URLhaus Database

You are currently viewing the URLhaus database entry for http://forma6.fr/cgi-bin/FFNqc6OaiS8X7IN1H52/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2119200
URL: http://forma6.fr/cgi-bin/FFNqc6OaiS8X7IN1H52/?i=1
URL Status:Offline
Host: forma6.fr
Date added:2022-03-29 12:42:04 UTC
Last online:2022-03-29 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 12:43:05 UTC to abuse{at}ovh[dot]net)
Takedown time:4 hours, 37 minutes Good (down since 2022-03-29 17:20:13 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-292756661307933233.xlsxls 3dc1ecfd1f0d9fe97274513ab0bbaf4b5447f9cc990bba9a95a6ac238116994dVirustotal results 20.34% Heodo
2022-03-298123420686092.xlsxls 63bd32a0fe469f74ded0c05b18cd562e671cf5d2655ccdd9b54ed62c92004750Virustotal results 28.81%SilentBuilder
2022-03-2932330016498.xlsxls fa0b00a97c0fcdee52edad2f04692efa11a8567946cffac17a52cfef6da485a6Virustotal results 26.67%SilentBuilder
2022-03-2958143530536.xlsxls ade8be9f42310d7208c19f38eedbbdd38a925237d349718844a036d2ebaa7af3Virustotal results 26.67%Heodo
2022-03-2915455646260.xlsxls 14e8db56fca9ef89953aa6a21f61ebbccfe2782c5fdd241c5ad63eecc3c4279en/aHeodo
2022-03-2985548513901511269.xlsxls 46692cba31025f9d807061836f0b29a018625ce3e52cbba38fd9968af6ebe6bcVirustotal results 26.67% SilentBuilder