URLhaus Database

You are currently viewing the URLhaus database entry for http://giscomunicacion.com/picture_library/WseaYDSP5zSGsH9P72rz1f4Tco/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123053
URL: http://giscomunicacion.com/picture_library/WseaYDSP5zSGsH9P72rz1f4Tco/?i=1
URL Status:Offline
Host: giscomunicacion.com
Date added:2022-03-30 18:42:04 UTC
Last online:2022-03-31 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 18:43:05 UTC to abuse{at}arsys[dot]es)
Takedown time:7 hours, 0 minutes Good (down since 2022-03-31 01:43:14 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31DHF-606757145.xlsmxlsm 5c682f8054f1b9bb175d9a5784b8fd5bc06364ddf2b802d9aa5fa0abe6cb3a33Virustotal results 36.51% Heodo
2022-03-30AG-950185760.xlsmxlsm 2b1f1f87033e83e264f05939f180b63165e067861f9c6f1253aedc9c9e1efb6en/a Heodo
2022-03-30VZ-7279037.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30PMK-37723040003428.xlsxls a14fb7f51582ec1f9af65f4300ff4dde6a99d12bd2b08f70863ca16d508c72baVirustotal results 28.33% Heodo
2022-03-30NF-49334545.xlsxls 2c52e5c5b59a9935971907d5a7da5617d5abec8d681b68f50c7201fd3943740fVirustotal results 28.33% SilentBuilder
2022-03-30UK-41126093359966.xlsxls 7813b5f2ba1876b183aec911e5a55402903c7b4702fef4c3c0055557490ef04aVirustotal results 28.33%SilentBuilder
2022-03-3056201579678084.xlsxls 6a42829e15c0d59a451f47b85ef79e416f44ffb13c49dd25eac35478c2f5d303Virustotal results 28.33% Heodo
2022-03-30826606396090.xlsxls a70944dc8486f8580125d6fc42dc181656aa83f9c9e1917512927e24fa13f69an/a SilentBuilder