URLhaus Database

You are currently viewing the URLhaus database entry for http://hillnyou.com/wp-includes/usN25SBC0RXi2o0ZqjURqfYhXUH/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122628
URL: http://hillnyou.com/wp-includes/usN25SBC0RXi2o0ZqjURqfYhXUH/?i=1
URL Status:Offline
Host: hillnyou.com
Date added:2022-03-30 14:41:04 UTC
Last online:2022-03-30 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 14:42:05 UTC to abuse{at}contabo[dot]de)
Takedown time:5 hours, 52 minutes Good (down since 2022-03-30 20:34:41 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-30341654811100.xlsxls 59cb698a7354641948808325fe575e61e34b626ab012f8ac911dda41a730b706n/a Heodo
2022-03-305807824670199149.xlsxls 60c0dad4980aff53d768039fa5b011ca4215035e86e7cd917d6fa9675cecad30n/a SilentBuilder
2022-03-304070619586022472.xlsxls afc46d6c9997ec7eff8e0790a557aca5339229db13887d493eb4e0bbf9fa20b1Virustotal results 28.33%SilentBuilder
2022-03-301575303425.xlsxls 48f8db12e68c170ee127dbfc92d5052aecb6e381f85910d86ba35b032a7737dfVirustotal results 25.00%Heodo
2022-03-30192466884235064914.xlsxls b2565c24c9c72461d71c25df5d6ea291c53cd27725217f8c6585653cbdf72648Virustotal results 25.00%Heodo
2022-03-304432439281742.xlsxls 5206671cef156681bda1a374c1140c4dc8e4796b93d323161c15c6767afe3fcfVirustotal results 23.33%SilentBuilder
2022-03-3068014978327609.xlsxls b99d9bc7449ede3c758265e19188659e67c5d8199c26ea6c86fbf67f2334b4d5n/a SilentBuilder