URLhaus Database

You are currently viewing the URLhaus database entry for http://escueladecinemza.com.ar/_installation/mavKbOyR3ru0TK7X8UwbSCe2ayux/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2119528
URL: http://escueladecinemza.com.ar/_installation/mavKbOyR3ru0TK7X8UwbSCe2ayux/
URL Status:Offline
Host: escueladecinemza.com.ar
Date added:2022-03-29 16:05:08 UTC
Last online:2022-04-23 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 16:06:10 UTC to abuse{at}hostmar[dot]com,abuse{at}dattatec[dot]com,pablo[dot]pepe{at}adinet[dot]com[dot]uy)
Takedown time:24 days, 9 hours, 11 minutes Bad (down since 2022-04-23 01:17:17 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31XNF-2045569826.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 37.10% Heodo
2022-03-31HF-594837117407447.xlsmxlsm b0fa5dda99558a54917cc9a5f6269d440cd8b30ed825f72c837d6e4044d9f628n/a Heodo
2022-03-31NM-26455275712.xlsmxlsm a7ae8fb40c5d93e9ddbfc68b000b65ba19b085e7a19d3a5d9bef1c243a6add91Virustotal results 43.55% Heodo
2022-03-31SM-3544970525.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31II-12912582.xlsmxlsm 41f790fa1e0f18e897bdad1de2c9452310c964ab0c50e831d9c1150af849edf4Virustotal results 41.67% Heodo
2022-03-31HI-954246095.xlsmxlsm 9490224310276e55dea4f02cf1d9c3c81919929e8abc13c37b670025f1f7a3d0n/a Heodo
2022-03-31OUO-489371894.xlsmxlsm 65b87a95369159fb3d54556f3f316f9e13eadd8b95e9e13f6a8d9cc79f43a8e6Virustotal results 40.68% Heodo
2022-03-31NML-7472889.xlsmxlsm 4409b097292f1ed1adedbae38fcecf71370a64209f9bb5ffff019b71e8a88533n/a Heodo
2022-03-31OFR-12393804341.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31DM-6501483936184.xlsmxlsm db67f0509c5f982c9eb1fab5a17d14ea07d5a1e13b2f5ee3b35ccf93700588e4n/a Heodo
2022-03-31NN-050612766610.xlsmxlsm 08e924859a3a3f17c099cca75fbb3cfd7f8cd726fa2e89fb47ff02f9687143ban/a Heodo
2022-03-30ZTZ-69904367060.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30RGU-25349397552.xlsmxlsm fd0dfb80a1cb4bbdef0cf9b9a2503563ed8679d88a305b246dce39b58a105bf7Virustotal results 31.67%Heodo
2022-03-30YEZ-058619840.xlsxls 82be92d18fb73fad9b6f0e90da074abbf2aaffd91c4493491620452f19bd281dVirustotal results 26.67%SilentBuilder
2022-03-29n/ahtml c12b7e4e0cb973427105a9cbde87f7ec52b4de5697d359f8305736214a99751en/a