URLhaus Database

You are currently viewing the URLhaus database entry for http://gillbanks.com.au/contact/9IqDfevg4C30GHkW4O7eKWsKWsE/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123057
URL: http://gillbanks.com.au/contact/9IqDfevg4C30GHkW4O7eKWsKWsE/?i=1
URL Status:Offline
Host: gillbanks.com.au
Date added:2022-03-30 18:48:07 UTC
Last online:2022-04-19 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 18:49:06 UTC to abuse{at}serversaustralia[dot]com[dot]au)
Takedown time:19 days, 12 hours, 35 minutes Bad (down since 2022-04-19 07:24:31 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31AQX-42763010275.xlsmxlsm 09505f38dc69865b951b157cf9900abb04934cf9ca62028700bda6099ac98c9aVirustotal results 33.96% Heodo
2022-03-31GXG-020357227.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31ZLR-897832551751521.xlsmxlsm cd0891f674a1b120041667766fab973b77fadebbd9104df4ec85619dfa69086bVirustotal results 36.51% Heodo
2022-03-31EQ-59290324404.xlsmxlsm 08e64e582d9d42f5f3a21eaff52bcb72b4a3abfc761561ff28f40bf937dedb2cVirustotal results 38.10% Heodo
2022-03-30DU-54193945391.xlsmxlsm cd87c584d61ecb87fbf42b6e2214664f3d1feb22fee767b261b3c269b8210d92Virustotal results 39.68% Heodo
2022-03-30BHJ-92151036.xlsmxlsm 39bbb570609ea300f9d959dcf23f2161043c6dedc230f97e7eab2388db651831Virustotal results 37.10% Heodo
2022-03-30ZO-7150953712223.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51Virustotal results 33.87% Heodo
2022-03-30MRZ-4936064613.xlsxls 34c12fb797211966f38e1025e683ec8ecc00b70e39d5f463213f7b09eea896c4Virustotal results 28.33%SilentBuilder
2022-03-30TMF-01086275.xlsxls f0beb35ec05b2573e3690db6e67f03dfd61681549208e49e015a7cd815e86d10Virustotal results 28.33%SilentBuilder
2022-03-3038296411026.xlsxls 351b340794aa53151cbfc28a0915520349e8d2d2d33a41efd0c82e71dffcc9b2n/a Heodo
2022-03-3070693344096945.xlsxls 8bfc93fd8fca203b767fe8a42772096296b844cc0d17a204f588c992e6fe7cfeVirustotal results 28.33% SilentBuilder