URLhaus Database

You are currently viewing the URLhaus database entry for http://eipweb.com/cgi-bin/xOmjzaHqorTrUXQ/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120172
URL: http://eipweb.com/cgi-bin/xOmjzaHqorTrUXQ/?i=1
URL Status:Offline
Host: eipweb.com
Date added:2022-03-29 17:55:05 UTC
Last online:2022-06-18 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 17:56:08 UTC to abuse{at}bluehost[dot]com)
Takedown time:2 months, 20 days, 14 hours, 57 minutes Bad (down since 2022-06-18 08:53:30 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31ZXZ-724486206.xlsmxlsm 896ef5fb12bd10c84fa96213d6a86aa368388e4806b9c882fd601a113482ff74Virustotal results 33.87% Heodo
2022-03-31WJ-459213753313476.xlsmxlsm 36828e7a04990e1d0b2b67ccfa64ea170ff92c77cf92107d904f1e106c1d676bn/a Heodo
2022-03-31FA-2009269077412.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31CNS-8872860.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231Virustotal results 40.98% Heodo
2022-03-31ZJZ-9888580.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31TCP-402408168648480.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51Virustotal results 41.94% Heodo
2022-03-31FWC-117574377239632.xlsmxlsm a099f9c9c8eff7049da288a1205f1c0ccd52a4954930cabdd7a00dafbe8bbe6dn/a Heodo
2022-03-31ISS-6500893309221.xlsmxlsm a43da1637de01a06d72a9d09981de5132b8bd971844704ee9fc7c5e07450a49dn/a Heodo
2022-03-31ZO-80644255946.xlsmxlsm 52939ecf287fe6bf3435960c423bf17f7ea8452f102024e9aca86cf806fdd533n/a Heodo
2022-03-31BX-0697650.xlsmxlsm 0c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3Virustotal results 36.51% Heodo
2022-03-31OE-2784212.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-30II-343990281400.xlsmxlsm f6d9028f6903f57570a969a97a510120fa11d93ce778cfeac61862c36d6b6bd2Virustotal results 38.98% Heodo
2022-03-30BE-212564525443.xlsmxlsm 08e64e582d9d42f5f3a21eaff52bcb72b4a3abfc761561ff28f40bf937dedb2cVirustotal results 35.48% Heodo
2022-03-30KZ-9227820404.xlsmxlsm 7b790cb9f037644da2aa7daf038bef787f020bc8aad1932fb1e8c4c5ab3b4766n/a Heodo
2022-03-30QU-640784724.xlsxls 2fb5d6b4684b1f180fd682f92fc346420c16376d64b8b8ec6b0564247000dc58n/a SilentBuilder
2022-03-300561453932.xlsxls 3b7de1493be097dcb0cc89361c753b8f43f5de20b45e403c7f809ab2f7d2b03bVirustotal results 24.56% SilentBuilder
2022-03-3012030653837098998.xlsxls 4475ab45a2d8b2297f49e985f0d17f5ae879c80cc960e17055819eef352f138cVirustotal results 26.67% SilentBuilder
2022-03-307544195552960.xlsxls 9413cad13f6984ead99ed414e0569446e58817727b472a9ffea3097eb76d2e10Virustotal results 28.33% SilentBuilder
2022-03-300893836752779.xlsxls b2eb6b0d2399ec53a26411617b183d00a09f80e54adf21f4661cdb254b678578Virustotal results 26.67% SilentBuilder
2022-03-30365966793141.xlsxls 5aa5eaa6978bc5dd39ec66d659e21ae075374067866bb46c3447fa2d13f4d99eVirustotal results 26.67% SilentBuilder
2022-03-3006401119600895375089.xlsxls 9c35fffa92d67bbca9eac86d6fc450530e6a190f08cd5234dda6a159c4b699ccn/a SilentBuilder
2022-03-307842889387758533000.xlsxls 69542b3dd50ede56ad6fd0d3841c3aaf9ba207a33dd4053d72d8bf3247be6068Virustotal results 23.33% SilentBuilder
2022-03-304690807059188916.xlsxls 680f0f283478f314621677f9fa1388a88017cd003d7173163cdcc4f16cbedfddVirustotal results 24.56% SilentBuilder
2022-03-304564493949233330.xlsxls 1f4abd57d6305167ea781e255bf801474d77d7415dc16bfa03bcd9c6afb8e977n/a SilentBuilder
2022-03-3042465761351410826307.xlsxls b77b0ef522691f56c326dbd8bfd07faa9b30f9426461ff385a1e744c3e469678n/a SilentBuilder
2022-03-305046034627586263042.xlsxls 17a017e03150a780f08ebd41dde43ac2babb836c2e92674995af925cce5b19dfn/a SilentBuilder
2022-03-30315953340847856.xlsxls c1cbd56f3ba76c3bdd704399b552ac54d6463b6dbbe45adb3334d7178c0ed493n/a SilentBuilder
2022-03-302191625854096201.xlsxls 53a8cf28fa59ff225a7a58d4ab09db8ad23bed8afdb2ae42232a8f11acf3553bn/a SilentBuilder
2022-03-307708873462.xlsxls ed919e7317e9edb91eb7468e26cad1b08ecd328cfb669e1fb95bc2f3171b2ec8n/a SilentBuilder
2022-03-3028859051649360144.xlsxls 19f6caa7a30df844b400ba5f224bd75901e715d328ef9a38903900f0fa773946Virustotal results 25.00% SilentBuilder
2022-03-3054801267137201800656.xlsxls 47857229b4e3390c46a0c815ba051979c912f8098d62136f34264d948602e776n/a SilentBuilder
2022-03-3070589908067.xlsxls 0064a9e50d81734b02d6e46a0c7438caaac87d97c3a8d2e252d116c08094820bn/a SilentBuilder
2022-03-30390604200736560846.xlsxls 8268e3b187b04e9310ead1910af5d33341941f04739fe068e06eb341969b71afVirustotal results 25.42% SilentBuilder
2022-03-30740040755113396.xlsxls b1c3d43a1b9fd0f97ca13511fa5bea8e9c537383fd9ca4962779312fc30460efn/a SilentBuilder
2022-03-308680496917183523.xlsxls a29527126ce0d0f97fe09f82e3d8e555b5c6fba10d6cec9bd9062a2b9d4df7f7n/a SilentBuilder
2022-03-30509096791596936461.xlsxls 8afc3601bdf149acb399f6b30fe3188535845cbd8af7c0cf469d02e7524b2b6an/a SilentBuilder
2022-03-30303745439739.xlsxls 9e567a344081987a4426f78ec523045fd89cefc8790ccd11bc7c7e84a0816144n/a SilentBuilder
2022-03-303118681615772856374.xlsxls 4b1bbda0a79f94fcfb3e365b20d67277bf11d406f08d6a6417636af0142eea75Virustotal results 22.41% SilentBuilder
2022-03-3020711087673052065.xlsxls 3f55a18289a4defdb2b50e5314a7972d39bd0d4e7e2da0826a91f163eebe2a9cn/a SilentBuilder
2022-03-298488758010.xlsxls c7e78d00cf4d1eda853fe906d22b26c5e9a03e67f2ab9f2755ee7b7fb8c54ee6n/a SilentBuilder
2022-03-2997259174529.xlsxls 4db12a7472a2427ea88cb16a24494b46824688abd29824abffa27f9366e46f30n/a SilentBuilder
2022-03-290403293385.xlsxls b26329204d4a737b51b710c6fb4ca573291be87a1fb5606f0e0b75987c09908fVirustotal results 23.33% SilentBuilder
2022-03-29422058110918.xlsxls 67a20d8315c3e1cb24416ae035906dcd81592e4320a2168428e11db1afeee329n/a SilentBuilder
2022-03-2963432398575118674091.xlsxls 37b9f7f289229073f7615e9694ead523ff3f6cdf77a0cf2d0694d910a10ce6b7n/a Heodo
2022-03-295346386911264793.xlsxls b10478442a0de8c6a68e9c10f22d7cb2fe59302d1283d184edc5ea41bb607d16n/a Heodo
2022-03-29665871555561923073.xlsxls e7b03ed1a9795dc92083442565b98454f681a5cb1cbb0c34f4ceed7ca7ef7f67n/a SilentBuilder
2022-03-2924495288066226587.xlsxls 47c9e54827d5eb1bedf091b985d4c3db3dbd311b612c0a62bc274c20f46af944Virustotal results 23.33% Heodo