URLhaus Database

You are currently viewing the URLhaus database entry for https://fensterfront.com/yh/WAEc5bkS938g4aAZx1U1whGaMc/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2119385
URL: https://fensterfront.com/yh/WAEc5bkS938g4aAZx1U1whGaMc/?i=1
URL Status:Offline
Host: fensterfront.com
Date added:2022-03-29 14:20:05 UTC
Last online:2022-03-30 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 14:21:06 UTC to abuse{at}hosteurope[dot]de)
Takedown time:18 hours, 38 minutes Good (down since 2022-03-30 09:00:04 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-300478001032100613555.xlsxls 4e9360135bc764d3e1c38b136a67db8939b68992f983c17c2096ee12d028b362n/a SilentBuilder
2022-03-303569740773407.xlsxls 7597defb4baf2b0e2bac5b71f4f2cce4b215b9269a11b07be5dd44e5a750956dn/aSilentBuilder
2022-03-30270174510602.xlsxls 052fbc6590f24acff458963b590eef70e2476dda44c74382ebbbc8cc3a9e9c25n/a SilentBuilder
2022-03-302974214492712.xlsxls 44d5403251abf78bcc06490d12cef37dfb9c334dea049aedafa5e6a86bbfb235n/a SilentBuilder
2022-03-305977211566850.xlsxls c7a30f982cf0763c857f2e0e5b13267783a2764655f5addb8b79305c04db0413Virustotal results 23.33% SilentBuilder
2022-03-306799875375045.xlsxls 9e567a344081987a4426f78ec523045fd89cefc8790ccd11bc7c7e84a0816144n/a SilentBuilder
2022-03-30051461326175215912.xlsxls b3f2c6b1c48d4cb99c33506b2e9be25b0039ac0ba0c9c67e0cb79790ac7ba8f6n/a 
2022-03-3061693271167903812.xlsxls a86068c11ddc91fe81492d31c721514cb80c6bb1948c7cf126fe733af7205e52Virustotal results 21.67% SilentBuilder
2022-03-3012057078153401.xlsxls 0d02c7086648aa7d020cc5a5ed181f99f3d51c2c9a2522726d0bf1cc14b9110fn/a Heodo
2022-03-296218532796467361.xlsxls b8c49a9df5c1a3bc0537ffe1119107d04df77d72c06ed2e3fa7ebd2c7ca0b584Virustotal results 23.33%SilentBuilder
2022-03-29902830137007126964.xlsxls d2c2f994b521bda48acab4fdb007d4fd5b14e1d30efd50a47348c9021992ff50n/a Heodo
2022-03-297061612792410.xlsxls a679c80a799b163cf0ad3f464c4a1bc023c7d6dd0715662da376d6260a4b9040Virustotal results 24.56% Heodo
2022-03-297751996013758.xlsxls 6e5d4d61f6b1d0d27afe34e697395676dd75e6089767b1126d340b7c343a8642n/aSilentBuilder
2022-03-2937493363091815573188.xlsxls 43fce2e605be1e82e8989d5ff11ae5a74e6feb9e3c323b672c3acac8dac661d1n/a SilentBuilder
2022-03-2916698668008279.xlsxls dba7a4b42e291b9f9fa4c9734d6671a1ebb6dda6e2bec200a0d72322ad1f37b6Virustotal results 21.67%SilentBuilder
2022-03-29779861526110166784.xlsxls 0a6154f3c866b22e26356c0459f4b0eabee2bf9a7dffa104440b5db1ea99e2f7n/a Heodo
2022-03-29641381059533610470.xlsxls 47c9e54827d5eb1bedf091b985d4c3db3dbd311b612c0a62bc274c20f46af944Virustotal results 23.33% Heodo
2022-03-2953838928539389.xlsxls 82712ef6878423d4241b9bb9d22d2c9188f6d92ba57da69b6c7da9128fd3dfe6Virustotal results 23.33% Heodo
2022-03-290414092001229.xlsxls 723395fe95e3d656d422955edae3e78b38c2665cac6e68947fcbd18817801e4dVirustotal results 23.33%SilentBuilder
2022-03-290342032630219.xlsxls d6646a94355639bf44f2e0fd0805e12c8f774cb87361d5bbc1a9f2f606c35f14n/aSilentBuilder
2022-03-29543141472903.xlsxls 81113b572a380caf1d7469e353abb8ea79ec0dfa9c19a9e4add89e0e1cb8fd50n/a SilentBuilder
2022-03-2902844490273111.xlsxls f826114223c99e0d29401b4f95bd67ff825dba627a87a19e2c69a76a93d6773eVirustotal results 26.67%Heodo