URLhaus Database

You are currently viewing the URLhaus database entry for https://camaravotuporanga.sp.gov.br/conteudo/LFT3r6eLqdvHvD/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2109272
URL: https://camaravotuporanga.sp.gov.br/conteudo/LFT3r6eLqdvHvD/
URL Status:Offline
Host: camaravotuporanga.sp.gov.br
Date added:2022-03-21 14:20:09 UTC
Last online:2022-03-21 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-21 14:21:23 UTC to abuse{at}bluehost[dot]com)
Takedown time:6 hours, 41 minutes Good (down since 2022-03-21 21:02:55 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-21DyldhTrxrYdpn4Bf.dlldll 22bf6e59e5e9a33eba12805f122146a29e9100a4780b6dc329bcc3441ac1c32fVirustotal results 22.06% Heodo
2022-03-21MvjO9pOqELAqA.dlldll cfb9e6fb19fd045aec698587513dd58f2ffc5d6918bdc89eaccdc35ef41ae195n/a Heodo
2022-03-218V4k7cs6yt7Tq.dlldll 5990a872b77b153ee81dc1c05b0a3c41bc09e4b271c9a2ca82b14377f2b16121Virustotal results 33.82% Heodo
2022-03-21ViHJXJw.dlldll ef535da3532a8ccaeb526b91e8ccc64cc28992072e409159e3b4dcfee1229241n/aHeodo
2022-03-2119boWGBCyfyDoC5iodu.dlldll 2a35e496e5dc53dc619d935f2f7ffc9508b078917519bdeb174784cdddab824eVirustotal results 30.88% Heodo
2022-03-218E6jfil5w6HNZ3B3q6x.dlldll 860e3d6f1bbe79105ccbc22da4b38a982e03adcb9244b976d4f4ac38d6a7eeabn/a Heodo
2022-03-218xPrpfg.dlldll 97d8ea058be29f1ca249f0d3621ae7b53a1f3481e0474d1bee3d51b2c55f806bVirustotal results 22.06% Heodo
2022-03-21tIwnaeiWVl1eQ7.dlldll f85faa3cc6f9563086250e27424bb49aaa950d930b773d6d16f62e82f49e6593n/a Heodo