URLhaus Database

You are currently viewing the URLhaus database entry for http://escgayrimenkul.com/cgi-bin/FdUYrA1SAQhjYhmuce6XHiD/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2119535
URL: http://escgayrimenkul.com/cgi-bin/FdUYrA1SAQhjYhmuce6XHiD/?i=1
URL Status:Offline
Host: escgayrimenkul.com
Date added:2022-03-29 16:16:04 UTC
Last online:2022-04-02 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 16:17:04 UTC to abuse{at}bluehost[dot]com)
Takedown time:4 days, 1 hours, 4 minutes Bad (down since 2022-04-02 17:21:08 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31YW-3979203995350.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31UPH-03819997831.xlsmxlsm 97f11e4cd509aefb731d8b1a4b299c8ab4096e270f05f52d8e0eb6d2366fa501Virustotal results 38.71% Heodo
2022-03-31MQ-40691725.xlsmxlsm b034cfc88c6603dc0f5519ecba2dbba8c5382b26b8c25da23f8d40368ce8e7b5Virustotal results 33.87% Heodo
2022-03-31PCF-164683863.xlsmxlsm 6102217f21897ac71dc164ee9cb69526d874d45e748754b44309ae2b1d620880Virustotal results 40.32% Heodo
2022-03-30HCO-61202990253.xlsmxlsm 39bbb570609ea300f9d959dcf23f2161043c6dedc230f97e7eab2388db651831Virustotal results 37.10% Heodo
2022-03-30MOW-416215405124.xlsmxlsm a635724502ddf792c6bc78f232c678f559b02ac1baa5cb61f924b6d2d7aeccd0Virustotal results 39.66% Heodo
2022-03-30KP-5229896.xlsxls 31ad327541ee0627096151e901dee22241e584b78b52c17eee5a1c40a6f25490Virustotal results 25.42% SilentBuilder
2022-03-302642804857204926630.xlsxls 3493b3210a3ce325a05cc7da5ffc69d323e0a0a645d8bdfaf1016a2de52ee1b5Virustotal results 26.67% SilentBuilder
2022-03-307434191631.xlsxls e6816092d6eb5bec7ab8d5463c45994379e212925e29994c9a28a826b9f0ee92n/a SilentBuilder
2022-03-3021392352387.xlsxls d5f2d5f02c59a803bf893a762e415bbc73fb5f9bf24595dfccc683b1a6a4276cn/a SilentBuilder
2022-03-3016549269244058.xlsxls 2ba33211dbb1821465ce7c7f6a909d39aa96f40ded8ddf32f7710400542876e1n/a Heodo
2022-03-30331580684445.xlsxls bdaa48d2231c1b2486ed207cdf3114a4df1292b4defcef137daabfe6bc8070a5n/aSilentBuilder
2022-03-304186623806741278469.xlsxls e611b90b8bc15c80bb5f0082078206905163b422bcd2afba293b7c1b673d7abfn/a SilentBuilder
2022-03-3077746370997497.xlsxls 6c3c1ceff2ee60d10947b652910cfe07a5a89db87ca507ef674e29e55d58a7a6Virustotal results 23.73% SilentBuilder
2022-03-30652255264990149.xlsxls 7143175fc3b45a138566f093a1985efc2564810ae4d8b541b63ec7570f121339Virustotal results 14.89% Heodo
2022-03-30398277557755.xlsxls 061216d57577da5b9c7c95e57d26f695be2a2c7be18b94baf676719e6be08d66n/a SilentBuilder
2022-03-30052204103580914.xlsxls 1f4abd57d6305167ea781e255bf801474d77d7415dc16bfa03bcd9c6afb8e977n/a SilentBuilder
2022-03-30651992839502344198.xlsxls bfc4346b81b8cab420b161be78ca4bb5c5451f4342fe4334900389f56b8bdfccn/a SilentBuilder
2022-03-300695762825.xlsxls 2b82324426c06592a76bf7c5c8aa1dee1ce453a2735ecdb3d54a179a452bc4b9n/a SilentBuilder
2022-03-304038661178591.xlsxls 9ac2d9b09fb438722746956ab539706646f6999e4f41d608a15e5d7be2f03a6fn/a SilentBuilder
2022-03-3038714150153559606.xlsxls 4d57182432ade39fbabce23e685ff21cc1d6cf5966f8bf69e222d84d6c2176e4n/a SilentBuilder
2022-03-3055841342725855.xlsxls ed919e7317e9edb91eb7468e26cad1b08ecd328cfb669e1fb95bc2f3171b2ec8n/a SilentBuilder
2022-03-304636129398668.xlsxls fc11990e224dccd621a3e096de9d3ba9ea970ea8434a56a20ff5dbf00ac1bd90Virustotal results 25.00% SilentBuilder
2022-03-30313791149850358.xlsxls 905937ee43f2fc5221d18f42e0e1b2514bd1059016ddac70a5fe00c2092cf34an/a SilentBuilder
2022-03-304968533963.xlsxls 60c10b6c651a9926b3b26455439340955ed88932bfbe0b5908534088eeb92037n/a SilentBuilder
2022-03-3075168320273.xlsxls 562cb8922d82b50caf2e7452a6db106849432c9577c62aca3f1fd5fe90cd5308n/a SilentBuilder
2022-03-304918462463.xlsxls 5d07768d877f9d761c1fe49cf016d97f4195d6d138a24dd6d936faa5654ce764Virustotal results 23.33% SilentBuilder
2022-03-3050137899684720209244.xlsxls 9e011d77b179dc3075654faa2f570ff83e31cb879ef14891e49805831790a329Virustotal results 25.00% SilentBuilder
2022-03-304264625592.xlsxls 48de62f0ea202f9f6a63f26983545a5c456251ffe79dc9d394d8a599c8069208n/a SilentBuilder
2022-03-3097527895405588.xlsxls 795d1cb7302f7f2d226a7a50f9a1dfaca81c320aabc71f47113736bc0712a6a7n/a SilentBuilder
2022-03-3019610099471974937.xlsxls 8e9245a7ff1bf4c43cee8e3b568af8044010cbaa655b23ea98c86a5ac18ca472n/a SilentBuilder
2022-03-30104941405077404.xlsxls b8d670ca1984f7ecc9e90c4bc0c4c4d96172690aead7080171735f96c11ba21fn/a SilentBuilder
2022-03-2955278408125.xlsxls a7d32a6ad1390861e427965afd7fdab97df7cfc63b6eee10247c5e03d6e83bd1n/a SilentBuilder
2022-03-292158827860412197227.xlsxls cf32dd8b34af56ba98e8e60de33e463349578b7c5f034c6b5394c1de65d8b3bbn/a SilentBuilder
2022-03-2932646880115276215.xlsxls 3e97f09fc53890ba2d5ae2539b5c8df372ed2506ed217d05ff2cf8899d15b8e6n/aSilentBuilder
2022-03-2932846140543166274.xlsxls ed2f8d7e4690bad774218068fb147924da6ac0dc68f5329699e01075b866a262n/a SilentBuilder
2022-03-292519862682472620.xlsxls bc35c9548837ac5fe336c7e42965272c5bc571c06c2bff143deba56cfdcf8f3bn/a SilentBuilder
2022-03-293704943443.xlsxls 11e85a3bcab8d5d4f43929a8cf0783d612f20f10f38a0d84e702f110e149e565Virustotal results 23.33% SilentBuilder
2022-03-2987409012460368943.xlsxls d35e74f5e8250188d382b47a3c7a6804501f2ba7830d3ff47597207256487ee0n/a Heodo
2022-03-2963686952613699.xlsxls fed653b6d6b107a271c13302a2df3109edc3833db5d2b947f0471fe97b2a0ba0Virustotal results 22.03%Heodo
2022-03-295562695380.xlsxls 86b13aa1fccdc55676730cebc42451a0b238f65af9d6c2b47d6f91508e4b626eVirustotal results 23.33% SilentBuilder
2022-03-29575782310692.xlsxls d95969e51a63d943f36d9d5189079e570a3d5eefa5abb6c24c243ca139b5788dn/a SilentBuilder
2022-03-2930574368876053388.xlsxls 04875c7681484f64bb4bfa3232a4892a93e00c148b57a96030400caafd1168d6n/a SilentBuilder