URLhaus Database

You are currently viewing the URLhaus database entry for http://galdonia.com/js/D9lv/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123185
URL: http://galdonia.com/js/D9lv/?i=1
URL Status:Offline
Host: galdonia.com
Date added:2022-03-30 19:58:04 UTC
Last online:2022-03-30 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 19:59:06 UTC to abuse{at}gruposys4net[dot]com)
Takedown time:3 hours, 4 minutes Good (down since 2022-03-30 23:03:19 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-30CAJ-10086284560.xlsmxlsm 7b790cb9f037644da2aa7daf038bef787f020bc8aad1932fb1e8c4c5ab3b4766n/a Heodo
2022-03-30FN-5065182.xlsxls 82be92d18fb73fad9b6f0e90da074abbf2aaffd91c4493491620452f19bd281dVirustotal results 26.67%SilentBuilder
2022-03-30642361955664.xlsxls 3493b3210a3ce325a05cc7da5ffc69d323e0a0a645d8bdfaf1016a2de52ee1b5n/a SilentBuilder
2022-03-30893943274333.xlsxls 7c9ef24f3522ff243e77f5d6e0cb50f6766916fcc1ad2fe845f9d509e39a6b3fVirustotal results 25.00% Heodo