URLhaus Database

You are currently viewing the URLhaus database entry for http://bekx.devsrm.com/wp-content/Pb0i9V7bRkwzWSE02lEZJ2aRi/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120527
URL: http://bekx.devsrm.com/wp-content/Pb0i9V7bRkwzWSE02lEZJ2aRi/?i=1
URL Status:Offline
Host: bekx.devsrm.com
Date added:2022-03-29 20:39:04 UTC
Last online:2023-01-21 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 20:40:06 UTC to abuse{at}asmallorange[dot]com,eig-abuse{at}endurance[dot]com)
Takedown time:9 months, 27 days, 20 hours, 3 minutes Bad (down since 2023-01-21 16:43:14 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-3021791599324936.xlsxls 2b82324426c06592a76bf7c5c8aa1dee1ce453a2735ecdb3d54a179a452bc4b9n/a SilentBuilder
2022-03-3088699702600469018680.xlsxls b0bb73b26ef4bb7bbfc7a11f9623721be84f3b00cab0c87a0a89597f79cc9be4n/a SilentBuilder
2022-03-309389900217.xlsxls 01986c3420bb1e16b56c4b6ee323e628bcdbe7c0afb96cf1d80b0c1c46f6054fn/a SilentBuilder
2022-03-301374136597670977.xlsxls 4929501cdf479939048f8d61525fa08573395607348de23b0b9326f031600e26n/a SilentBuilder
2022-03-3054113171111523.xlsxls 4d53d44c975b7bc07383a80364e591a49c73956a74beea60f7c3f1bdbf748659n/a SilentBuilder
2022-03-3096125777337805.xlsxls 6a3046a535a92689c6e5bc58e7a4bc8f4c0edb1646c288ae60283ec9136b1ed4n/a SilentBuilder
2022-03-30544124373120943447.xlsxls 64fb06d13278cbe4fb6ab3d09eaaf56ef4f16c48d82da4f164e8b4483358be7dn/a SilentBuilder
2022-03-305350197164742583.xlsxls 4049f60f0d4b2bde89b6e0f8474744ae0eba1eab4ce2a4e33066e480db5f9105n/a SilentBuilder
2022-03-30413832089290367.xlsxls fcc9433ef4577609340bc031159a9d1329e9f97cd05dc2093d12abe1857691f9n/a SilentBuilder
2022-03-3049200092076.xlsxls 32f3e722f746ac4acff3f58e739da7e4f035e631b1e425e69d4dc62e69100dc8n/a SilentBuilder
2022-03-309070514259785358.xlsxls 30ca6fe2cdcf114cf2d4aaf09ec92ff5ef2f13a9ecf72ca8a5d37195f6688aa3n/a SilentBuilder
2022-03-303815762324699720.xlsxls 39e9199a1a4f3bdec4b6df74937c1a5b178d8f55f2a9ed84a1480e5dbb2be75cn/a SilentBuilder
2022-03-3031999689627528186268.xlsxls 18a5aadfb1ade6b05280001f26d457382545510248408bbf0ba6d73aecd59e1en/a SilentBuilder
2022-03-307430297923289727.xlsxls 8bc576d7a20e6614e7b139a3ee525c37e46da65fcd2d59a8d4adf1b57354ae05n/a SilentBuilder
2022-03-2965707701803036632187.xlsxls c7e78d00cf4d1eda853fe906d22b26c5e9a03e67f2ab9f2755ee7b7fb8c54ee6n/a SilentBuilder
2022-03-2913075879209226753.xlsxls ccb548d41cebfcba2c1b04912fb4f992cca90e013536c6716e1cb2b8145b98d6n/a Heodo
2022-03-2900455708345665549.xlsxls cbcd73a418e0bf221cabd2fdbdd72a9ffb59774bc3a8a94d5a5ba7c6849a8451Virustotal results 21.67%SilentBuilder
2022-03-295526567636310589928.xlsxls d8771461e364a331ffde01dbd3e64c5e2550e47ae04569f9e31bf14a77ce2bf3n/a SilentBuilder
2022-03-293727712421377334.xlsxls 7bf1dc8f35c99f9d3a1d337a70482f7818a82fc80d4e3b9476471b52e5b3604fn/aHeodo