URLhaus Database

You are currently viewing the URLhaus database entry for http://farmaprov.com.ar/wp-content/Cq8qOt0kUFEeERW84oljGQtqAoA/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120429
URL: http://farmaprov.com.ar/wp-content/Cq8qOt0kUFEeERW84oljGQtqAoA/?i=1
URL Status:Offline
Host: farmaprov.com.ar
Date added:2022-03-29 19:34:09 UTC
Last online:2022-03-30 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 19:35:08 UTC to abuse{at}privatesystems[dot]net)
Takedown time:14 hours, 18 minutes Good (down since 2022-03-30 09:53:30 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-301074933923504398401.xlsxls 5e42f72b6f48384d2369d13cce199bc20da44c757705ba69765152d0d1d02f96n/a SilentBuilder
2022-03-301838966107337.xlsxls 19f6caa7a30df844b400ba5f224bd75901e715d328ef9a38903900f0fa773946Virustotal results 25.00% SilentBuilder
2022-03-3077996409444803.xlsxls d8fa6629e2e76e50fca563d0c65c4ebdeb6d3476fbf62a732152525b3d650f18n/a SilentBuilder
2022-03-306883645264744.xlsxls e2ee016889aedab89bbc5f12cac6caa90469cc9399fb4d492feda727602e4ed4n/a SilentBuilder
2022-03-309881220711946894700.xlsxls fa291395f719a90cebdce4e7d311f4fb35c20358ff5b78b90db5691798067e1bn/a SilentBuilder
2022-03-301248970566645.xlsxls 459b54f01ba74dc3ecc3a710a11a380049b0858bcdbf1be8a2a601ec2b6b436bn/a SilentBuilder
2022-03-3088908138532.xlsxls 3104d47a09c86d04fa246fcabdc6ef69732755446d66d42f19dec29a33d057acn/a SilentBuilder
2022-03-302160860133839880.xlsxls 2872a3f29c0e2652d14465e6ce5d3d0413e0a9c8729674c30c07548844641006n/a SilentBuilder
2022-03-3017271332746398745933.xlsxls 795d1cb7302f7f2d226a7a50f9a1dfaca81c320aabc71f47113736bc0712a6a7n/a SilentBuilder
2022-03-3061320561376762.xlsxls 4b1bbda0a79f94fcfb3e365b20d67277bf11d406f08d6a6417636af0142eea75Virustotal results 22.41% SilentBuilder
2022-03-3007292532222.xlsxls 9b7452e408963921f685e25246f5c63af11c407ac04a6fa47ffe38b3325b52bdVirustotal results 22.03% Heodo
2022-03-2905168780057.xlsxls fe7634683727f4e2c4ddaf2eea56dd2291955ef5396c96bb353ccbc080e996d7n/a SilentBuilder
2022-03-29302640018039976763.xlsxls 4db12a7472a2427ea88cb16a24494b46824688abd29824abffa27f9366e46f30n/a SilentBuilder
2022-03-299754524139.xlsxls f3daec8edc00ed830633da822f31e2ad20e1a27bff73831a2d6521ac7f4deef0n/aSilentBuilder
2022-03-2985710697236828266.xlsxls b26329204d4a737b51b710c6fb4ca573291be87a1fb5606f0e0b75987c09908fn/a SilentBuilder
2022-03-2940002338765193182.xlsxls a679c80a799b163cf0ad3f464c4a1bc023c7d6dd0715662da376d6260a4b9040Virustotal results 23.33% Heodo
2022-03-297269091192.xlsxls 67a20d8315c3e1cb24416ae035906dcd81592e4320a2168428e11db1afeee329n/a SilentBuilder
2022-03-296423246403515.xlsxls 43fce2e605be1e82e8989d5ff11ae5a74e6feb9e3c323b672c3acac8dac661d1n/a SilentBuilder
2022-03-2914638698293517.xlsxls b10478442a0de8c6a68e9c10f22d7cb2fe59302d1283d184edc5ea41bb607d16n/a Heodo