URLhaus Database

You are currently viewing the URLhaus database entry for https://www.refyparlemantera.mg/-/vPIEGKm49pC/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1985875
URL: https://www.refyparlemantera.mg/-/vPIEGKm49pC/?i=1
URL Status:Offline
Host: www.refyparlemantera.mg
Date added:2022-01-18 08:52:04 UTC
Last online:2022-01-22 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-18 08:53:07 UTC to abuse{at}ovh[dot]net)
Takedown time:3 days, 22 hours, 34 minutes Bad (down since 2022-01-22 07:27:55 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-2056014314209.xlsxls c0bdcb5bc94529906c63365cec6d08f576fddd0d78a93d487147c88c58816b45Virustotal results 55.93%Heodo
2022-01-182589740117159091.xlsxls 5b375b073c39b03e9ccf40dc5fa4651bb2e28721896d5abc68a3886e2dd691a7n/aHeodo
2022-01-1800291996760759.xlsxls 5feb30d01fb35d5fde34eb531e533bbfe6870e26612f2b397214636aed65988dVirustotal results 16.95%Heodo
2022-01-1831832183825724151.xlsxls f74f1937436ffe314a94cebb131fdaa70c307b0893ffee51d13c88f0338a4451Virustotal results 16.95% Heodo
2022-01-187090145270859.xlsxls cb72411eda14bcfa779768a7613cfd14ee3fe81b4146cd94786f02b6f1a6c385n/aHeodo
2022-01-187230105466612647.xlsxls 518b04d7884a023cf712471a10ae16dc5baa8b507f100979cdc790ff3363aca7n/a SilentBuilder
2022-01-18203349168919195189.xlsxls 19cc6e596b124cab97ea402ee82f4c206665a9ba84918289f1e80509f82f9d49n/a SilentBuilder
2022-01-18019161427552501.xlsxls 314455a381d1cd20522649589eae3f0ff07ddebc5d2893df56f7a858461f6eeeVirustotal results 20.00% SilentBuilder
2022-01-18436644471818467.xlsxls 6577c9fea8500bde03a74901072bf5c391ef8a7d8d9968c26c08d4d60a1e54ecVirustotal results 18.33%SilentBuilder
2022-01-18602336742743.xlsxls 8544b5801a4f8d2ded0d3f5fb5aaca099619c047f3064650e9871d613d4038d1n/aHeodo
2022-01-1882383179167422539.xlsxls 79fc3533aae32859d8e01829961c4220470c43e8e81e769c428e34a0d5ceeb85Virustotal results 18.33% Heodo