URLhaus Database

You are currently viewing the URLhaus database entry for https://celhocortofilmfestival.stream/css/716-811740/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1968253
URL: https://celhocortofilmfestival.stream/css/716-811740/?i=1
URL Status:Offline
Host: celhocortofilmfestival.stream
Date added:2022-01-11 19:53:04 UTC
Last online:2022-01-21 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 19:54:08 UTC to abuse{at}cloudflare[dot]com)
Takedown time:9 days, 12 hours, 29 minutes Bad (down since 2022-01-21 08:23:58 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12vp_1818.xlsmxlsm b94a04d3a5f75fb0370e59e96488c49848647fd60e1b9ef2a9e898ff5b53f6caVirustotal results 10.00%Heodo
2022-01-12HWW_921.xlsmxlsm c95bf0dd160b7a12ab600aee9220e652b1b1cc3b006f264c324a0c0a9d5aa257n/a Heodo
2022-01-12QYJ_94306703.xlsmxlsm 90c68041ea2e1e9b44724b9e68a58b8490996a52a5c2eda58d2eef0247b37283Virustotal results 9.84%Heodo
2022-01-12978857612502214.xlsmxlsm d193efb518a026a5507a4bb6bc168c2f7922c39ce1bb8fd5553512152cc2b88dn/a Heodo
2022-01-1174723275_0259074.xlsmxlsm d3e6a6a97ad6e4f79e73386e88cddd5b958d0f8745c551837dd366b929671704Virustotal results 10.17% Heodo
2022-01-11q_2578702.xlsmxlsm 1b8fafe40bc98e1d41a794e824ab4ca505634fe25fdea8a3e560be3938ba1b58n/a Heodo
2022-01-11DIYXH50382.xlsmxlsm e06e1cc33f42f59f86b44d17359234628540e287dc10a39ac66ae21449abd380Virustotal results 9.68%Heodo
2022-01-111653-426.xlsmxlsm d232986e906c448669c346c5edefc1d51b9224b6d53afd360e4768f9861eafadn/a Heodo
2022-01-1122008-75970.xlsmxlsm aa920a2c74b8982c5dd77f97f0dd2d6c7fd69f047983447d6ae43cdf1573b07dn/a Heodo
2022-01-11fvxer_82302.xlsmxlsm 2a43f2180ac8723fc79222c637ad6743128611c7c89843cec720bd884dd1b72fn/a Heodo
2022-01-116787885711075.xlsmxlsm 8ad61be673c186c9cdfb6c6c8d750fbcf80f920d4905742c0ed9d67833026ed7Virustotal results 9.68% Heodo
2022-01-11ybutio973.xlsmxlsm 71da6e57fe5adfa0b06f8ba9525e6db95e7c25246179fa8563561d24e79e6c65Virustotal results 9.68% Heodo
2022-01-11yydary_34720303.xlsmxlsm 929fd76e8373d3c14a1fa542d4222dba73cb21f0c5cdaa0c8b7acea0a53d8f0bVirustotal results 10.00% Heodo
2022-01-11TA-376364.xlsmxlsm e8aafc15bf0669df883db0e64e8f43f3682a856e74e19e95d9aa6b44aed98ea4Virustotal results 10.17%Heodo
2022-01-1142451067-63.xlsmxlsm be28d13f222be634d640dd982c04039f80c9ada5efc2eb126adca4c9a3595d6dn/a Heodo
2022-01-114921395-685.xlsmxlsm 867a5e845a227cfb9fa1988fa078679d6b6fa0bae43ffebfe412f97bba373ddfn/a Heodo