URLhaus Database

You are currently viewing the URLhaus database entry for http://imuba.metodista.org.br/b/fBY0JW2ecXebkSHJ5uOUW83BwLE41h/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1993830
URL: http://imuba.metodista.org.br/b/fBY0JW2ecXebkSHJ5uOUW83BwLE41h/?i=1
URL Status:Offline
Host: imuba.metodista.org.br
Date added:2022-01-20 21:00:06 UTC
Last online:2022-01-27 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 21:01:11 UTC to abuse{at}bluehost[dot]com)
Takedown time:6 days, 19 hours, 1 minutes Bad (down since 2022-01-27 16:02:22 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-219822344619859.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 36.67%Heodo
2022-01-218040550167691.xlsxls b443a467b699497e7eabc0c3bdf7bf6a86705a29944ec4ee8e249abb7d17828fVirustotal results 38.98% Heodo
2022-01-212543908884.xlsxls 5733b0f4ff735d3282e9f35d49f2415eb5b786859209d98bdfeb412b55d09958n/a Heodo
2022-01-219892809114047207176.xlsxls 2f51046242d3bd4fc8a58e9ee765707e09c8efbc4bd58b302262b181e9960bf1n/a Heodo
2022-01-219959229256.xlsxls a012d6c3ff9ac12c39dc7e32fb51008897bf8ec0ea7291f80801a2bcdf195cffVirustotal results 40.00%SilentBuilder
2022-01-213551500965178935351.xlsxls 08e9cfb42b052e00b6236416ac76a10be4787f0ec137401a92bce8fed5f84d48n/a Heodo
2022-01-21659411930445486.xlsxls 7ecf0d5b556f400f2d98ef9f7e90373854ec0bda7732f5300223f9c600405235n/aHeodo
2022-01-2192617655726143995633.xlsxls 09cac9c9cb6daf68f51433121e6e0678e7c9703512d4abb09623c1363ab92689n/a Heodo
2022-01-211091872553568.xlsxls d314b3d22bcf83bf1f0dfb95189d8101cf360bfb61041246129f3f95f8de2402n/a Heodo
2022-01-2165259245272794249.xlsxls 6232ba47b182fc60d16bf5b9d41f5dc614f2f348e83414c533df7ccbfb940885Virustotal results 38.98% Heodo
2022-01-218108353173798.xlsxls 702e9fcc889535f1c31e1bad34de6e4456520ca0687f9240a318140924bed3cdn/a Heodo
2022-01-21948916760655237.xlsxls 8b24ef9d0556c1351a46d2e0eb996b21b65638c41dc79cd5b676a79bf0d18a17n/a Heodo
2022-01-2168354440494.xlsxls 9ad38c251b929edaf974d16b81d02e8b87ca16da14c4aa4eea44df09aa210c69Virustotal results 32.20%Heodo
2022-01-2156044583609591795583.xlsxls 3b8dc8f1f75a66d545d45ee9f4160ea99cff4e8cc3f5b265ea27736a3eabf381n/a Heodo
2022-01-212364322709798112.xlsxls 2847438e4b48ee5f630b8d0a3d5361bf4071aa308d8999a69cba995fa548add5n/aSilentBuilder
2022-01-21333505582519975.xlsxls 9eb1535c5aaefb0a3a2b583a4aad8ef65f55b805294dca339ab2f8e632ebffedn/a Heodo
2022-01-211841545293.xlsxls afb4a25125020d107aa065816ff0c80dfbc85d700a654a29b73aa8143c2e909fn/a Heodo
2022-01-2127361433463390.xlsxls 4c2ddd629e265246f75b3e606e6bc899afb3c82020fc9a8f440e7793d6fed047n/a Heodo
2022-01-219543605447.xlsxls 3accfd2337522a6c68a1018979e3ac6603237e13aff0b962ae093662129d8609n/a SilentBuilder
2022-01-211204445152312.xlsxls 4520398e8aeabb1aed9cd4899a2ac014545d9ad9383959288cf2470f9c1c4731n/aHeodo
2022-01-2114968275781189955.xlsxls 1b6134b3db142025a7ebff094a48928647019264965031e089063502561e7ca5Virustotal results 22.03% Heodo
2022-01-2109996626102233397534.xlsxls e57baf9289180802e131633ce599fd55a0a67db3423c45d62f4a88fbf94a0874Virustotal results 18.87% Heodo
2022-01-21718289303661913135.xlsxls 46e07bbc26b054bd482b53d0528f74edc997f805951abdafb92a26dc38b7bf64n/a Heodo
2022-01-214810886815.xlsxls cb72aea24f710a0d9b643de1e759ace18205bc20aa8aa7a91ecf20e556cad41fVirustotal results 22.03% Heodo
2022-01-2198504133745767951.xlsxls 2d259bd946fb388d1a7d75d28ba591aca3377e0ca8b49e0add414fe82b76f483Virustotal results 20.34%SilentBuilder
2022-01-20081735315535196.xlsxls 2181997083632b17484474d7152e18c8a65175b823c871b164d15d2e20a8ae16Virustotal results 22.03%SilentBuilder
2022-01-2087819406831641867345.xlsxls 39123bd1932920eca6749593bee628c405f8bb88114d8647a5d9db8b5914f46cn/a Heodo
2022-01-207719955264.xlsxls 79ab6a611483efd4c9e4394ac5c6a91c458857820c4c4b9bdecf0cab92acf8f2n/a Heodo
2022-01-20401423338718233.xlsxls 1aa1e797bd106f28bc73e4a09bd4d3eb7a13943ef42f06bda76c41fbca54d0ben/aHeodo
2022-01-20326670811632.xlsxls a72795a18fa2b90928f307e227b1f1a57590672870b3acc9e8cb0eb4d38bdbffn/a Heodo
2022-01-200012720455219.xlsxls 8a39d34f5c3133db2f6137b02545e312f05bbdabceda4bd830948380fa4c98c7n/a Heodo
2022-01-20015370882237887984.xlsxls 0aa692cc9abe6360ac72502a9f27fb0e3d401153dfe067524c82c56b7e5f8625n/aHeodo
2022-01-20276568392241206927.xlsxls 423c9fe2d7c27c2f91785e754d0281d61626e45074695a9ad965ea73bba4b93cn/aHeodo
2022-01-20429814090116690417.xlsxls 817f4c96e056390228a3d9ce57239ad521627a3617b13e4043dc99c91569ffccn/a Heodo
2022-01-20001172765632454340.xlsxls 8a07b30e84df7c4db85691e055e4f39fb78621392b7a282b3b64d13a675e14b1n/a Heodo
2022-01-20451940142786451.xlsxls 1d51a274899e8d9f5f0d731c91c8308a7437c80c22a0d67f92aa4ed958175e85n/aHeodo
2022-01-2083497092105.xlsxls 05a911b6500c48bd6eac6fabddeab2bfb919a6bc513ff4a8265e5c77e12e03a5n/a Heodo