URLhaus Database

You are currently viewing the URLhaus database entry for http://dn000893.ferozo.com/agenda/y6Yz4Jv1kBEcbpMyDR3Rvb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120515
URL: http://dn000893.ferozo.com/agenda/y6Yz4Jv1kBEcbpMyDR3Rvb/
URL Status:Offline
Host: dn000893.ferozo.com
Date added:2022-03-29 20:29:07 UTC
Last online:2022-04-30 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 20:30:07 UTC to abuse{at}hostmar[dot]com,abuse{at}dattatec[dot]com,pablo[dot]pepe{at}adinet[dot]com[dot]uy)
Takedown time:1 month, 1 days, 4 hours, 49 minutes Bad (down since 2022-04-30 01:19:54 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31YZ-749513542.xlsmxlsm 83a8039af1534f4fc93efcdb7e429c799f144ace1f33b37ca42a57ee7a559499Virustotal results 45.90% Heodo
2022-03-31BWY-968071320177660.xlsmxlsm 0a23b203754e6a043fa99f6cf518c8ffa19a34557a7471edad072d54c4a76dacVirustotal results 42.86% Heodo
2022-03-31BUT-8721312429422.xlsmxlsm 99717c4eea8cfa905a207ea753e12bcd957f480eda47749d5cd5ae2f362a4f7dn/a Heodo
2022-03-31FCH-080161477.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31LG-23072065.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31AUT-878721223297261.xlsmxlsm 2550670f68b05aae7f04bfed13c37b7f3ee48a1677ac9eef2e7c3c0a88aefdffVirustotal results 43.55% Heodo
2022-03-31KVU-08851622.xlsmxlsm 63ba5c63fa8f569c1870ab57faeeec2933a7bdb28c90458f6c5373f1a71dcef4Virustotal results 36.51% Heodo
2022-03-31HH-2644313.xlsmxlsm 409e55effd488af9a3d098060e33fe5d66743135fc711a07d6ce4c57e2f2c2bbn/a Heodo
2022-03-31TF-3764485709435.xlsmxlsm 5285de9e0e5323564d48a5d9fc627190ed9bae90f9c0e818958768b0d7c856b1Virustotal results 36.51% Heodo
2022-03-31LT-997857027.xlsmxlsm d4f941f7232c98be2d39a4a97edcad5b4648430bb60ad5a21747b37e705ff2d2n/a Heodo
2022-03-31PNW-5957833538.xlsmxlsm 4f1ab8d0a0a6f8a7964b32b8a4bdd94bad95e6774501cf7685028a40efc761e2n/a Heodo
2022-03-31UW-43153553.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231n/a Heodo
2022-03-31YHX-30432770331510.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-30II-676184967570.xlsmxlsm 9c9a20409a6f877c7a05d8fea297269be5e70e70ce416ddb6edc5e8d95a88a98Virustotal results 39.34% Heodo
2022-03-30KAS-9191100014618.xlsmxlsm 39bbb570609ea300f9d959dcf23f2161043c6dedc230f97e7eab2388db651831Virustotal results 37.10% Heodo
2022-03-30LM-3353848399798.xlsmxlsm 168a9aa1b5fa37a354fd6ccba71dcd29cbcd503a578504c69feb38bd84a8a691n/a Heodo
2022-03-30HB-792483872008.xlsxls f3101b6d16751623f8a025bfbf75ae9a32c68b534dccbab4452ee72a9fbe0f5fVirustotal results 28.33%SilentBuilder
2022-03-30SRV-0502722.xlsxls bc8049d90da2c6ed214cd043d2d754a1f8fc802010a6367d5cac254aa1853a67Virustotal results 26.67%SilentBuilder
2022-03-29n/ahtml ce560d283d9db5b6261603a030d2dd6ff87e3f593938824e97e0ca8526da897dn/a