URLhaus Database

You are currently viewing the URLhaus database entry for http://ekinbodrum.com/css/4f8AiYrivhAG26y/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120156
URL: http://ekinbodrum.com/css/4f8AiYrivhAG26y/?i=1
URL Status:Offline
Host: ekinbodrum.com
Date added:2022-03-29 17:44:04 UTC
Last online:2022-05-14 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 17:45:06 UTC to abuse{at}hostlab[dot]com[dot]tr)
Takedown time:1 month, 15 days, 15 hours, 48 minutes Bad (down since 2022-05-14 09:33:09 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-04NTS-8972369817.xlsmunknown d6a0c64657e8ae8f3cc4f7c889bc274239350ec34d2d77e7329e41bbc456a93aVirustotal results 8.62% 
2022-04-04NTS-8972369817.xlsmunknown 0e06e6b65cb58876edb109c097794669b36079a67c95834982acd6c681b366d8n/a 
2022-03-31IF-59279030530753.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31JIY-0189420.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231Virustotal results 40.98% Heodo
2022-03-31OJ-759855137210587.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31UW-32332182.xlsmxlsm 100a059429276f981fa6268ee948f1403f73c2fdd01e41148fbea55e773bb1bcn/a Heodo
2022-03-31ID-2431302936.xlsmxlsm 65b87a95369159fb3d54556f3f316f9e13eadd8b95e9e13f6a8d9cc79f43a8e6Virustotal results 40.68% Heodo
2022-03-31NJP-61153607.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564n/a Heodo
2022-03-31DA-7856688258.xlsmxlsm 6ba49c8a1bc5dddfc74a33d1c6f53df15e682043f2e3e66963ef4577191206cdn/a Heodo
2022-03-31NR-8742682960.xlsmxlsm 638588dd97949a25ee7322aa73731204406054bf2db2043063ebfdc82d353f65n/a Heodo
2022-03-30PV-709093708.xlsmxlsm 2909468da77be7c90d3c57fa66be2e6250afde34bd400f2c815be9bfd89be7ddn/a Heodo
2022-03-30XOU-1518799481.xlsmxlsm 70c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080Virustotal results 33.90% Heodo
2022-03-30ZM-3520215752.xlsxls 2fb5d6b4684b1f180fd682f92fc346420c16376d64b8b8ec6b0564247000dc58n/a SilentBuilder
2022-03-3025581852728750830.xlsxls 351b340794aa53151cbfc28a0915520349e8d2d2d33a41efd0c82e71dffcc9b2Virustotal results 28.33% Heodo
2022-03-3051526526081.xlsxls 4475ab45a2d8b2297f49e985f0d17f5ae879c80cc960e17055819eef352f138cVirustotal results 26.67% SilentBuilder
2022-03-3096825160831521276275.xlsxls 786cdbbcab12d6076e895521a41dc5e5bd48fd09dbc85d4843a128c04dec73c2n/a SilentBuilder
2022-03-3058722116431620894.xlsxls f9fb4d5914f4d35aadbdf779dafd269c3581ca7296e7d927d8acdb38b5bf5a2bn/a Heodo
2022-03-30723993436198010.xlsxls 7e23ee736d4dfb8a361e8867027e49d1cabadb8a99f76ee5afae043b5a4bffc4Virustotal results 26.67% Heodo
2022-03-30156435249524.xlsxls 18620190f7162d9df017a561138e2ee83549e1aab9382f9b29b27542a490a169n/a SilentBuilder
2022-03-303348384591.xlsxls 7b104224ca183d73b657b9fde19b9889e4c25eed58259d1990bd0feb59f3a740n/aSilentBuilder
2022-03-306156200633340.xlsxls 69d8211fe32a1c511c6fd358005bceb8e19e01d9cc927c01b9f0760c13b75d6cn/a Heodo
2022-03-3031278838867366.xlsxls 9aae3a9d0d57dec1eb2e6151e4930c4624c95638ea038cfcd64436bf32abb39fn/a Heodo
2022-03-300685390536208490715.xlsxls d4cfb0c8440f63b52a9a6506210f17aa2cbdeac594081472fa3f4c8440fbbc1dn/a SilentBuilder
2022-03-305617566064560.xlsxls 53695dcf97841c90ec048a84804fbdd56aca83a71ad0ea445d6606181c7fcd64n/a SilentBuilder
2022-03-300800302659445.xlsxls 2b82324426c06592a76bf7c5c8aa1dee1ce453a2735ecdb3d54a179a452bc4b9n/a SilentBuilder
2022-03-303965381491153901870.xlsxls b0bb73b26ef4bb7bbfc7a11f9623721be84f3b00cab0c87a0a89597f79cc9be4n/a SilentBuilder
2022-03-304922106406.xlsxls 4d57182432ade39fbabce23e685ff21cc1d6cf5966f8bf69e222d84d6c2176e4n/a SilentBuilder
2022-03-30622421856800207.xlsxls 2ed370e7b10a0832ccc6c51912b84345f0b6b1a0d19f212a86886497ec9bee8fn/a SilentBuilder
2022-03-3035455352588.xlsxls fc11990e224dccd621a3e096de9d3ba9ea970ea8434a56a20ff5dbf00ac1bd90Virustotal results 25.00% SilentBuilder
2022-03-3002012218097151.xlsxls 54a4af2bca66a6a370cf8cef6558048fdc01232749e0da6feb0842c73ec34854n/a SilentBuilder
2022-03-3082278018569757647.xlsxls 99f00e2a4ed7ffc848c6d17b428903f2234a4279a94026429569afa46cbf1f52n/a SilentBuilder
2022-03-30123496868717.xlsxls 996fdc85f7db15b75ad84ae9c548b13c128a222af239737a7a5cadd42ee4757an/a SilentBuilder
2022-03-3080820796667187192924.xlsxls 85a517c8a98c039c699d728c89dd5cd5aa6aac0c77601894e0c40a528d987736n/a SilentBuilder
2022-03-30398895429295930876.xlsxls b1f9a8c2b79e9e80247652fcb54a87ead4d7b32c51769ae1622b94d9af3edeecVirustotal results 21.67% SilentBuilder
2022-03-3099383618432126.xlsxls 6280ad828511d4eb90c7c03d7f193d8f55f363f130e0c4aacc7481220313b846n/a SilentBuilder
2022-03-306049168926.xlsxls f37c6c8662785514f852d04f94ac6b2217b3c5244e84dae528f13c5b8b95daecn/a SilentBuilder
2022-03-304260199724732154981.xlsxls 4b1bbda0a79f94fcfb3e365b20d67277bf11d406f08d6a6417636af0142eea75Virustotal results 22.41% SilentBuilder
2022-03-3030168688225806219566.xlsxls 6e59acf9d3a2753b58d6e85224cd82fa45cd9e7e392cc4bc18d0577ae539036cn/a SilentBuilder
2022-03-295256570838385948318.xlsxls 5945c872c336b1839e2d24e8ade8c28cd4bfda3b45281798c978e0989334a219n/a Heodo
2022-03-29959226545565.xlsxls cf32dd8b34af56ba98e8e60de33e463349578b7c5f034c6b5394c1de65d8b3bbn/a SilentBuilder
2022-03-2903098537249.xlsxls 81ba58623792becf40d816c7b68f709ae3ff2985753490501f12ea3987f9bb5eVirustotal results 21.67% SilentBuilder
2022-03-2944266079139.xlsxls 780842ee666eee15433cecc5089ad60af4b2d3c041d601a6863f9d6b036c7934Virustotal results 22.03%SilentBuilder
2022-03-294105326218767840226.xlsxls 6741b0effa1844c85e25015d8c01ab0330e793dc563cfe2977746f5eb7a37fd3n/a SilentBuilder
2022-03-290674283652228660688.xlsxls 6d7f03a15d7e07cfbc738ccb0b064abc31733873e7ddc662815454136a5fbc42Virustotal results 23.33%SilentBuilder
2022-03-2976538213995301.xlsxls aa7f8032eea8a66f2a2fcb725bfc16899f61552dfb4e2e7b9c6a4d1bfad9d604n/a SilentBuilder
2022-03-291819488127855162.xlsxls 912ef80d96550207598474c59820892d1bf52be76ac1c04f833228027a222f0cn/a SilentBuilder
2022-03-290649051362087851573.xlsxls c92ded7a25787ebf85924eaa3bcda461a2f4bcd31f482604e652d7334645fe1dVirustotal results 22.81% Heodo
2022-03-2928457499418278159.xlsxls 0c25f93da9444156e572c7d66e1076bd12ecb8dc6efb16d485da111c8b47739fn/a SilentBuilder