URLhaus Database

You are currently viewing the URLhaus database entry for https://amplamaisbeneficios.com.br/contratos/MWnnZG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2101667
URL: https://amplamaisbeneficios.com.br/contratos/MWnnZG/
URL Status:Offline
Host: amplamaisbeneficios.com.br
Date added:2022-03-17 08:58:13 UTC
Last online:2022-03-17 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-17 08:59:16 UTC to abuse{at}hospedagem[dot]net)
Takedown time:11 hours, 1 minutes Good (down since 2022-03-17 20:01:00 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-17eoR0yoJrG00Dvb7oN0nwXayHWmN7B5MnYYd.dlldll b3d0dae65296c76f0204f75c5e6b9c75fdfe3f8a37ef8b365430b8f74890b579Virustotal results 22.39% Heodo
2022-03-179V48RMKjlQUGsU9dwwPInm.dlldll 05ceb6a38d3d2ae1935616b4993359563f45b7d357b84ca0368874e350bc2f31n/a Heodo
2022-03-17Cf0hShCD9MqzoRTVBWgSkEFpgJGHwSo00GR.dlldll 2567299cc5b8a036d6f47ae1383191e00520145fcd3dc4f9990f8df3ebdd7d3bn/a Heodo
2022-03-1700WHFo9UZ8FjGEehg4FTjUynznvEdQoGm.dlldll b780a7a3a6d6225ee9f46eca258658b586f58e11e19cdc98f86e90e62a364a6fVirustotal results 11.94% Heodo
2022-03-17r4arJvddcXsrKUf4VyL6lcmgoIkxLjrGAt.dlldll 6240b1382d1b514d36ac1f42a4b72d23391da891b201e28c102586ecb32f988cn/a Heodo
2022-03-17CC0b2ImMmHkRYJUefzAO8etlwgUCjm.dlldll 6f6e4f987e501839b775b7b5747d4aa26cf8986e635669f4ba4a22f303c4ca63Virustotal results 23.88% Heodo
2022-03-17U5vqIqMX4BjwDetHmDQGd1tA3BHHww.dlldll 3e8632cf50a1f6550d9cced568e7d48fcd9080ea76fb88a1d1c3d6210bcb1053n/a Heodo
2022-03-17Fys80jLa2Dg7zQXiUtnJGVmyp.dlldll 125f6cc3e582731abc8a2126c9c5048f336e18cf40ecee377a6321d5272d049cn/a Heodo
2022-03-17HdX5JSZFq3nKH3LO1v4nfsV216KwNXk.dlldll 64b826abff89032148a4d12d7d253587f2b5152f084ffecd33408561abd2fce7n/a Heodo
2022-03-17u9wqokOM51Yvk80j9kcoifAJyg0MmOGKe.dlldll 9691d4f25c0d4e609cf1ccc78769a05a447d358242216d23b8dcdc8e7222581dVirustotal results 11.94% Heodo
2022-03-17E7yaQf1Z0sVh8mYpZSN.dlldll 70710a581743b7e83f350348951a523114b71f5f0a1b2c4d4a713031f7a62695n/a Heodo
2022-03-17GFLbscV1AntRvQZ162Q48nGtZN.dlldll 083d457d208ad35fa8a86dc39bfc32d43a2feffa59d698736d66c0fda6253af9n/a Heodo
2022-03-1777bnYEfAOL.dlldll b44c1f302cd49fe4bceb2afffd03dc87234eaaef6779dc0588ef965afd058311Virustotal results 14.93% Heodo
2022-03-17CL3pSol.dlldll f44668570cfdc87c702bde33204ba646f9d384ea5dd02480d05aac69ad133dcaVirustotal results 11.94%Heodo
2022-03-17iNdGqntKg0Yi5pDJH7IL.dlldll 7554407aaa07f67c2e79ddab35b39e5bd5474fbb2021456b5ef3bf4ef9e7940cVirustotal results 13.43% Heodo
2022-03-17VG2q0YYYflZK6PS93ynSDfJ.dlldll c0c59f4c6d836d48e1d8633a01f120d39a645e45d378fa0fd5b7ccec1725a132n/a Heodo