URLhaus Database

You are currently viewing the URLhaus database entry for http://20.206.70.41/Ambev.apk which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2615497
URL: http://20.206.70.41/Ambev.apk
URL Status:Offline
Host: 20.206.70.41
Date added:2023-04-21 13:15:15 UTC
Last online:2023-05-05 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: r3dbU7z
Abuse complaint sent (?): Yes (2023-04-21 13:16:07 UTC to abuse{at}microsoft[dot]com)
Takedown time:14 days, 3 hours, 40 minutes Bad (down since 2023-05-05 16:57:03 UTC)
Tags:apk SpyNote

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-04n/azip e62483d2d9528ed14d8607992451985dd5c0bf934b773664f02bc047325050ebn/a 
2023-05-03n/azip 564accd52d50e27211207ffcd45fed4a4b31db6a44676fd31d07f3c9b072e438n/a 
2023-05-02n/azip 7eb90db11d11f90512b62a2b5f184783fa49a2ebb512aed1a2f0e1d3d640a577n/a 
2023-04-27n/azip a923892e2da3c2360280fc307e0389afae809d7420546798c2fc83bed3426752n/a 
2023-04-26n/azip 992f2ae59880ee318469827e923e5b47dcd49a9662b14b4403ab23e88a5540b6Virustotal results 25.00% 
2023-04-21n/azip dee1eaaa8879a7d321ef4e698203be7b23eeda80a6dea3c70cbf3138597b1800n/aSpyNote