 061e17e2d439a3a3345414a01c54208e9ca6e4fb189542b8124668e6dd9659b7Virustotal results 27.59%SilentBuilder
2022-03-2990624899157679800478.xlsxls b27cdd913a87253ea55001d2db3724f441cfb36c91a603982cf4c0fc7a9d3c22n/a SilentBuilder
2022-03-297173533660017.xlsxls 4c815a49ee680d680791d6675b253a0407bee7805e8d7d9a443ea0869df8097en/a SilentBuilder
2022-03-294900457286.xlsxls 5a004200cb6d06164729fd88e5f06276468288808064ce9830f2e5dad73654b5n/a SilentBuilder
2022-03-288154460879463908.xlsxls 6cfd86adfe720a6432fb65748f6d9c8607f6c15fe412f73e1efd964268152bbaVirustotal results 21.67%SilentBuilder
2022-03-28412148679326087852.xlsxls 30b98714004926df00d1c71bf7c6e5dd673fa31627f3a130bb3f31c5fe0b0118Virustotal results 22.03% SilentBuilder