URLhaus Database

You are currently viewing the URLhaus database entry for http://economizesa.com.br/cgi-bin/fA1Y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2125298
URL: http://economizesa.com.br/cgi-bin/fA1Y/
URL Status:Offline
Host: economizesa.com.br
Date added:2022-03-31 18:54:04 UTC
Last online:2022-04-03 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-31 18:55:07 UTC to abuse{at}hostgator[dot]com)
Takedown time:3 days, 2 hours, 46 minutes Bad (down since 2022-04-03 21:41:44 UTC)
Tags:emotet link epoch4 heodo link xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01QK-45178222.xlsmxlsm 5d31e83b1dda43ba478dbf1bbd5b1ab90021810860493110ac6175f69e58a93dn/a Heodo
2022-04-01LLM-4383983892.xlsmxlsm 0baff6c11648937580735dcff8208034790a0e1ee649431e79b2b6221d825c40Virustotal results 52.38% Heodo
2022-04-01GX-80647148.xlsmxlsm 83a8039af1534f4fc93efcdb7e429c799f144ace1f33b37ca42a57ee7a559499Virustotal results 49.18% Heodo
2022-04-01CL-79422171.xlsmxlsm 60c4d1f685f36a0120a23c7fd8aa5ca2ae442c84ade6fc63771c5463defd9bd7Virustotal results 45.16% Heodo
2022-04-01NW-78808323760.xlsmxlsm dd701c6097144f29f8fbdddc93a18a1c0ce3c3b51d5b4f0c6683e906ba8426d9Virustotal results 42.86% Heodo
2022-04-01UHY-4446949528.xlsmxlsm 47b6e78d6a7d4cd13da293ca1246d01543b0da63ccfd3e20830723be355497edVirustotal results 43.55% Heodo
2022-04-01DA-5964881303.xlsmxlsm e01debc832c8bd1cc77634631d977cbabf9ab55828f7336d6b5219e75549244bn/a Heodo
2022-04-01MMJ-91444730.xlsmxlsm 1cb0214ebc21c13015d927c504acfbe080983909d8839ef9b28c5e270d1f4f1cn/a Heodo
2022-04-01YJ-55091444.xlsmxlsm 6463322a887744e8e04715bf20b67bc671561c87d8cf5ef5d4791ddfb5f1eb0aVirustotal results 39.68% Heodo
2022-04-01GQ-865888446.xlsmxlsm e99a1144b3f8e1ef8f39b170d03c0b95f551aef01c0f6ad02a526b61bdbd0442Virustotal results 44.26% Heodo
2022-04-01CR-55301012015.xlsmxlsm 53ba0571642eb8162dba83cbc3390d3483fdc2cc3748ac1bb4cfbe34542f57f5n/a Heodo
2022-04-01PE-856660908.xlsmxlsm 4d52dfe6d7f72aada80362bf080ef49a439b176e7c488de69e8d6cc39feefb9cVirustotal results 48.39% Heodo
2022-04-01YB-8861391241.xlsmxlsm 2b24ae43b66b722398ecdce2eda45ce724f63487f3059dffa976479d26a9f3b7n/a Heodo
2022-04-01TFS-821856264.xlsmxlsm fa9f8c915e7e2c8f789e6e390d3b655689e5cb9e29f1b971fb833bad6cfdb0c9n/a Heodo
2022-04-01PA-43131509961810.xlsmxlsm 027cdc2c1f7a5137ca0fb9585bd5b7b98bb73c9e51073632d4101a1b533eddf8n/a Heodo
2022-04-01WOO-375532394986.xlsmxlsm 1cef59b0cfd651edd1b587c50988c75a14b39c325a3f41839e3ce51c08f7f753n/a Heodo
2022-04-01TDG-4949086.xlsmxlsm f44ceacfc82ef479898e80139a379537a6807c7f104c6d71216c269dfa7b02a8n/a Heodo
2022-04-01EBZ-3935243819.xlsmxlsm dffde7ff06d4b4d38ae8f02750d5c59b2a1a293d05af04210b8e79d0b3fd4043Virustotal results 41.94% Heodo
2022-04-01NSY-8028083.xlsmxlsm 033009536542621d4d21d3368787a56ecdf807bccc352f8014ebf00a5a57c6f6n/a Heodo
2022-04-01AY-57192465.xlsmxlsm 9ae3ff917d99c0e0ba1f6dde3bcfebd781ab332d65552b032855ca627606cccbn/a Heodo
2022-04-01CWJ-911997838880.xlsmxlsm 45a99040aab95ccb6eae75a169ae10f79883e11c53c29bc41ffffd0a329940cen/a Heodo
2022-04-01XE-539079394418.xlsmxlsm 4c7b060bb7b1693ef3943692ce9c62204426393f9af92ca39c4c57e09b03cc25n/a c8fc17ff030feb3383d8889f69abbb
2022-04-01YH-1696136978284.xlsmxlsm 73dc0a16c8430b50b28054c9e0b1e54cc8174554e7b63b4e2fa4be17c3cac1d6n/a Heodo
2022-04-01DX-85593639.xlsmxlsm dcc6409e704780116523a3e6ca35edf1399b381568d26b6d0373d1d9e00be491n/a Heodo
2022-04-01ZR-155647197640.xlsmxlsm ccd56be98c55e12bd6055a6653472e9d7f1a8847dec281a9a3b6af0ed000c226n/a Heodo
2022-03-31XGI-5202703.xlsmxlsm 5131287d80e747b0ac91053a0490859150d9f84995214a9136ed22466de08835Virustotal results 38.10% Heodo
2022-03-31YDM-3944459286.xlsmxlsm 5fb54e96fe17c395fa69dc06933558b083ae9cfb1391218f12c539c2645a8311n/a Heodo
2022-03-31MYR-61039901874.xlsmxlsm f4e10c5743205f55ce4eca43f3741f71ecfdca9391ae883123c3372d5daae4b1n/aHeodo
2022-03-31CW-06932805138486.xlsmxlsm a511cc3375e58ef7201e233c3bf07a3e37506bda58ab9bd64047cf5656cd4932n/a Heodo
2022-03-31YW-17665993.xlsmxlsm 2fa93c2dfef003816d473094a03ffe57ed6fd6cbbd21f22831af88634fc3287dVirustotal results 37.10% Heodo
2022-03-31OS-57623044.xlsmxlsm 0a23b203754e6a043fa99f6cf518c8ffa19a34557a7471edad072d54c4a76dacVirustotal results 42.86% Heodo
2022-03-31NBH-6888351922.xlsmxlsm 46c4bca622e4ec244f8999280567cf11b73d31d875ea21c347d737e6605992abn/a Heodo