URLhaus Database

You are currently viewing the URLhaus database entry for http://emesconcontabil.com.br/wp-admin/ER0hzRIkU0uaw2sZeWqlQuwrx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120134
URL: http://emesconcontabil.com.br/wp-admin/ER0hzRIkU0uaw2sZeWqlQuwrx/
URL Status:Offline
Host: emesconcontabil.com.br
Date added:2022-03-29 17:24:06 UTC
Last online:2022-04-16 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 17:25:07 UTC to hostmaster{at}registro[dot]br)
Takedown time:17 days, 19 hours, 18 minutes Bad (down since 2022-04-16 12:43:14 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31NBK-296477895990254.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31YFO-7718495.xlsmxlsm 97f11e4cd509aefb731d8b1a4b299c8ab4096e270f05f52d8e0eb6d2366fa501Virustotal results 38.71% Heodo
2022-03-31AW-44588902.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31HLV-001077358655.xlsmxlsm b7434efd7fea43c4a794bcb8e1e055804c16bb20b9bef7bbb1c06b5bc23f419an/a Heodo
2022-03-31UU-311551429533875.xlsmxlsm eb39b29661d81cbcd7a00f191c61ce9902b80b68e1e03215e56221bfc85863efVirustotal results 39.68% Heodo
2022-03-31PX-363950497404961.xlsmxlsm 4bf2a2327ebd2d1421b849168375d718ca7eedfca6a369b4d947836eba831db3Virustotal results 38.10% Heodo
2022-03-31WK-160073413082042.xlsmxlsm 52f73166b6afefeb75e3e2459eb3b8a48e0c9309f83620f4fdbcfcbedaff3f66n/a Heodo
2022-03-31QYD-1219301752018.xlsmxlsm 0c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3Virustotal results 36.51% Heodo
2022-03-31JV-05546405.xlsmxlsm 93e06d8850641586fe31c662da490f8ff442f4f86021f50799e1174dcace1f72n/a Heodo
2022-03-30FTR-5507707951932.xlsmxlsm d3ad5641b527c4ec7e77e037ed81f1913c394f063e13677b8744b26fb09bdeceVirustotal results 36.51% Heodo
2022-03-30LO-00695277892.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30GPP-5293101617523.xlsmxlsm a9850d81856c9d96fc75ccfe0a62c2142422d5feb66ad218a0b057a52bc4c554n/a Heodo
2022-03-30ZEM-38121187.xlsxls 1d74cb46d2219761b01e8425e6ec57120fdb867a48735edee3b9bfafd3706caeVirustotal results 25.00% Heodo
2022-03-30QNF-6808943021050.xlsxls dd89ded2be5b0a176d6a4d7e4d75f19fd83294a5b0a6da3fcaf12119bbf6f6f2n/a SilentBuilder
2022-03-29n/ahtml a485412b243dcc531b76d5e337fea1b7b8ca9a4abb9759af228be6e56e4070e3n/a