URLhaus Database

You are currently viewing the URLhaus database entry for https://doktortj.com/content_files/7d9ZiEBEQhmRpAAQNT/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2121482
URL: https://doktortj.com/content_files/7d9ZiEBEQhmRpAAQNT/?i=1
URL Status:Offline
Host: doktortj.com
Date added:2022-03-30 05:33:08 UTC
Last online:2022-04-05 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 05:34:06 UTC to abuse{at}idnic[dot]net)
Takedown time:5 days, 20 hours, 21 minutes Bad (down since 2022-04-05 01:55:51 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31EPA-20477673.xlsmxlsm 2fa93c2dfef003816d473094a03ffe57ed6fd6cbbd21f22831af88634fc3287dVirustotal results 37.10% Heodo
2022-03-31MOJ-0928250.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31UE-66129680694079.xlsmxlsm 36828e7a04990e1d0b2b67ccfa64ea170ff92c77cf92107d904f1e106c1d676bn/a Heodo
2022-03-31UPH-995032259187702.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-30ZYN-3500888407530.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30AIC-42013734.xlsxls c37ffc0e87ede2e654c4112c8d1b9172041a21bc4174b248ee2c81af738bcaf5Virustotal results 28.33% Heodo
2022-03-30ZWZ-49969117785633.xlsxls bc8049d90da2c6ed214cd043d2d754a1f8fc802010a6367d5cac254aa1853a67Virustotal results 26.67%SilentBuilder
2022-03-307027114424760.xlsxls 8ac921427017ffda78505e0ab7d5ef4aa736131b9914734111910f5350b10306n/a SilentBuilder
2022-03-30515760703391.xlsxls 9b3c07ec8e135d5706a87f86ddac9da3702a1913064f7982abee3545039bc251Virustotal results 25.42% SilentBuilder
2022-03-3013974479752175.xlsxls 15b8f817ad756bd04cd33d34f0a4670b25afa33c7ab59f37b322284809532d05n/a SilentBuilder
2022-03-30500698138028.xlsxls 4d57182432ade39fbabce23e685ff21cc1d6cf5966f8bf69e222d84d6c2176e4n/a SilentBuilder
2022-03-3029903764564525.xlsxls ed919e7317e9edb91eb7468e26cad1b08ecd328cfb669e1fb95bc2f3171b2ec8n/a SilentBuilder
2022-03-303050439447.xlsxls 17ecc742902925465369b5dc8bb6c8c87d9e16a1cdde0c38c3b4264f73029cd6n/a SilentBuilder
2022-03-301151832046530522431.xlsxls 66115ef823bbc6b8007ee6b6508af174566899af8df63ea1f6707b293153f2bdn/a SilentBuilder
2022-03-30215168470648106754.xlsxls 7bc0a080f39d5c19c14ef549d30373cf03116dd942536ee0c02249e4f94fafben/a SilentBuilder
2022-03-3064476680894031.xlsxls e5f9e976372f6a3247c8146223863a6a67975ee3696f537dd115f52cdfe22a5dn/a SilentBuilder