URLhaus Database

You are currently viewing the URLhaus database entry for http://www.cenomp.com.br/templates_c/nZeK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120584
URL: http://www.cenomp.com.br/templates_c/nZeK/
URL Status:Offline
Host: www.cenomp.com.br
Date added:2022-03-29 21:27:05 UTC
Last online:2022-12-08 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 21:28:08 UTC to abuse{at}bluehost[dot]com)
Takedown time:8 months, 13 days, 6 hours, 0 minutes Bad (down since 2022-12-08 03:28:27 UTC)
Tags:emotet link epoch4 heodo link redir-doc xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31HE-01460817382481.xlsmxlsm 4e6c2dd2bb0183aa17caa2084632719d1b9d42cae3e0c96f6770b216822b8d01n/a Heodo
2022-03-31MBA-6361525.xlsmxlsm a395d2ca627270c1b53481050d39c6395c778682e98aeedcb00d1f68fd1ec23fn/a Heodo
2022-03-31MT-436036833.xlsmxlsm c201ae0ab0516a27d14400b4af28d4189bb2c6d8b589c4fadb025c26645f19bfVirustotal results 38.10% Heodo
2022-03-31OZ-3543271.xlsmxlsm a4c90f279a6b95cfa27debaf12cd09e6dd57fb1eb87803667a8b0527c7fc27cen/a Heodo
2022-03-31RBN-0495296.xlsmxlsm 896ef5fb12bd10c84fa96213d6a86aa368388e4806b9c882fd601a113482ff74n/a Heodo
2022-03-31KBI-932593424.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31KV-662380674.xlsmxlsm b0fa5dda99558a54917cc9a5f6269d440cd8b30ed825f72c837d6e4044d9f628n/a Heodo
2022-03-31DFZ-89938459.xlsmxlsm bc2b30e9969aa7dc11544b73955d47d12ec3d2febe998b5cef4b57c89dde7215n/a Heodo
2022-03-31CYD-02824295038.xlsmxlsm 08e64e582d9d42f5f3a21eaff52bcb72b4a3abfc761561ff28f40bf937dedb2cVirustotal results 38.10% Heodo
2022-03-31YL-8105698.xlsmxlsm df344251ca9c5fdc148f67495779187ecfaeb8d12fb21d8fd0d3912176d9728fn/a Heodo
2022-03-31TK-70333659372974.xlsmxlsm eb39b29661d81cbcd7a00f191c61ce9902b80b68e1e03215e56221bfc85863efVirustotal results 39.68% Heodo
2022-03-31RJ-64407474.xlsmxlsm 1307e68be83cfe870bd173adacc15538d13394117209f1df836b2656adb85383n/a Heodo
2022-03-31QRL-1074399984.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564n/a Heodo
2022-03-31ZBC-48394476.xlsmxlsm 6ba49c8a1bc5dddfc74a33d1c6f53df15e682043f2e3e66963ef4577191206cdn/a Heodo
2022-03-31AA-73921044.xlsmxlsm d0e1bf9a8969b0e7856ed1015033cef4c745a120413c76d61b1560e323de2359n/a Heodo
2022-03-30VVJ-7306268436.xlsmxlsm f6d9028f6903f57570a969a97a510120fa11d93ce778cfeac61862c36d6b6bd2Virustotal results 38.98% Heodo
2022-03-30CDZ-252304981.xlsmxlsm 39bbb570609ea300f9d959dcf23f2161043c6dedc230f97e7eab2388db651831Virustotal results 37.10% Heodo
2022-03-30XCX-8996074.xlsmxlsm 2e8dfaff0039f7b69af5f699d0efff85cca1b5dbe2a50082b7ccc49503545053n/a Heodo
2022-03-30FL-37646591634448.xlsxls c37ffc0e87ede2e654c4112c8d1b9172041a21bc4174b248ee2c81af738bcaf5Virustotal results 28.33% Heodo
2022-03-30BY-157989397030.xlsxls d743d15057637cf8074f2c125e85dec324808dae8860051c978dcda48f641d86Virustotal results 28.81% Heodo
2022-03-29n/ahtml 51952f461f4739e463566d63f0af828065789e1011eb8714cc7c7c31d16a6bc2n/a