URLhaus Database

You are currently viewing the URLhaus database entry for http://www.chemsky.tn/64prPlDhbugztyb2Zl/xjvFXPUX7XeoPWTqSQ2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120577
URL: http://www.chemsky.tn/64prPlDhbugztyb2Zl/xjvFXPUX7XeoPWTqSQ2/
URL Status:Offline
Host: www.chemsky.tn
Date added:2022-03-29 21:21:04 UTC
Last online:2025-01-26 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 21:22:06 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:2 years, 10 months, 13 days, 17 hours, 58 minutes Bad (down since 2025-01-26 15:20:20 UTC)
Tags:emotet link epoch4 heodo link redir-doc xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31EEO-8053211.xlsmxlsm 64d92f79a2d87571d428b7b19ef4f5c1680c24c8952a2f46b84f217cfba19766Virustotal results 39.68% Heodo
2022-03-31MH-42345924833193.xlsmxlsm a395d2ca627270c1b53481050d39c6395c778682e98aeedcb00d1f68fd1ec23fn/a Heodo
2022-03-31OR-206170613639388.xlsmxlsm 7ca9c48ab76e34256ebad65fa28f1eb8b3da601b413e19e03a1442046b3aefean/a Heodo
2022-03-31MPQ-332846656157093.xlsmxlsm e59276e130a11d91bdcec998cec6de7401536612687c58e70cae7763d17b7726n/a Heodo
2022-03-31IY-09796436917609.xlsmxlsm 0a5cc2b92b228a835529cc7fa4fe679ebabedd3166e10b19c80c5f4d6795f4f1n/a Heodo
2022-03-31CFM-2844436.xlsmxlsm da7fdf635815dc2ebb6fe69fa637d655ab6667aa7195ba89002790a17c19dc19n/a Heodo
2022-03-31UJR-37222188150753.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31HJ-737351789.xlsmxlsm c91108a630fb89be6e53e693ea5240bc7be18d74be099b965d92647bd239c6bfVirustotal results 41.94% Heodo
2022-03-31JGN-687967630859.xlsmxlsm 63ba5c63fa8f569c1870ab57faeeec2933a7bdb28c90458f6c5373f1a71dcef4Virustotal results 36.51% Heodo
2022-03-31SRD-5237932394.xlsmxlsm b5df411a9037fcd4dc6b3e92145aae14064c20edf7476a543c778bdb8af22600Virustotal results 36.51% Heodo
2022-03-31BK-574673817194.xlsmxlsm bb415157a1b9bbe60b44a718eaed436370f6a07df786986c3adde6f5f22c12feVirustotal results 39.68% Heodo
2022-03-31UTF-7470654371448.xlsmxlsm 4bf2a2327ebd2d1421b849168375d718ca7eedfca6a369b4d947836eba831db3Virustotal results 38.10% Heodo
2022-03-31UC-9974788.xlsmxlsm 52f73166b6afefeb75e3e2459eb3b8a48e0c9309f83620f4fdbcfcbedaff3f66n/a Heodo
2022-03-31PVY-878891277910758.xlsmxlsm 70c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080Virustotal results 43.55% Heodo
2022-03-31YK-790356645065.xlsmxlsm 93e06d8850641586fe31c662da490f8ff442f4f86021f50799e1174dcace1f72n/a Heodo
2022-03-30MWT-501125747.xlsmxlsm 4de0ee96907c9c431a85d1a6b259851537ab1e75656a55ec2f03b2d8d06326b5n/a Heodo
2022-03-30PEB-80881855.xlsmxlsm 533372e6130ad44ced6eae30ab3af8be4ae172cc7585719b61074bb861f2dbben/a Heodo
2022-03-30IU-06769440936.xlsmxlsm 9e78d6dc74b334eb5028dc17bee0a1a27fe2636eeefce10ba2adc3244ac9de2bVirustotal results 37.10%Heodo
2022-03-30XV-2683994800.xlsxls d743d15057637cf8074f2c125e85dec324808dae8860051c978dcda48f641d86Virustotal results 28.81% Heodo
2022-03-29n/ahtml fa6bf80111d4292f9acf1fbbf8096bcb0a3e965e9d33cce509ea353621f13364n/a