URLhaus Database

You are currently viewing the URLhaus database entry for http://economizesa.com.br/cgi-bin/gZSppeiuOneFdNZfubX2iQ/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120218
URL: http://economizesa.com.br/cgi-bin/gZSppeiuOneFdNZfubX2iQ/?i=1
URL Status:Offline
Host: economizesa.com.br
Date added:2022-03-29 18:25:06 UTC
Last online:2022-04-03 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 18:26:05 UTC to abuse{at}hostgator[dot]com)
Takedown time:5 days, 2 hours, 59 minutes Bad (down since 2022-04-03 21:25:45 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31CBI-493545719888.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31AC-1286533.xlsmxlsm c171d718d9aecb5ad1e27309660f8da7a568f9798e03d4c6683d7825b5a122c9n/a Heodo
2022-03-31TK-92716229.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31CXB-464719973792.xlsmxlsm b0fa5dda99558a54917cc9a5f6269d440cd8b30ed825f72c837d6e4044d9f628Virustotal results 42.62% Heodo
2022-03-31AIA-4223510747.xlsmxlsm 62ab476e343b12678cf4018d6d930dd8a13ca58be794dcc0cd82e693a7ed2962Virustotal results 36.51% Heodo
2022-03-31UT-0073933.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31OC-84902981795.xlsmxlsm 41f790fa1e0f18e897bdad1de2c9452310c964ab0c50e831d9c1150af849edf4Virustotal results 41.67% Heodo
2022-03-31ZB-23201587826.xlsmxlsm db67f0509c5f982c9eb1fab5a17d14ea07d5a1e13b2f5ee3b35ccf93700588e4Virustotal results 38.71% Heodo
2022-03-31MX-479893672459298.xlsmxlsm 30deb7a7086f74317285271a2e26e40dc43b461a1a77c77480ea742b02cbe51fVirustotal results 38.10% Heodo
2022-03-31SG-72055158.xlsmxlsm 265f4ce97b8c4a17c8f27359496edc3f97e2e6926a267fba16797dd5c6e3a70bVirustotal results 45.16% Heodo
2022-03-31LYY-62848511.xlsmxlsm 52f73166b6afefeb75e3e2459eb3b8a48e0c9309f83620f4fdbcfcbedaff3f66n/a Heodo
2022-03-31YVR-02279798212.xlsmxlsm 70c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080Virustotal results 43.55% Heodo
2022-03-31DXR-20582338705.xlsmxlsm f93f882fe4bac2b1210512c64a2985c99282b49a95a2aaa3bfcf6865d6dd0056n/a Heodo
2022-03-30UCH-445320811482.xlsmxlsm 02f7ef1691ec8641839243cd9f60e615e9aa574f15080676df8358547eacebdaVirustotal results 40.98% Heodo
2022-03-30DZN-4437548837.xlsmxlsm 687a158c15f9b76ec9b11906e548b587dcd7cd319e90477c89b1341f5d6b1eben/a Heodo
2022-03-30QOW-595042415485.xlsmxlsm 7b790cb9f037644da2aa7daf038bef787f020bc8aad1932fb1e8c4c5ab3b4766Virustotal results 32.26% Heodo
2022-03-30DFN-407957550.xlsxls c37ffc0e87ede2e654c4112c8d1b9172041a21bc4174b248ee2c81af738bcaf5n/a Heodo
2022-03-307732070439805166.xlsxls 00f6421fe8f4847be025bde29b82ccb92d3bb76d95ca4d36c6b87d9f173d3d01Virustotal results 26.67% SilentBuilder
2022-03-30844208044525522.xlsxls afab90f284e5f643a8fa8a6eafd154175a22394254db310f0dcddc607a5ed468n/a Heodo
2022-03-30746798761914.xlsxls de03ab1d198136ce8f5fba27d87ceed99696fc46da6cb9ce7614b3824e02dec1Virustotal results 25.00%SilentBuilder
2022-03-30228039569341.xlsxls 517ad9640522ddd6180f39e1bdf5dff22b469b04cba6c10f4c0d6e3bcca16b19n/a SilentBuilder
2022-03-30197251005851454.xlsxls aa86d1be623622ae373fc9dcfb7365d513d0e273891e34b480ab2d7b10d6a7bbVirustotal results 26.67% Heodo
2022-03-30469099452108177.xlsxls 203c1be5a8f01fb454836563bd0b29fef4caf2983afe37d1cd46feb86d3eb83fn/a SilentBuilder
2022-03-302765570282757332315.xlsxls a1ba5ac09b442e2f6efad0a758c88012fb154fbe7efaa640758103f3b1ba01a9n/aSilentBuilder
2022-03-3084561316175801.xlsxls 69d8211fe32a1c511c6fd358005bceb8e19e01d9cc927c01b9f0760c13b75d6cn/a Heodo
2022-03-30547444773950664.xlsxls 680f0f283478f314621677f9fa1388a88017cd003d7173163cdcc4f16cbedfddVirustotal results 24.56% SilentBuilder
2022-03-304184314033456293.xlsxls 92b068c533ae97aca8470cdbc6e8d3bf23caaf19f593b462e8352e58cf21c352n/a SilentBuilder
2022-03-3047167850349.xlsxls bcef9c934fe5112b2ca48f5a9ea696c33d3114b345c63d7c331254037faff1a0n/a SilentBuilder
2022-03-304568139613885170393.xlsxls 9446c54eb7a685ed2b0425e43e20af5e527530c1fe26ed9bfc6764c24dc44c8fn/a SilentBuilder
2022-03-3003458577153625900037.xlsxls 14bdb02d74882b5302b1c28f4beef21d98c62c276f039562eac7c9b9b008deean/a SilentBuilder
2022-03-306131119667343.xlsxls 53a8cf28fa59ff225a7a58d4ab09db8ad23bed8afdb2ae42232a8f11acf3553bn/a SilentBuilder
2022-03-30401656930813.xlsxls 4148c2fcfeafb479b13ec8c2b305fd2ebf671b61fe044476575a5b2be2b929dbn/a SilentBuilder
2022-03-30098222985215.xlsxls f30f9c9233859f2549dc271d14fd86bdebcc72c70e9c51ba4606b75cbf745473n/a SilentBuilder
2022-03-3049135395963861501.xlsxls 66115ef823bbc6b8007ee6b6508af174566899af8df63ea1f6707b293153f2bdn/a SilentBuilder
2022-03-304344059787779.xlsxls a612e9a7b8f4a08f1b73f5a7e07b586913f327d8bd789ca7ce7c1e6e80883f91n/a SilentBuilder
2022-03-3053386969637225846735.xlsxls 385fc2720a678cc5b53d3d58caa225e7fa24e29c86ff6acecb609afb7659caa4n/a SilentBuilder
2022-03-304930357817.xlsxls c12be159aaffc14d6672e97c280868c12ceadd8a60e48769ddefa0d64313e18an/a SilentBuilder
2022-03-30663486137780.xlsxls 01409366f137f73a060ee83b1e33ce1812614f9182737ebfa8b621d931f2aef4Virustotal results 23.33% SilentBuilder
2022-03-309954264814.xlsxls 8bc576d7a20e6614e7b139a3ee525c37e46da65fcd2d59a8d4adf1b57354ae05n/a SilentBuilder
2022-03-292262059484.xlsxls c7e78d00cf4d1eda853fe906d22b26c5e9a03e67f2ab9f2755ee7b7fb8c54ee6n/a SilentBuilder
2022-03-291267345568.xlsxls 4db12a7472a2427ea88cb16a24494b46824688abd29824abffa27f9366e46f30n/a SilentBuilder
2022-03-292122926490.xlsxls b26329204d4a737b51b710c6fb4ca573291be87a1fb5606f0e0b75987c09908fVirustotal results 23.33% SilentBuilder
2022-03-29003308283593827511.xlsxls a679c80a799b163cf0ad3f464c4a1bc023c7d6dd0715662da376d6260a4b9040Virustotal results 24.56% Heodo
2022-03-292607259355542203.xlsxls 6ddbab092ea3334218e1a42e8c21dacd63db67a4c382a78095e0712c06d9a667n/a SilentBuilder
2022-03-2942307640493225426795.xlsxls 344d265223d65f14fe5e136251216baa48b99ba5e8cb3d985ad294f6e003f2dfn/a SilentBuilder
2022-03-299266684469392197621.xlsxls 54d08522ffbd96a675e5aea3d3658b9aeafed3508940f376269fdebe9a930237Virustotal results 23.33%SilentBuilder
2022-03-2930476325464635.xlsxls 9ee8c765cc806dba9a3cb89ca942431c9b7fd2b539696103f96589c04703aad5n/a Heodo