URLhaus Database

You are currently viewing the URLhaus database entry for http://www.escueladecinemza.com.ar/_installation/AxyH53DnAgWuZCichBN7ZHqLx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123386
URL: http://www.escueladecinemza.com.ar/_installation/AxyH53DnAgWuZCichBN7ZHqLx/
URL Status:Offline
Host: www.escueladecinemza.com.ar
Date added:2022-03-30 23:10:09 UTC
Last online:2022-04-23 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 23:11:06 UTC to abuse{at}hostmar[dot]com,abuse{at}dattatec[dot]com,pablo[dot]pepe{at}adinet[dot]com[dot]uy)
Takedown time:23 days, 1 hours, 51 minutes Bad (down since 2022-04-23 01:02:15 UTC)
Tags:emotet link epoch4 heodo link xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01SQU-893401591728589.xlsmxlsm 5d31e83b1dda43ba478dbf1bbd5b1ab90021810860493110ac6175f69e58a93dVirustotal results 43.55% Heodo
2022-04-01DY-9851359265.xlsmxlsm c4cad5d5b47c3ff87c13590baac506dd7292f1e93b72c0f3e990b4726243b6b4n/a Heodo
2022-04-01DT-540278283416295.xlsmxlsm f05bfe09754313735c1939aa2a1a85f904c8bd3fb4deb0a44b70ddb02166b319n/a Heodo
2022-04-01PE-205399350800015.xlsmxlsm 5e318e7afaeff1da0ab8f38c466b9fb4e911da7fae7a6eb58cfbab3175d51263Virustotal results 41.27% Heodo
2022-04-01ZXT-467454796131.xlsmxlsm d32c4d0a8c9ac509e3acbd4b041b2d01cc771c0e20828ebd64d2d8fbf49fba7aVirustotal results 45.16% Heodo
2022-04-01CZC-17114681967.xlsmxlsm dd701c6097144f29f8fbdddc93a18a1c0ce3c3b51d5b4f0c6683e906ba8426d9Virustotal results 42.86% Heodo
2022-04-01ZTF-73103267304735.xlsmxlsm 178e56af34b8983297784e7e795578c7567350c8ef3be2b30a43a05de59b9e8bVirustotal results 47.62% Heodo
2022-04-01NN-7627730019.xlsmxlsm 05aecb805762b1c7cae04f8f46d0d43392d1b6e4880c93d82f69ef52d8dd2660Virustotal results 41.27% Heodo
2022-04-01LQ-1644415669.xlsmxlsm d058072d305f952c54981e50bbd34cf23dd0386a4924a4bdb8a91f46e0498d4fn/a Heodo
2022-04-01CQL-82040307191.xlsmxlsm 64d236fdcb188d517ddb0fd6ffcaf1759dddd828de26d1cf6b605031589da663n/a Heodo
2022-04-01ZR-2009534203.xlsmxlsm 8f4649ad2259125c87f3339f5e5089f1f425485a0f16ac55a672a31b8ba49c2cn/a Heodo
2022-04-01VCP-68617170.xlsmxlsm b784d4f4f32d64afab8f413f40ca82365ae3115763bc79d6fa46a5e4ea94f01en/a Heodo
2022-04-01VT-3234716609971.xlsmxlsm f4e10c5743205f55ce4eca43f3741f71ecfdca9391ae883123c3372d5daae4b1Virustotal results 41.94%Heodo
2022-04-01CAF-619607754368679.xlsmxlsm 5a5c8a3d5de13a95ffc29d40c54fe8440d1c84f706e59960f5f1621715b8a1dcn/a Heodo
2022-04-01EY-2464163251.xlsmxlsm b25b9d420c3585bd014abd2e590a74feab98bbb0ee612c465a5e152b28c67e0bn/a Heodo
2022-04-01MR-6935307309.xlsmxlsm 3390185d81ea6becb7bb5c59f26400a3c75b99da77bd95eb76e9417ca984b4dfn/a Heodo
2022-04-01MJ-3356063595197.xlsmxlsm 5ea7243ee6fea62276b79e7f2bf602ec3058d33fb8ddbc31faf71eb0eadf1a90n/a Heodo
2022-04-01WE-975581058205224.xlsmxlsm 5118b85e7ffcf61644564e2660990ff4e6becc430b13aca19a931d25f3d4c1d9Virustotal results 38.10% Heodo
2022-04-01NSF-29130408.xlsmxlsm e407f7217907368560ef28caf164f34190a5295c4c75afaaeea21386e8bed99cn/a Heodo
2022-04-01YOH-68890893387.xlsmxlsm 7347e4cf31a837aec00dd4d093a63e3f2b67a89b6af8965707c47717e8075482n/a Heodo
2022-04-01EA-4036014337.xlsmxlsm 9ae3ff917d99c0e0ba1f6dde3bcfebd781ab332d65552b032855ca627606cccbn/a Heodo
2022-04-01HT-2100272728.xlsmxlsm 5144b4176d2f9e56ad483565884642378be09039de1f2a353cb355c00dfa1894Virustotal results 43.55%Heodo
2022-04-01DK-0481899072.xlsmxlsm 441ae7dcf7d20f39dce4201542202d7c62c067457d1476c2bda9c819979879ebVirustotal results 45.90% Heodo
2022-04-01GJ-9553126006.xlsmxlsm 68696caf69e14a066ca54423f72a2e7693b03f5ce299e609265a3e72df925abcVirustotal results 39.68% Heodo
2022-04-01DQQ-447619994.xlsmxlsm 7865998de760d97246decb7fc619579d9389e6c2cdf72097738e48a74a0bafe2n/a Heodo
2022-04-01BFT-540833752773.xlsmxlsm d470a9368b15c6f1e3e1c49a452ab86e75500fc1585044f4c9dcdadaadd804d7n/a c8fc17ff030feb3383d8889f69abbb
2022-04-01TK-189466116.xlsmxlsm d17e95fb87ae8a3011b050d5c9c089f3bc06fddd1a61feb4812380e96b541e73Virustotal results 46.77% Heodo
2022-03-31KH-24638501509.xlsmxlsm 872c806b2f7f3d9e9fa2365cf07997b152c6209d41197d5584295b3f3cbdfb70n/a Heodo
2022-03-31VW-66675006043529.xlsmxlsm da7fdf635815dc2ebb6fe69fa637d655ab6667aa7195ba89002790a17c19dc19Virustotal results 41.94% Heodo
2022-03-31DRB-125610968397735.xlsmxlsm dffde7ff06d4b4d38ae8f02750d5c59b2a1a293d05af04210b8e79d0b3fd4043Virustotal results 38.10% Heodo
2022-03-31ZWJ-8180982.xlsmxlsm a395d2ca627270c1b53481050d39c6395c778682e98aeedcb00d1f68fd1ec23fn/a Heodo
2022-03-31VM-672804666952.xlsmxlsm 62c189060c43573eb24597cf25c683c10baa2d25165f5de393f846864ecefc46n/a Heodo
2022-03-31JIQ-575128168205875.xlsmxlsm c10cd4c9b699a22be539e47e16dbb91c80084b3afa570a9eb66c2206c3096b9aVirustotal results 40.00% Heodo
2022-03-31PHQ-887499822753.xlsmxlsm 317b14af792a2e4b877fd65cd6dc1cdceaf3d9573dcc1cf673e5008d38f7b6caVirustotal results 35.59% Heodo
2022-03-31MY-034348012299544.xlsmxlsm d17f996f89de5c8c22e600186d7d54a2e0172758ad5cd4d2accbf22b58848bbfn/a Heodo
2022-03-31UBO-285353624042849.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31XS-40621706.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231Virustotal results 40.98% Heodo
2022-03-31AE-036408131230656.xlsmxlsm 64c57c337892c7579a7c6d302233570e6f2450b0d0152b3b32de811347079a2an/a Heodo
2022-03-31KT-9488956145463.xlsmxlsm a099f9c9c8eff7049da288a1205f1c0ccd52a4954930cabdd7a00dafbe8bbe6dVirustotal results 38.10% Heodo
2022-03-31BD-935652076.xlsmxlsm f88eb7101fdc0fe20190969ec3bb4651bf4f270d9a9636d6c1e1a84ae46a9cd6Virustotal results 37.10% Heodo
2022-03-31IZ-3225005431.xlsmxlsm 30deb7a7086f74317285271a2e26e40dc43b461a1a77c77480ea742b02cbe51fVirustotal results 38.10% Heodo
2022-03-31XOD-7924136454337.xlsmxlsm a43da1637de01a06d72a9d09981de5132b8bd971844704ee9fc7c5e07450a49dVirustotal results 36.51% Heodo
2022-03-31IOJ-4021193207533.xlsmxlsm 61ad9b2b8c9707a14412bf30d2e17c11d75dd548e841d9b4eb6299ca1e0456d5n/aHeodo
2022-03-31TQE-424737306915.xlsmxlsm 0c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3n/a Heodo
2022-03-31JY-13709431594530.xlsmxlsm f93f882fe4bac2b1210512c64a2985c99282b49a95a2aaa3bfcf6865d6dd0056n/a Heodo
2022-03-30JQP-2251165.xlsmxlsm d3ad5641b527c4ec7e77e037ed81f1913c394f063e13677b8744b26fb09bdecen/a Heodo
2022-03-30GII-722001350816393.xlsmxlsm 265f4ce97b8c4a17c8f27359496edc3f97e2e6926a267fba16797dd5c6e3a70bn/a Heodo