URLhaus Database

You are currently viewing the URLhaus database entry for http://fontecmobile.com/pk/TsR23QKKRQFRUFmFgQ2fIGkkk7Vg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2119220
URL: http://fontecmobile.com/pk/TsR23QKKRQFRUFmFgQ2fIGkkk7Vg/
URL Status:Offline
Host: fontecmobile.com
Date added:2022-03-29 13:00:06 UTC
Last online:2022-05-28 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 13:01:05 UTC to abuse{at}hivelocity[dot]net)
Takedown time:2 months, 0 days, 1 hours, 38 minutes Bad (down since 2022-05-28 14:39:31 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31FM-598935452.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31FOX-1684820440.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231Virustotal results 40.98% Heodo
2022-03-31LK-46595617298602.xlsmxlsm a1057f814e603d7b7ff7b711305cac0ef15e48b78499802d411424a19ee235f8n/a Heodo
2022-03-31PVY-606357389.xlsmxlsm d496d617d84291189c4e523cd4b174b705c401ea76c1782f79077eca4eef5512n/a Heodo
2022-03-31GN-80955879900.xlsmxlsm ed2c24997ee2d47a9cc1d73571d3466166ce479c5bc10602b744894b32f9a009n/a Heodo
2022-03-31UVS-64073182134.xlsmxlsm b7434efd7fea43c4a794bcb8e1e055804c16bb20b9bef7bbb1c06b5bc23f419an/a Heodo
2022-03-31AIN-94322970.xlsmxlsm 6102217f21897ac71dc164ee9cb69526d874d45e748754b44309ae2b1d620880Virustotal results 43.33% Heodo
2022-03-31VC-1271067956.xlsmxlsm 83071445fecb136d595c8b4c6edbe66c5127e003402a4a41ccaab915687ec19cn/a Heodo
2022-03-31HRQ-052565180091106.xlsmxlsm 02830d05c8978247bcf9d67de7de69472a79c9f8c2a34c6e19174da73f50f627n/a Heodo
2022-03-31UVC-467790178103.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31RAU-77832711863.xlsmxlsm 08e924859a3a3f17c099cca75fbb3cfd7f8cd726fa2e89fb47ff02f9687143baVirustotal results 38.10% Heodo
2022-03-30FKP-20067739.xlsmxlsm 02f7ef1691ec8641839243cd9f60e615e9aa574f15080676df8358547eacebdan/a Heodo
2022-03-30GI-87641009791196.xlsmxlsm 0d52cf42b7a5f7ec21d78ec1ab0861571f4136b9d08a6de2c4baea447cac0a6an/a Heodo
2022-03-30TFO-91633786.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30WSD-2521930182.xlsxls 82be92d18fb73fad9b6f0e90da074abbf2aaffd91c4493491620452f19bd281dVirustotal results 26.67%SilentBuilder
2022-03-30KP-076877314819428.xlsxls dd89ded2be5b0a176d6a4d7e4d75f19fd83294a5b0a6da3fcaf12119bbf6f6f2Virustotal results 28.33% SilentBuilder
2022-03-29n/ahtml 0e19714e49177eb1bed7a7662e9be9e79af205926e495bfd2cd791bd85592ce7n/a