URLhaus Database

You are currently viewing the URLhaus database entry for http://easassessoria.com.br/erros/G1ncoBjBME4UwaEppe9cApEWqaB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2118002
URL: http://easassessoria.com.br/erros/G1ncoBjBME4UwaEppe9cApEWqaB/
URL Status:Offline
Host: easassessoria.com.br
Date added:2022-03-28 22:57:05 UTC
Last online:2022-04-04 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-28 22:58:06 UTC to abuse{at}hospedagem[dot]net)
Takedown time:6 days, 19 hours, 25 minutes Bad (down since 2022-04-04 18:24:04 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-30JA-200810561099456.xlsmxlsm 4fadf9d0ce08783dd924f9ab1f1691dbdf07251396bb218f92cfef0279739a25Virustotal results 32.26% Heodo
2022-03-30UFX-9549973154170.xlsmxlsm 70c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080Virustotal results 33.90% Heodo
2022-03-30XOS-6471403680155.xlsxls c83aefdafdc478ffff051002d1c7b4675c068648d57fca17f788d575ce297596Virustotal results 28.33%SilentBuilder
2022-03-30EO-80460612193.xlsxls 2fba5997186a1e4e2da7496bd7a1bca3eaf425971cc76dd7be878f3fd88add07n/a SilentBuilder
2022-03-30UL-337078252.xlsxls 7813b5f2ba1876b183aec911e5a55402903c7b4702fef4c3c0055557490ef04aVirustotal results 28.33%SilentBuilder
2022-03-28n/ahtml eb30e08e94ff140f208b0932091014af7c37d86a72206c42414e53b29cea031fn/a