URLhaus Database

You are currently viewing the URLhaus database entry for http://dznainre.heliohost.us/cgi-bin/UtiIBg5gL7YBcrLVTKtXjoHbDEUbAV/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2119188
URL: http://dznainre.heliohost.us/cgi-bin/UtiIBg5gL7YBcrLVTKtXjoHbDEUbAV/?i=1
URL Status:Offline
Host: dznainre.heliohost.us
Date added:2022-03-29 12:30:08 UTC
Last online:2022-04-12 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 12:31:05 UTC to abuse{at}he[dot]net)
Takedown time:13 days, 18 hours, 15 minutes Bad (down since 2022-04-12 06:46:22 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-2971781540759127518549.xlsxls 396b3021587fcbf09e3f5ded6c9922f91564ea6b9bea65ff30ce0d7f1c9bfdb6n/a SilentBuilder
2022-03-292848233085.xlsxls 5378941e26ce682d3e7979a83503640db4ccde8b49fdb1b38dacebfd0f200665n/a Heodo
2022-03-2945561363808979747.xlsxls 8b374c1d932f35d409569aebfcdc8d691f79009c79916d9d794a892583968c88n/a SilentBuilder
2022-03-2999658082594112156.xlsxls f6fcd17a0f9ac625fbdc7082aaf01b5cf749e979bab76a1839c27a3fa804f2efn/aSilentBuilder
2022-03-29416413553017014122.xlsxls 4c5383ffd6ae7cdc8f45354d2dca02b8f315980d3baab72da93884ff322c55d4n/aSilentBuilder
2022-03-2959745814319486340810.xlsxls fd45dbcb4421d2e1dab4a3a89b5f3ad86804cd028f538e6b5863ed931418bfc3Virustotal results 28.33% SilentBuilder
2022-03-298703278650991057.xlsxls 2e17ea0e89889002764dc4aae016b399c71ba824d3accc5cfb2cdbcbdacbf37dVirustotal results 30.00% Heodo
2022-03-2987290568730.xlsxls 780193b1e897cc787e18fd767aef87f9c66de17516dabd1b3345feb3b032ca81Virustotal results 28.33% SilentBuilder
2022-03-29071733276061784277.xlsxls 59846e1c9e998c424dfe77213f55c164c21cadf7a9f3744d9bcfab9b5770c254Virustotal results 26.67% SilentBuilder
2022-03-2983235312433.xlsxls 69d3d7130fc1f24121d302729d41f48fb104db2cea3b86352e1c8517afbcda8eVirustotal results 26.67%SilentBuilder