URLhaus Database

You are currently viewing the URLhaus database entry for http://blumer.com.br/lasc/0Gu6EIpjaQF9k/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2119446
URL: http://blumer.com.br/lasc/0Gu6EIpjaQF9k/
URL Status:Offline
Host: blumer.com.br
Date added:2022-03-29 15:07:08 UTC
Last online:2022-06-13 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 15:08:07 UTC to hostmaster{at}registro[dot]br)
Takedown time:2 months, 15 days, 22 hours, 26 minutes Bad (down since 2022-06-13 13:34:14 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31VD-528301905782780.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31UJK-464548979726726.xlsmxlsm 97f11e4cd509aefb731d8b1a4b299c8ab4096e270f05f52d8e0eb6d2366fa501Virustotal results 38.71% Heodo
2022-03-31DPW-78614337.xlsmxlsm 4d68481027dc3987acbc7b6e5a8e958cfdcee70287facb9764a512bcf99b1798n/a Heodo
2022-03-31XSA-3900340167394.xlsmxlsm 54bb2433c32ae91e6033d49276536fd303652e555e7d1cdf5e1aa0bf9f483d18Virustotal results 40.32% Heodo
2022-03-31QDF-24471401823.xlsmxlsm bb415157a1b9bbe60b44a718eaed436370f6a07df786986c3adde6f5f22c12feVirustotal results 39.68% Heodo
2022-03-31FHK-835674532.xlsmxlsm 6102217f21897ac71dc164ee9cb69526d874d45e748754b44309ae2b1d620880Virustotal results 43.33% Heodo
2022-03-31JZM-31294537332.xlsmxlsm 4f1ab8d0a0a6f8a7964b32b8a4bdd94bad95e6774501cf7685028a40efc761e2n/a Heodo
2022-03-31LFO-4930441464240.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31TMO-0766657.xlsmxlsm 5c682f8054f1b9bb175d9a5784b8fd5bc06364ddf2b802d9aa5fa0abe6cb3a33n/a Heodo
2022-03-30IJ-246357867642729.xlsmxlsm 3bfd193ea92a687030d7b2fb3354e52980ad28ba1cae92579b53f5473b44f37an/a Heodo
2022-03-30ED-81983639.xlsmxlsm ae3937925f18c7db77b2fd19394cb114cb460741dfa2b7c5bd10de9c5c2e35fdVirustotal results 33.87% Heodo
2022-03-30XOE-81470331899.xlsmxlsm a9850d81856c9d96fc75ccfe0a62c2142422d5feb66ad218a0b057a52bc4c554n/a Heodo
2022-03-30BN-38195110535.xlsxls c83aefdafdc478ffff051002d1c7b4675c068648d57fca17f788d575ce297596Virustotal results 28.33%SilentBuilder
2022-03-30BG-1282784619.xlsxls 7813b5f2ba1876b183aec911e5a55402903c7b4702fef4c3c0055557490ef04aVirustotal results 28.33%SilentBuilder
2022-03-29n/ahtml 3d5c61c1444e8f11475296b629c64c7d43cdb914e9381004f979d41d33a8e359n/a