URLhaus Database

You are currently viewing the URLhaus database entry for http://eastowncafe1.marketgriddev.co/assets/653356803-86741/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1968406
URL: http://eastowncafe1.marketgriddev.co/assets/653356803-86741/?i=1
URL Status:Offline
Host: eastowncafe1.marketgriddev.co
Date added:2022-01-11 20:42:05 UTC
Last online:2022-01-16 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 20:43:07 UTC to abuse{at}digitalocean[dot]com)
Takedown time:4 days, 13 hours, 25 minutes Bad (down since 2022-01-16 10:08:18 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12KBM-4.xlsmxlsm e64991c009715f3cd077bfef9f339f8b58c16ac9d35300e911fce66b692b4f3cVirustotal results 19.05%Heodo
2022-01-12k-27010.xlsmxlsm 27d6855c830f8df3fde9a9f56e1cf9c88ad097a4cb45b4983f63e70a7c0517d0n/aHeodo
2022-01-12DA-517.xlsmxlsm 95b5366bdbf5fe09a9d671cb374b1661b0612ca2ef30fa484d38afd99573b2ebVirustotal results 9.68% Heodo
2022-01-12256009_050124.xlsmxlsm 90c68041ea2e1e9b44724b9e68a58b8490996a52a5c2eda58d2eef0247b37283Virustotal results 9.84%Heodo
2022-01-128551258187.xlsmxlsm d193efb518a026a5507a4bb6bc168c2f7922c39ce1bb8fd5553512152cc2b88dn/a Heodo
2022-01-12201570373_58.xlsmxlsm f20a142423cea7ec0369d225894d4cf71f4c31d425bf0215de2b6277a5354192n/a Heodo
2022-01-11H_435578.xlsmxlsm 6ec9e504112744f9f07ce60fb9315cdcd427d27a16c248fbe9746477bfc851afVirustotal results 9.68% Heodo
2022-01-11gy_9140489.xlsmxlsm aaa2fbc449fbe3b4eb3c69e272ff4b1f3723b0741d5fe86ced352aece337439cn/a Heodo
2022-01-11rQc_2556.xlsmxlsm aa920a2c74b8982c5dd77f97f0dd2d6c7fd69f047983447d6ae43cdf1573b07dn/a Heodo
2022-01-11cojqdiv99743917.xlsmxlsm b8662d7aff6b2489b65fd6ddc022a5a87c6adb0e1ed1f0286ccd80c0bc11471fVirustotal results 9.68% Heodo
2022-01-11QEL_810493.xlsmxlsm 20be5590c08561d3a5be97621400daf8528533950a589089a00a259da40668d8Virustotal results 9.68% Heodo
2022-01-113342429_5615909.xlsmxlsm 71da6e57fe5adfa0b06f8ba9525e6db95e7c25246179fa8563561d24e79e6c65n/a Heodo
2022-01-117250-95429342.xlsmxlsm c4bc03a927a72a21be0b15c8c55124264c456a940a325d8071f5cbcb7032f1c8n/a Heodo
2022-01-11ZP-7.xlsmxlsm 6c410c1ef971638f6cb6b26c9c1613bd8cb7c3bb10ea63146e40405c80cca38an/a Heodo