URLhaus Database

You are currently viewing the URLhaus database entry for http://hcsnet.com.br/wp-content/zvPeH/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122629
URL: http://hcsnet.com.br/wp-content/zvPeH/?i=1
URL Status:Offline
Host: hcsnet.com.br
Date added:2022-03-30 14:46:05 UTC
Last online:2023-01-07 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 14:47:06 UTC to abuse{at}dreamhost[dot]com)
Takedown time:9 months, 13 days, 7 hours, 56 minutes Bad (down since 2023-01-07 22:43:23 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31CPP-00348181.xlsmxlsm 7093cef5fa36d3a3226ede66e633684706991f11f806fdad017d28a40684cc76n/a Heodo
2022-03-31MW-62008409102.xlsmxlsm f18597d133d32b346f94d05eb9a0865b4ed9a863e7dbcd4cbf10bb847803c37cn/a Heodo
2022-03-31BW-6826010190581.xlsmxlsm 5144b4176d2f9e56ad483565884642378be09039de1f2a353cb355c00dfa1894n/aHeodo
2022-03-31DQH-3181066315.xlsmxlsm 1bdada6954ab20722dfb51b2ace2e6fcdfb556210c74bb059752552f5fa8f78fVirustotal results 42.86% Heodo
2022-03-31TVG-58976990024988.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 35.48% Heodo
2022-03-31MD-3177168433.xlsmxlsm 62c189060c43573eb24597cf25c683c10baa2d25165f5de393f846864ecefc46n/a Heodo
2022-03-31FYV-766895848054.xlsmxlsm 5255a810d7f6ce0a8c496654d7751b05993139ba23432677b64b01c9c44af0fdn/a Heodo
2022-03-31ZBM-2039001849972.xlsmxlsm c171d718d9aecb5ad1e27309660f8da7a568f9798e03d4c6683d7825b5a122c9n/a Heodo
2022-03-31BN-6879367255.xlsmxlsm fcefa2ebaa9e5cce06f5519640eab5413a9b9f6a53ed3fe2f3754c9a610418ban/a Heodo
2022-03-31LEQ-595984083.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31EF-1595764800930.xlsmxlsm fea58fae76c86e5f07c7f8b032f84174206bc489d92c49fe54a5b51d2658faf8Virustotal results 34.92% Heodo
2022-03-31YII-946463007284073.xlsmxlsm a1057f814e603d7b7ff7b711305cac0ef15e48b78499802d411424a19ee235f8Virustotal results 40.98% Heodo
2022-03-31BB-05306195.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31SYM-9420378590975.xlsmxlsm 578e2f6c9e64cb4de6991bae88f0e1e8d38afce9fb954c64d9ed303053647d94Virustotal results 38.10% Heodo
2022-03-31BJ-645248689.xlsmxlsm 5398ede44f8abb980cb617b23ffd5bfb408113787f654b7a399e95025aded8ceVirustotal results 40.32% Heodo
2022-03-31LYN-69356955.xlsmxlsm a43da1637de01a06d72a9d09981de5132b8bd971844704ee9fc7c5e07450a49dn/a Heodo
2022-03-31ENL-7172363.xlsmxlsm 52f73166b6afefeb75e3e2459eb3b8a48e0c9309f83620f4fdbcfcbedaff3f66n/a Heodo
2022-03-31SF-572773140.xlsmxlsm 0c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3Virustotal results 36.51% Heodo
2022-03-31XHT-64114080.xlsmxlsm 5c682f8054f1b9bb175d9a5784b8fd5bc06364ddf2b802d9aa5fa0abe6cb3a33Virustotal results 36.51% Heodo
2022-03-31JES-40455992.xlsmxlsm 08e924859a3a3f17c099cca75fbb3cfd7f8cd726fa2e89fb47ff02f9687143baVirustotal results 38.10% Heodo
2022-03-30QPW-66432318.xlsmxlsm 08e64e582d9d42f5f3a21eaff52bcb72b4a3abfc761561ff28f40bf937dedb2cVirustotal results 35.48% Heodo
2022-03-30VT-594892159.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30PCW-177929406083375.xlsxls c83aefdafdc478ffff051002d1c7b4675c068648d57fca17f788d575ce297596Virustotal results 28.33%SilentBuilder
2022-03-30VYH-13549875091244.xlsxls dd89ded2be5b0a176d6a4d7e4d75f19fd83294a5b0a6da3fcaf12119bbf6f6f2Virustotal results 28.33% SilentBuilder
2022-03-3016845625164614880.xlsxls 59cb698a7354641948808325fe575e61e34b626ab012f8ac911dda41a730b706n/a Heodo
2022-03-30378267372081715886.xlsxls ee875bfdf282dbcdf5711f1553cefe21d02aa98fff3f24f6802ad8165c34287bn/a Heodo
2022-03-3044006748117749806096.xlsxls 21cd95fb4f71525407b37a901590819a18d24ca48bd6b8f7170ff423e780dd4bn/aSilentBuilder
2022-03-3077016255579896.xlsxls 89c9bba23213aec7d1d4ddbe14609b0d215e72dccc6c1d13444ec507d57c142eVirustotal results 25.00% SilentBuilder
2022-03-303283925626896.xlsxls 4ab971149585b19d7afb5a3f53f257d7a4e34be34de69ba2efb91277b3d84b89Virustotal results 25.42% SilentBuilder
2022-03-304780646326921.xlsxls ac553e92c95bea557e54d66351d2c1937f8e92b8a5864dba69bdb9299c5b01c0n/a SilentBuilder
2022-03-3079332962663547996.xlsxls 9516cec1ec1966ef048e5db73db64efa00188b43420a99551c9830768698b5d6Virustotal results 25.00% SilentBuilder