URLhaus Database

You are currently viewing the URLhaus database entry for http://emiber.hu/cgi-bin/6DigFER8eUkoOTiMEWVmjgiK2uwh/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120113
URL: http://emiber.hu/cgi-bin/6DigFER8eUkoOTiMEWVmjgiK2uwh/?i=1
URL Status:Offline
Host: emiber.hu
Date added:2022-03-29 17:15:05 UTC
Last online:2022-03-30 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 17:16:07 UTC to abuse{at}ezit[dot]hu)
Takedown time:21 hours, 35 minutes Good (down since 2022-03-30 14:51:30 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-302922504697.xlsxls 7597defb4baf2b0e2bac5b71f4f2cce4b215b9269a11b07be5dd44e5a750956dVirustotal results 21.67%SilentBuilder
2022-03-3024864344134480082412.xlsxls 0064a9e50d81734b02d6e46a0c7438caaac87d97c3a8d2e252d116c08094820bn/a SilentBuilder
2022-03-3094960136288497060451.xlsxls 51a8819534ed48bd71579b6e79307358b76ceaae81aafc73cbb8e8b77e977061n/a SilentBuilder
2022-03-309028904035123711176.xlsxls a4206c582c5af97000782abf9ccf8ccafa231a34f5a74ac9b534286ef656d253n/a SilentBuilder
2022-03-30105728281947340.xlsxls b1f9a8c2b79e9e80247652fcb54a87ead4d7b32c51769ae1622b94d9af3edeecn/a SilentBuilder
2022-03-30238553129707.xlsxls a1c1f7785047048e4479c915a444f098c878a44e2a4496cfb20d84d6c2b17f8bn/a SilentBuilder
2022-03-3005308837434.xlsxls f37c6c8662785514f852d04f94ac6b2217b3c5244e84dae528f13c5b8b95daecn/a SilentBuilder
2022-03-3082482704966022.xlsxls 8e9245a7ff1bf4c43cee8e3b568af8044010cbaa655b23ea98c86a5ac18ca472n/a SilentBuilder
2022-03-307054895013876.xlsxls b8d670ca1984f7ecc9e90c4bc0c4c4d96172690aead7080171735f96c11ba21fn/a SilentBuilder
2022-03-2940371934819242492927.xlsxls 3cd17e7df9642d09bd3d735e259ca8f9c4ff061f1070a601f3e638df5fbe1647n/a SilentBuilder
2022-03-29057079178676451925.xlsxls b1607ec0f6786f359c81b5a083c3ba60a429a0cc7d89c5d7613b026afa3a1651Virustotal results 21.67% SilentBuilder
2022-03-2919108277792075735518.xlsxls 877dbc6908c214d0a451b962f01dff21a6b87f149d7ddace0d2a408d39ecfd23n/a SilentBuilder
2022-03-291339554098.xlsxls 0d459aa7c1a588a576c7017f7707f991abecb6756d0575dd98a104f900218e31n/a SilentBuilder
2022-03-2928809967573.xlsxls 5facd7e6e06801b2f98d8622d9dfa7549dc7fbcc4d2f1cd957f193d81a1e7e31Virustotal results 23.33% Heodo
2022-03-2936485185863530532607.xlsxls d2d3ee44f59528659d087d1782d7d4f6c95c2c5e22fcdeb342fbfd95014f3869n/a Heodo
2022-03-296677494878642111770.xlsxls 4a1f67eac68a30b3e0d924a827eb976aebd1eca8f0cfdb68ca7d4adeb3d86abdn/a SilentBuilder
2022-03-2925561414224018601643.xlsxls 6121550710d668a4b80ca4f056d91829e4a793dc1a04fd52c9ebd937b02fb685n/aSilentBuilder
2022-03-291262061082265.xlsxls 785f830ec42e6e6de3f29b1037818fa35ba3bf5bdcc06cff94a3bc582927086cn/a SilentBuilder
2022-03-290106649397523.xlsxls 4268dc47de4d11bc5cc3876e399602c2904c5903a08e1150763c0534a38a1ffaVirustotal results 23.33% SilentBuilder