URLhaus Database

You are currently viewing the URLhaus database entry for http://hiprofile.com/suspended.page/kbNxxBwUPw9/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122601
URL: http://hiprofile.com/suspended.page/kbNxxBwUPw9/?i=1
URL Status:Offline
Host: hiprofile.com
Date added:2022-03-30 14:14:05 UTC
Last online:2022-03-30 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 14:15:06 UTC to abuse{at}softlayer[dot]com)
Takedown time:4 hours, 49 minutes Good (down since 2022-03-30 19:04:57 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-30902865848648.xlsxls ca7ae0768d8ec84c9636a4287b0924f63b6c34a876d90a1db949444a9f913e9en/aSilentBuilder
2022-03-3070810509468349.xlsxls 181e4104c2fab5383f15d6f7f3c380fbe4bdbed44fca9b65eb88da3eec9c387en/aSilentBuilder
2022-03-30841608961423.xlsxls b2565c24c9c72461d71c25df5d6ea291c53cd27725217f8c6585653cbdf72648Virustotal results 25.00%Heodo
2022-03-303220388095.xlsxls 05b7de9ea6dc7fc6aa9bee8c26c08424ecb944f734630f2f5f708dd38c643200Virustotal results 25.42% SilentBuilder
2022-03-30453605246309910.xlsxls 69542b3dd50ede56ad6fd0d3841c3aaf9ba207a33dd4053d72d8bf3247be6068Virustotal results 23.33% SilentBuilder
2022-03-3057133668812.xlsxls 7143175fc3b45a138566f093a1985efc2564810ae4d8b541b63ec7570f121339n/a Heodo