URLhaus Database

You are currently viewing the URLhaus database entry for http://fkl.co.ke/wp-content/Elw3kPvOsZxM5/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120075
URL: http://fkl.co.ke/wp-content/Elw3kPvOsZxM5/?i=1
URL Status:Offline
Host: fkl.co.ke
Date added:2022-03-29 16:42:12 UTC
Last online:2022-05-03 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-05-03 11:08:05 UTC to abuse{at}contabo[dot]de)
Takedown time:1 month, 5 days, 5 hours, 45 minutes Bad (down since 2022-05-03 22:28:22 UTC)
Tags:emotet link heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-019827882191.xlsxls 62aa0bc0617f8f40908642b1e9b933ef99c9b9a46e7fd061ad689eff28a438faVirustotal results 56.67% SilentBuilder
2022-03-2994057321582.xlsxls cc266b9401d5c5d656b33d57ed8d5741a00fb44191f189b3b9d47b24a7ea537cVirustotal results 23.33%SilentBuilder
2022-03-291958180614.xlsxls f65a94d6277859d9a378a87196fb29020f43daa4f319b0e64d292a3d15fc8b9an/a SilentBuilder
2022-03-291046375262005.xlsxls c52e93e91b5d59d300c8514569b22a800531880de8cf3da12f3bf4166ebb3781Virustotal results 23.73%Heodo
2022-03-29186054013330276154.xlsxls c92ded7a25787ebf85924eaa3bcda461a2f4bcd31f482604e652d7334645fe1dn/a Heodo
2022-03-2940272398528.xlsxls 82949dfed8639199d9a4ee44fdd0f4e946c8636cbc904cdd5dc80f5ad1035been/aSilentBuilder
2022-03-293784142222723078194.xlsxls 23f8a8f49c3c031d30875fae0ca861f77ca7de37772390ea7645e05f5eb02cban/aSilentBuilder
2022-03-2923814839106702242037.xlsxls 902afb7f03df7e3f3edd6d2d4caa7a2ec9530afd4f2a720d9fe66a89b30b5970Virustotal results 23.33%SilentBuilder