URLhaus Database

You are currently viewing the URLhaus database entry for http://mail.coronaplastering.com/assets/Fu3Nykfksg5GvJnli26/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1992862
URL: http://mail.coronaplastering.com/assets/Fu3Nykfksg5GvJnli26/?i=1
URL Status:Offline
Host: mail.coronaplastering.com
Date added:2022-01-20 14:57:04 UTC
Last online:2022-01-24 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 14:58:11 UTC to abuse{at}digitalocean[dot]com)
Takedown time:3 days, 13 hours, 26 minutes Bad (down since 2022-01-24 04:24:45 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-219538033901433.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 48.28%Heodo
2022-01-215702848501144.xlsxls fc79dd33ef2208cbe871b54938ff2ad295a34cb9a720e4995853dfed5761db18n/a SilentBuilder
2022-01-2104571078799781680.xlsxls 08e9cfb42b052e00b6236416ac76a10be4787f0ec137401a92bce8fed5f84d48n/a Heodo
2022-01-20925861364862368.xlsxls 51dc452edd7c975ac8f632ad888d6cada4233c19aa061416076abbdb2ac596b4Virustotal results 22.41%Heodo
2022-01-207495438673402101.xlsxls 67d5e8d2c3fcf5a17f0c7aad1b6f8963102dd00bdb62a3179605c3cdf659ab3cn/a Heodo
2022-01-2096047742708576767.xlsxls 5ba1e7e7b37d9efbafaaa5049277348349998f11e6252edb0aa7fcc37bf94c99n/aHeodo
2022-01-204747520902339887877.xlsxls c964bd44cc4dfa14cdab694d620128715a62156b83e9aeb8496b88228937afbaVirustotal results 20.69% Heodo
2022-01-200134889439342.xlsxls 626b64eb053b331d97bf169957fd1988e63344984f364b3e6616c48dfdffff22Virustotal results 42.37% Heodo
2022-01-20497141658350740050.xlsxls 2bc45370dd6eed0f3059fe82bd82d8aeca954819c9ad8ea823d36a8e01c7e92cn/aHeodo
2022-01-206041869071827610244.xlsxls 6c993bfdab714689f5b5924440eb9d1289f73941b3784a6b1fe4798ef65ce200n/aHeodo
2022-01-205407827383003186.xlsxls ec7b717fed554ec4124d956ab43c4ec1f2c66cc692ed85b9956bdaf9c4914085Virustotal results 41.38%SilentBuilder