URLhaus Database

You are currently viewing the URLhaus database entry for http://gestion.roimarketing.es/application/yZfIvwLmfTgYbbJxvZ/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1993318
URL: http://gestion.roimarketing.es/application/yZfIvwLmfTgYbbJxvZ/?i=1
URL Status:Offline
Host: gestion.roimarketing.es
Date added:2022-01-20 17:40:14 UTC
Last online:2022-01-20 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 17:41:11 UTC to abuse{at}arsys[dot]es)
Takedown time:2 hours, 5 minutes Good (down since 2022-01-20 19:47:07 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-200042383945216459385.xlsxls d91913b43fdaad89d95326947c38ee9122ea2792657d5c10b8ec0ac8982ce699n/a Heodo
2022-01-2095505391763801.xlsxls 039adcca4d205850117d5b2348ceec561c57868668ab822350ef94a9b9467842Virustotal results 41.67%Heodo
2022-01-201814137692231.xlsxls 40dd74fb1fba55980387dff7f457cfee8778be09fd503bc397f747bd97d82ffcVirustotal results 43.33%Heodo
2022-01-206660484516.xlsxls a871770ef1ba329147828026ab5d7d1d0edf83ea93fca2bb2d0faada51cf48e1n/a Heodo
2022-01-209341970727158087.xlsxls 093eb9276d5df2490f9dc0dd324349648f030d92ca6d4ab24d386d1d0eaea799n/a SilentBuilder
2022-01-2016208023845776.xlsxls 4627d88cb27d885555625326c40717630dbfc7708869fdde4d0064f2d59e5bb4n/aHeodo
2022-01-20576396774566778.xlsxls fff3ac0f2ce35babb7cf736ec26a8374c8babd255489994937c41a8c005e5b46Virustotal results 22.03%Heodo