URLhaus Database

You are currently viewing the URLhaus database entry for http://cloud.contec.pt/ljf3eS/Z53HvyFQaoQwZam1qPJf0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122578
URL: http://cloud.contec.pt/ljf3eS/Z53HvyFQaoQwZam1qPJf0/
URL Status:Offline
Host: cloud.contec.pt
Date added:2022-03-30 13:59:05 UTC
Last online:2022-04-02 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 14:00:07 UTC to abuse{at}contabo[dot]de)
Takedown time:2 days, 19 hours, 45 minutes Poor (down since 2022-04-02 09:45:39 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01GDI-20030753227627.xlsmxlsm 2efeae28ad35e91b7abb28eec555e20e394693d8454514a43fc119fde473348eVirustotal results 42.86% Heodo
2022-04-01UU-43914133435091.xlsmxlsm 60833a18e14a8b4eb21cec280bdac63e8a03eeda78c1c5e0e641624b72000be8n/a Heodo
2022-04-01SRM-3214495669.xlsmxlsm a2088f01e4a3b55cfbccaa117ef5c9ea67bf766a15d6beec4095f966a9fcc4ddVirustotal results 43.33% Heodo
2022-04-01FS-360994652.xlsmxlsm db05585c173bca5c340fd01dffcf23be710be4b482131d5bc16f4eedb265754dVirustotal results 37.70% Heodo
2022-04-01OY-153316127246984.xlsmxlsm 8cfdb13bd3fba245b5e3c5a06b90cdab4f8970b13e3ea5262aeb7bd089474bb3Virustotal results 36.67% Heodo
2022-04-01WJ-52051062094690.xlsmxlsm e659479a435f37e03d325154ad864519c5a6853aac0f16d605d7560f3a4a0863n/a Heodo
2022-04-01SPL-91368874032.xlsmxlsm fdaef695835e1a9e056fe2496ef611e4250388f7712102116b6717894e578f50n/a Heodo
2022-04-01DK-22798672381.xlsmxlsm 5118b85e7ffcf61644564e2660990ff4e6becc430b13aca19a931d25f3d4c1d9Virustotal results 38.10% Heodo
2022-04-01GMB-146858122.xlsmxlsm 21878746d787b1e233ca736e023094af743ff3c853baceaaba65afcd7cdb6823n/a Heodo
2022-04-01FOC-856389748167240.xlsmxlsm c201ae0ab0516a27d14400b4af28d4189bb2c6d8b589c4fadb025c26645f19bfVirustotal results 48.39% Heodo
2022-04-01JE-09969597062.xlsmxlsm e40bfb9b0a236fa78f9150e560fa82b899430dd6cf6da41388a30f8e09496ecen/a c8fc17ff030feb3383d8889f69abbb
2022-04-01MF-7401694.xlsmxlsm e5207cd147b8791ae79d2aad037958c960f6bf8f18c4e4e3749174d0ebd3fb62Virustotal results 47.54% Heodo
2022-04-01RUP-193848252213949.xlsmxlsm b7a2ba71c06e47b7011fb3b7f3a263a34c991d3eead33a69dbcf967bdeda5a96n/a Heodo
2022-04-01WC-432378132.xlsmxlsm 7865998de760d97246decb7fc619579d9389e6c2cdf72097738e48a74a0bafe2n/a Heodo
2022-04-01CT-5854429764.xlsmxlsm 95ef55ebe10de62e86f04fbe1ade582e008dfa6d36bdc7207146525626b6638bn/a Heodo
2022-04-01ZZ-084184755560486.xlsmxlsm 3005686dd6b770a4a0af0ba70ec91ea407d32838aa2acea56c5ab75f2a47ff56n/a Heodo
2022-04-01QX-4705039903.xlsmxlsm 4fa09bf32b85b3833ade1083764b776848c0d1455d84823012134e6297f9c773Virustotal results 37.10% c8fc17ff030feb3383d8889f69abbb
2022-03-31AOZ-38846686105.xlsmxlsm 5131287d80e747b0ac91053a0490859150d9f84995214a9136ed22466de08835Virustotal results 38.10% Heodo
2022-03-31YS-2694781128977.xlsmxlsm 5fb54e96fe17c395fa69dc06933558b083ae9cfb1391218f12c539c2645a8311n/a Heodo
2022-03-31ZIG-46092034228.xlsmxlsm aa3fff2c2d0daf56b10654b5f1f501b45c0cfd50fef9004498bca2a83c359e69Virustotal results 36.51% Heodo
2022-03-31FD-53673736.xlsmxlsm ccd9dcb6dc115061ff6e011cb77ac0c73d785a23c2019aabe11eba9b7500b118Virustotal results 38.10% Heodo
2022-03-31JM-3330596603.xlsmxlsm 64d92f79a2d87571d428b7b19ef4f5c1680c24c8952a2f46b84f217cfba19766Virustotal results 39.68% Heodo
2022-03-31DK-81783730575.xlsmxlsm 36b9445ba8e049935f86955d9c9251334fa60c940b28d69da57f97926e54211fn/a Heodo
2022-03-31UI-50032040768.xlsmxlsm b808345f10c7d203be0ecb6b375c02c5e489567303fc0253558940700b8bf3ban/a Heodo
2022-03-31JA-541918884824.xlsmxlsm c171d718d9aecb5ad1e27309660f8da7a568f9798e03d4c6683d7825b5a122c9n/a Heodo
2022-03-31VUM-04226391973.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31GZ-6043320992291.xlsmxlsm 53ef2d3a553342c46f5d3011cb07634e1f02b36dae99808e47dd459dd384e388n/a Heodo
2022-03-31LU-290726137860689.xlsmxlsm b034cfc88c6603dc0f5519ecba2dbba8c5382b26b8c25da23f8d40368ce8e7b5Virustotal results 33.87% Heodo
2022-03-31NF-5998013.xlsmxlsm d2a2d43a504e399e25c00b0903aa12cf19b7133c168606e1f66fc93323d3f65dVirustotal results 41.94% Heodo
2022-03-31UL-7779325682.xlsmxlsm 41f790fa1e0f18e897bdad1de2c9452310c964ab0c50e831d9c1150af849edf4Virustotal results 41.67% Heodo
2022-03-31TN-9719695962930.xlsmxlsm 30deb7a7086f74317285271a2e26e40dc43b461a1a77c77480ea742b02cbe51fVirustotal results 38.10% Heodo
2022-03-31RS-9722203.xlsmxlsm f1a59459dc11d8edab701cdd7610dd6310993ddb1aa04ab43f8fc3536040700dn/a Heodo
2022-03-31KK-99802229.xlsmxlsm 61ad9b2b8c9707a14412bf30d2e17c11d75dd548e841d9b4eb6299ca1e0456d5Virustotal results 34.92%Heodo
2022-03-31EXV-1488524531.xlsmxlsm 70c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080Virustotal results 43.55% Heodo
2022-03-31ALN-67625673.xlsmxlsm 93e06d8850641586fe31c662da490f8ff442f4f86021f50799e1174dcace1f72n/a Heodo
2022-03-30VM-15226884384.xlsmxlsm 2b1f1f87033e83e264f05939f180b63165e067861f9c6f1253aedc9c9e1efb6en/a Heodo
2022-03-30VNQ-7949494553.xlsmxlsm 4fadf9d0ce08783dd924f9ab1f1691dbdf07251396bb218f92cfef0279739a25Virustotal results 32.26% Heodo
2022-03-30UG-9336768360467.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51n/a Heodo
2022-03-30VA-16043305.xlsxls 34c12fb797211966f38e1025e683ec8ecc00b70e39d5f463213f7b09eea896c4Virustotal results 28.33%SilentBuilder
2022-03-30n/ahtml d5284b7b1cdcc6058ece6da4c5c7be76748f5d32da12fac9395da58a278e2e0dn/a