URLhaus Database

You are currently viewing the URLhaus database entry for http://empowercampus.com.br/wp-includes/nN1BLa70Fo8ZJ590P/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120093
URL: http://empowercampus.com.br/wp-includes/nN1BLa70Fo8ZJ590P/
URL Status:Offline
Host: empowercampus.com.br
Date added:2022-03-29 17:03:05 UTC
Last online:2022-04-05 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 17:04:05 UTC to abuse{at}bluehost[dot]com)
Takedown time:6 days, 9 hours, 15 minutes Bad (down since 2022-04-05 02:19:41 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31GT-8284771968.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31KXP-1907890809233.xlsmxlsm 97f11e4cd509aefb731d8b1a4b299c8ab4096e270f05f52d8e0eb6d2366fa501Virustotal results 38.71% Heodo
2022-03-31KLG-88811535.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31ATK-253376517897787.xlsmxlsm 6102217f21897ac71dc164ee9cb69526d874d45e748754b44309ae2b1d620880n/a Heodo
2022-03-31LM-078061586162.xlsmxlsm 8ffdaa8f731fe2148ad8c7dd79ce44c3dc17eadb46af64c64a76395fd0e629acVirustotal results 40.00% Heodo
2022-03-31DG-083946427518832.xlsmxlsm a099f9c9c8eff7049da288a1205f1c0ccd52a4954930cabdd7a00dafbe8bbe6dn/a Heodo
2022-03-31ODL-60968211.xlsmxlsm 4bf2a2327ebd2d1421b849168375d718ca7eedfca6a369b4d947836eba831db3Virustotal results 38.10% Heodo
2022-03-31IFA-09797756.xlsmxlsm 52939ecf287fe6bf3435960c423bf17f7ea8452f102024e9aca86cf806fdd533n/a Heodo
2022-03-31JZ-9576881.xlsmxlsm f93f882fe4bac2b1210512c64a2985c99282b49a95a2aaa3bfcf6865d6dd0056n/a Heodo
2022-03-30GL-06066755.xlsmxlsm 82d6d535c5748ff75ce83fe2ae2829986ec6eddb9cf2d9b7e71f1ade3fd92c57Virustotal results 39.68% Heodo
2022-03-30MB-132761407947.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30XPZ-647776256.xlsmxlsm 0d52cf42b7a5f7ec21d78ec1ab0861571f4136b9d08a6de2c4baea447cac0a6an/a Heodo
2022-03-30CJB-3981588773987.xlsmxlsm 70c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080Virustotal results 33.87% Heodo
2022-03-30ES-6290602.xlsxls 46218e7a1f860f4758adfd19dc3b12e27771a613ca00f687ccbe48a0c275f83en/aHeodo
2022-03-30DU-41618734594377.xlsxls dd89ded2be5b0a176d6a4d7e4d75f19fd83294a5b0a6da3fcaf12119bbf6f6f2Virustotal results 28.33% SilentBuilder
2022-03-29n/ahtml a3defe5c26cd7334ff8ed879e4cbc0dc913d6db853e81ae8573dc81f21fa0c57n/a