URLhaus Database

You are currently viewing the URLhaus database entry for http://gilbt.nazwa.pl/wp-includes/3yD2w2TfNmkAnYiRGmlH0wpplvdi/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123003
URL: http://gilbt.nazwa.pl/wp-includes/3yD2w2TfNmkAnYiRGmlH0wpplvdi/?i=1
URL Status:Offline
Host: gilbt.nazwa.pl
Date added:2022-03-30 18:12:04 UTC
Last online:2022-03-31 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 18:13:05 UTC to abuse{at}nazwa[dot]pl)
Takedown time:9 hours, 7 minutes Good (down since 2022-03-31 03:20:18 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31AGB-3737331280.xlsmxlsm 4409b097292f1ed1adedbae38fcecf71370a64209f9bb5ffff019b71e8a88533n/a Heodo
2022-03-31MS-140074727280.xlsmxlsm 6ba49c8a1bc5dddfc74a33d1c6f53df15e682043f2e3e66963ef4577191206cdn/a Heodo
2022-03-31YQ-169544571120.xlsmxlsm 93e06d8850641586fe31c662da490f8ff442f4f86021f50799e1174dcace1f72n/a Heodo
2022-03-30GGK-4839024.xlsmxlsm 533372e6130ad44ced6eae30ab3af8be4ae172cc7585719b61074bb861f2dbben/a Heodo
2022-03-30FAI-0063668.xlsmxlsm 42c504a0fee5cb3e3033b4f6d596ce78f3f3c1118dc4cdfddf0b54715c66117cVirustotal results 32.79% Heodo
2022-03-30EAJ-06385135367.xlsxls bc3aadb828bf8f9442d01bb0a1d6b11b7633b19d2d0f8dc6711897611c0a5c3dn/a SilentBuilder
2022-03-301707315493745321.xlsxls 9adde116bf0bac725d59a9758fe3135672fcf8e2a7d30d3ae41d6df39452d54aVirustotal results 25.00% SilentBuilder
2022-03-30883818731979.xlsxls 7324fd5254825996acb024055b8f85c89b19897ef327543836bad401b074d0b6n/a SilentBuilder
2022-03-3028498877673730296.xlsxls fa9ff98be2b2014f3459f9e24865c2c062491b891fcf51b2a6b03e208256305cn/a SilentBuilder
2022-03-3011018790530927.xlsxls a1043d987d910e34281c2a6f7280438e68ce6e5b3a58a35e9d60ebbe8ed97c9fn/a SilentBuilder