URLhaus Database

You are currently viewing the URLhaus database entry for http://duosmart.se/log/E0aRtV0qiCJF/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120179
URL: http://duosmart.se/log/E0aRtV0qiCJF/
URL Status:Offline
Host: duosmart.se
Date added:2022-03-29 18:05:05 UTC
Last online:2023-01-21 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 18:06:06 UTC to info{at}admax[dot]se)
Takedown time:9 months, 27 days, 17 hours, 16 minutes Bad (down since 2023-01-21 11:22:52 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31WTS-361627445.xlsmxlsm 62ab476e343b12678cf4018d6d930dd8a13ca58be794dcc0cd82e693a7ed2962Virustotal results 36.51% Heodo
2022-03-31MJT-15469036502.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31GX-55249912936.xlsmxlsm 08e64e582d9d42f5f3a21eaff52bcb72b4a3abfc761561ff28f40bf937dedb2cVirustotal results 38.10% Heodo
2022-03-31RD-03593617591.xlsmxlsm 575cdc6658b85600efd2d3c07f461b8adaeb0b181dfacfd318c0806e4915c95bn/a Heodo
2022-03-31RI-677882704.xlsmxlsm 65b87a95369159fb3d54556f3f316f9e13eadd8b95e9e13f6a8d9cc79f43a8e6Virustotal results 40.68% Heodo
2022-03-31IBB-837761078.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564n/a Heodo
2022-03-31EE-207783359375.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231n/a Heodo
2022-03-31JRO-68830411389.xlsmxlsm a1057f814e603d7b7ff7b711305cac0ef15e48b78499802d411424a19ee235f8Virustotal results 34.92% Heodo
2022-03-30MPO-5052964015653.xlsmxlsm f6d9028f6903f57570a969a97a510120fa11d93ce778cfeac61862c36d6b6bd2Virustotal results 38.98% Heodo
2022-03-30NUW-2721670282.xlsmxlsm 687a158c15f9b76ec9b11906e548b587dcd7cd319e90477c89b1341f5d6b1eben/a Heodo
2022-03-30ZU-455963008229208.xlsmxlsm 70c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080Virustotal results 33.90% Heodo
2022-03-30YJ-28220747.xlsxls f3101b6d16751623f8a025bfbf75ae9a32c68b534dccbab4452ee72a9fbe0f5fVirustotal results 28.33%SilentBuilder
2022-03-30TKP-45960022623232.xlsxls d743d15057637cf8074f2c125e85dec324808dae8860051c978dcda48f641d86Virustotal results 28.81% Heodo
2022-03-29n/ahtml 06aee1d5c3b0652e30731c9d9d503c38cdafebd0af74b3f1c9959e5e46ccc2ecn/a