URLhaus Database

You are currently viewing the URLhaus database entry for http://gillbanks.com.au/contact/9IqDfevg4C30GHkW4O7eKWsKWsE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123058
URL: http://gillbanks.com.au/contact/9IqDfevg4C30GHkW4O7eKWsKWsE/
URL Status:Offline
Host: gillbanks.com.au
Date added:2022-03-30 18:48:07 UTC
Last online:2022-04-19 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 18:49:06 UTC to abuse{at}serversaustralia[dot]com[dot]au)
Takedown time:19 days, 12 hours, 10 minutes Bad (down since 2022-04-19 06:59:47 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31AQX-42763010275.xlsmxlsm 09505f38dc69865b951b157cf9900abb04934cf9ca62028700bda6099ac98c9an/a Heodo
2022-03-31TBB-3123880090.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 37.10% Heodo
2022-03-31ZLR-897832551751521.xlsmxlsm cd0891f674a1b120041667766fab973b77fadebbd9104df4ec85619dfa69086bn/a Heodo
2022-03-30DU-54193945391.xlsmxlsm cd87c584d61ecb87fbf42b6e2214664f3d1feb22fee767b261b3c269b8210d92Virustotal results 39.68% Heodo
2022-03-30BHJ-92151036.xlsmxlsm 39bbb570609ea300f9d959dcf23f2161043c6dedc230f97e7eab2388db651831Virustotal results 37.10% Heodo
2022-03-30XAP-7102420053.xlsmxlsm 7b790cb9f037644da2aa7daf038bef787f020bc8aad1932fb1e8c4c5ab3b4766Virustotal results 32.26% Heodo
2022-03-30MRZ-4936064613.xlsxls 34c12fb797211966f38e1025e683ec8ecc00b70e39d5f463213f7b09eea896c4Virustotal results 28.33%SilentBuilder
2022-03-30n/ahtml a7f0b9ce1e214383b7cd3ff9846c5eeaaf938877fc41aa27203916da187bc40dn/a