URLhaus Database

You are currently viewing the URLhaus database entry for http://d37731.ispservices.at/font/RJqwJjl/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120498
URL: http://d37731.ispservices.at/font/RJqwJjl/?i=1
URL Status:Offline
Host: d37731.ispservices.at
Date added:2022-03-29 20:13:04 UTC
Last online:2022-03-30 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 20:14:06 UTC to abuse{at}a1[dot]at)
Takedown time:12 hours, 53 minutes Good (down since 2022-03-30 09:07:23 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-3069520502844.xlsxls 17ecc742902925465369b5dc8bb6c8c87d9e16a1cdde0c38c3b4264f73029cd6n/a SilentBuilder
2022-03-3007592039780349772920.xlsxls e6a63d647e1012f755a40dbaa61018c6f9b43eb17408dbad3b01ed09a5415adfVirustotal results 25.00% SilentBuilder
2022-03-300322455842030764069.xlsxls 4d11b3a06dccf68d365ed6fe59059434d439a139e229b490926f875e0fef78b5n/a SilentBuilder
2022-03-3067956388838035686487.xlsxls fcc9433ef4577609340bc031159a9d1329e9f97cd05dc2093d12abe1857691f9n/a SilentBuilder
2022-03-309531139157220.xlsxls a29527126ce0d0f97fe09f82e3d8e555b5c6fba10d6cec9bd9062a2b9d4df7f7n/a SilentBuilder
2022-03-300831206834547.xlsxls 0ef1d87a8603f19dbb5c1e6352e3668afad3b3c384b0d5b3dc198a3b9786a318n/a SilentBuilder
2022-03-3049934086012366348.xlsxls 39e9199a1a4f3bdec4b6df74937c1a5b178d8f55f2a9ed84a1480e5dbb2be75cn/a SilentBuilder
2022-03-30891528803208475.xlsxls 50c3d5a37ccc9d63435cb5ed56e8a758234f55c42f3d8a90c12fdde81ae649bfn/a SilentBuilder
2022-03-2966459439515757813.xlsxls 5945c872c336b1839e2d24e8ade8c28cd4bfda3b45281798c978e0989334a219n/a Heodo
2022-03-2914459986514503312.xlsxls 09c00288dd05705e10ced13056db3a9137cea631fe0acef89306d35bb35b9ee7n/a Heodo
2022-03-2905288191268718413119.xlsxls b1607ec0f6786f359c81b5a083c3ba60a429a0cc7d89c5d7613b026afa3a1651n/a SilentBuilder
2022-03-29015854299270.xlsxls d0dcb5614fc199cac0c2e01c32f8a6c20190be37070e392f783a7057427ee9ecVirustotal results 20.69%SilentBuilder
2022-03-298047915143584383.xlsxls bbc1337630f46853905e7fa804eb8bf2b3644f3a16a1911ea1fbd7fe1811c1ecVirustotal results 22.03%SilentBuilder
2022-03-2914339751126368595680.xlsxls f77514d8242b6369bf9a60e5bdd37355df0bf2965fc37c1e377e149de883a747n/a SilentBuilder