URLhaus Database

You are currently viewing the URLhaus database entry for http://economizesa.com.br/cgi-bin/gZSppeiuOneFdNZfubX2iQ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120217
URL: http://economizesa.com.br/cgi-bin/gZSppeiuOneFdNZfubX2iQ/
URL Status:Offline
Host: economizesa.com.br
Date added:2022-03-29 18:25:06 UTC
Last online:2022-04-03 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 18:26:05 UTC to abuse{at}hostgator[dot]com)
Takedown time:5 days, 2 hours, 59 minutes Bad (down since 2022-04-03 21:25:58 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31LLI-483702488059.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31HKB-9611841.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31UT-0073933.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31MW-845275797749844.xlsmxlsm 4e313f9f3abefe7d2a05b2d9ce9dae1683f91278ec0ac7cff68b9f232ff656dcn/a Heodo
2022-03-31OC-84902981795.xlsmxlsm 41f790fa1e0f18e897bdad1de2c9452310c964ab0c50e831d9c1150af849edf4Virustotal results 41.67% Heodo
2022-03-31MX-479893672459298.xlsmxlsm 30deb7a7086f74317285271a2e26e40dc43b461a1a77c77480ea742b02cbe51fVirustotal results 38.10% Heodo
2022-03-31HG-05739961686.xlsmxlsm f1a59459dc11d8edab701cdd7610dd6310993ddb1aa04ab43f8fc3536040700dn/a Heodo
2022-03-31RMB-02539217143683.xlsmxlsm 4bf2a2327ebd2d1421b849168375d718ca7eedfca6a369b4d947836eba831db3n/a Heodo
2022-03-31LJD-8347596516.xlsmxlsm 0c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3Virustotal results 36.51% Heodo
2022-03-31DXR-20582338705.xlsmxlsm f93f882fe4bac2b1210512c64a2985c99282b49a95a2aaa3bfcf6865d6dd0056n/a Heodo
2022-03-30ZZ-23463925741.xlsmxlsm 2b1f1f87033e83e264f05939f180b63165e067861f9c6f1253aedc9c9e1efb6en/a Heodo
2022-03-30DZN-4437548837.xlsmxlsm 687a158c15f9b76ec9b11906e548b587dcd7cd319e90477c89b1341f5d6b1eben/a Heodo
2022-03-30EBZ-8072100.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51Virustotal results 33.87% Heodo
2022-03-30HU-360737267135.xlsxls 2fb5d6b4684b1f180fd682f92fc346420c16376d64b8b8ec6b0564247000dc58n/a SilentBuilder
2022-03-30MW-64568276658.xlsxls dd89ded2be5b0a176d6a4d7e4d75f19fd83294a5b0a6da3fcaf12119bbf6f6f2n/a SilentBuilder
2022-03-29n/ahtml ca9559148ebd55f9dc72971c2c8cd87e4f648755a175aa5322fd50d02869bca4n/a