URLhaus Database

You are currently viewing the URLhaus database entry for http://hcsnet.com.br/wp-content/zvPeH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122630
URL: http://hcsnet.com.br/wp-content/zvPeH/
URL Status:Offline
Host: hcsnet.com.br
Date added:2022-03-30 14:46:05 UTC
Last online:2023-01-07 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 14:47:06 UTC to abuse{at}dreamhost[dot]com)
Takedown time:9 months, 13 days, 7 hours, 32 minutes Bad (down since 2023-01-07 22:19:29 UTC)
Tags:emotet link epoch4 heodo link redir-doc xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31CPP-00348181.xlsmxlsm 7093cef5fa36d3a3226ede66e633684706991f11f806fdad017d28a40684cc76n/a Heodo
2022-03-31MW-62008409102.xlsmxlsm f18597d133d32b346f94d05eb9a0865b4ed9a863e7dbcd4cbf10bb847803c37cn/a Heodo
2022-03-31IYI-0094658.xlsmxlsm 1bdada6954ab20722dfb51b2ace2e6fcdfb556210c74bb059752552f5fa8f78fVirustotal results 42.86% Heodo
2022-03-31EZ-9435993689.xlsmxlsm 64d92f79a2d87571d428b7b19ef4f5c1680c24c8952a2f46b84f217cfba19766Virustotal results 39.68% Heodo
2022-03-31TVG-58976990024988.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 35.48% Heodo
2022-03-31YZP-5753517.xlsmxlsm 317b14af792a2e4b877fd65cd6dc1cdceaf3d9573dcc1cf673e5008d38f7b6caVirustotal results 35.59% Heodo
2022-03-31RCQ-97824378000.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31BKM-17955415205326.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31BB-05306195.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31GGC-736805340.xlsmxlsm 566c3447fd5a1b7f7f0c942d484a0185bcd747d47f9c487452dcbfed1979bd52Virustotal results 33.33% Heodo
2022-03-31BE-3373681.xlsmxlsm f88eb7101fdc0fe20190969ec3bb4651bf4f270d9a9636d6c1e1a84ae46a9cd6Virustotal results 37.10% Heodo
2022-03-31TKI-7454202472.xlsmxlsm a099f9c9c8eff7049da288a1205f1c0ccd52a4954930cabdd7a00dafbe8bbe6dn/a Heodo
2022-03-31OY-712406759.xlsmxlsm f1a59459dc11d8edab701cdd7610dd6310993ddb1aa04ab43f8fc3536040700dn/a Heodo
2022-03-31IJG-397673226.xlsmxlsm 6f7875f81192db87ffea6b495f10f68edb22a26f0cbc22b47cc1fbaf1b160cddn/a Heodo
2022-03-31SF-572773140.xlsmxlsm 0c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3n/a Heodo
2022-03-31WXD-45560775.xlsmxlsm 93e06d8850641586fe31c662da490f8ff442f4f86021f50799e1174dcace1f72n/a Heodo
2022-03-30MTT-71266132.xlsmxlsm 2909468da77be7c90d3c57fa66be2e6250afde34bd400f2c815be9bfd89be7ddn/a Heodo
2022-03-30AGS-582464950.xlsmxlsm 4fadf9d0ce08783dd924f9ab1f1691dbdf07251396bb218f92cfef0279739a25Virustotal results 32.26% Heodo
2022-03-30PQD-04906153.xlsmxlsm a9850d81856c9d96fc75ccfe0a62c2142422d5feb66ad218a0b057a52bc4c554n/a Heodo
2022-03-30EXD-5529265990089.xlsxls a14fb7f51582ec1f9af65f4300ff4dde6a99d12bd2b08f70863ca16d508c72baVirustotal results 28.33% Heodo
2022-03-30n/ahtml 91672a2206092f7a20e40fa445e22f49368b9572e71111666a56a468d4dd9932n/a