URLhaus Database

You are currently viewing the URLhaus database entry for https://ent.draftserver.com/cgi-bin/1gCxNRb7et7VDkrO/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2119495
URL: https://ent.draftserver.com/cgi-bin/1gCxNRb7et7VDkrO/?i=1
URL Status:Offline
Host: ent.draftserver.com
Date added:2022-03-29 15:45:06 UTC
Last online:2023-01-21 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 15:46:06 UTC to abuse{at}amazonaws[dot]com)
Takedown time:9 months, 27 days, 17 hours, 22 minutes Bad (down since 2023-01-21 09:08:23 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-30323603985382160.xlsxls 17a017e03150a780f08ebd41dde43ac2babb836c2e92674995af925cce5b19dfn/a SilentBuilder
2022-03-3031409876632.xlsxls 1368718563ca6d717e28a11f2ed560ef1e7ebd71253649ab0bd46a45a96e835dn/a SilentBuilder
2022-03-3079212381210756457826.xlsxls 84e8a5c9e678935ebb0022e67a2160105d3f416ac8ff9118d76b0183acc1e233n/a SilentBuilder
2022-03-3090552431251485522.xlsxls 5e42f72b6f48384d2369d13cce199bc20da44c757705ba69765152d0d1d02f96n/a SilentBuilder
2022-03-300132636074.xlsxls 86e52f0a682a1df7d90d7bcd0397e524613976d02acd17e8af00191aa679645cn/a SilentBuilder
2022-03-307736244226.xlsxls 24b89cd019e6987a69e365e3f47d53dd2968bebc7d905925b81d541b0f286110n/a SilentBuilder
2022-03-307405110348976.xlsxls 2a5de4f07ce0362b1cdc10c72712206d13a61347bd8e326f37cb10f2336fd02en/a SilentBuilder
2022-03-3080937841186053.xlsxls 9f44435aee050df19b847bec6a4937cd1b45adacae6e23564b742fc03a4012b6n/a SilentBuilder
2022-03-3096576031628.xlsxls 5d07768d877f9d761c1fe49cf016d97f4195d6d138a24dd6d936faa5654ce764Virustotal results 23.33% SilentBuilder
2022-03-30672773363628847677.xlsxls 44d5403251abf78bcc06490d12cef37dfb9c334dea049aedafa5e6a86bbfb235n/a SilentBuilder
2022-03-30573116665438627.xlsxls ec2aa6f18594a4bc61f6fc977efd358ed21b613e43f91d5acd869c689c687f1dn/a SilentBuilder
2022-03-300213944356503257459.xlsxls 01409366f137f73a060ee83b1e33ce1812614f9182737ebfa8b621d931f2aef4n/a SilentBuilder
2022-03-309238301465414674323.xlsxls 119dde2b16a947658ca5ac6ba63f97a47e26b1fb1d29177c36bbd67ff0bc4252Virustotal results 21.67% Heodo
2022-03-292510900278536.xlsxls de194184575783e158c569cdb62687aa7e8fbb8472461511e2626db0430fadeaVirustotal results 23.33%SilentBuilder
2022-03-2966359064293.xlsxls c6838b4ea989471e3a9adb64996b9df81abf050a611dd96d4d2e098b4a8fc12bn/a SilentBuilder
2022-03-295836636260016737265.xlsxls f4be1e05d18e62bc58c82cac3b742f7db7f4a1f499d4a772a6e0f5b085da7d4dn/a SilentBuilder
2022-03-2943754841386190.xlsxls 3c425e75e8dd55c6300c63fe1dc1c0c60b40aa4586681c6e21d9e5c5e75a8c49Virustotal results 16.98% Heodo
2022-03-29543792186301.xlsxls 5facd7e6e06801b2f98d8622d9dfa7549dc7fbcc4d2f1cd957f193d81a1e7e31Virustotal results 23.33% Heodo
2022-03-2932206328310773.xlsxls 11e85a3bcab8d5d4f43929a8cf0783d612f20f10f38a0d84e702f110e149e565Virustotal results 23.33% SilentBuilder
2022-03-29954536511888235.xlsxls c52e93e91b5d59d300c8514569b22a800531880de8cf3da12f3bf4166ebb3781Virustotal results 23.73%Heodo
2022-03-29165318176846182.xlsxls 299eef9367c7d46794f985f1653108dff2ea664d29f31b8ba1a08c934e1d42b6Virustotal results 23.33% SilentBuilder
2022-03-29687211612820305802.xlsxls 867434fed6520d51d6ab9e462cc33d2a09e120de7603f17cb852687812ffb18fn/a SilentBuilder
2022-03-29428072456348153019.xlsxls 5bff4b82853506733c25f44c2619c4c6d8c7a828eaa9d5efb088548c4b7ef559n/a SilentBuilder
2022-03-291919472179616.xlsxls 9575e2971e7e9d0105384f20c77f085a66fe3e95903619289c697f24ab411e42Virustotal results 21.67% SilentBuilder
2022-03-298834507387558538.xlsxls 63bd32a0fe469f74ded0c05b18cd562e671cf5d2655ccdd9b54ed62c92004750Virustotal results 28.81%SilentBuilder