URLhaus Database

You are currently viewing the URLhaus database entry for https://academiamonster.com.br/wp-content/ysyOJDYgn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:263719
URL: https://academiamonster.com.br/wp-content/ysyOJDYgn/
URL Status:Offline
Host: academiamonster.com.br
Date added:2019-12-05 18:18:20 UTC
Last online:2020-01-20 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-05 18:20:08 UTC to abuse{at}redehost[dot]com[dot]br,flavio{at}redehost[dot]com[dot]br)
Takedown time:1 month, 15 days, 18 hours, 18 minutes Bad (down since 2020-01-20 12:38:14 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-13n/aunknown 9fae0bea3d93aaccb8e4a04dd7d87a104c1b6a3c618f38de8d3512fe99350cd8n/a 
2020-01-13n/aunknown e9e099aa935ed0084316a092585885775f46eed4e1ee874b4b5811ab6985e559n/a 
2019-12-06epjmq41_28532903.exeexe 9477806a113a42a11e11b2ebd31ff0e18677e37cbcd3fc2116b89e45eac49af6Virustotal results 18.06% Heodo
2019-12-06nfi6m6vyx_279320.exeexe a126685b04050c6abdad7cedc8394c3cb92b29ef201d2b6e03d2d83d87ace88bn/a Heodo
2019-12-06h3rs4x_7.exeexe cf6f2da9abe138ddf2bbc79092b6ea2c0da37a4ef4ce9b7655e822fc1af40b7an/a Heodo
2019-12-06vwgdtv4ow6_049.exeexe 8beda00f6f20ac6b92db611ab52d66b51869a1109c1d6236287b1b014f7f74c5Virustotal results 19.72% Heodo
2019-12-064e1_958539.exeexe 1e7a60a11412a14397e02b80a2715e758b46df2c5ab670cce3511b7fd8f34064Virustotal results 26.39% 
2019-12-067djw9rjs_826427.exeexe 3aa1a87ad5dc950ae64ee59289126833639597df4b90584573e7de18bafc1a7dVirustotal results 19.72% 
2019-12-0616h_1643.exeexe fbb4ab0f5ef726a487435fecf141c5f97654f692d32e9b38c095c03bcda725d4n/a 
2019-12-06xb2ft160_95032.exeexe 120c8dfebf9e3c51b76108e01f21ac46fe38e07decc32dba769832333ff65f30Virustotal results 19.72% 
2019-12-06u4a8_2755890238.exeexe f6d8a8e3a9c40c8529d1e88801a265efda310192019cc35800815ed06c448fd1Virustotal results 19.44% 
2019-12-06ak_88.exeexe 8ed1437e3da101c3a09734f0896f5e553dd5df627a114a1fc0996ca23bb53cf4Virustotal results 19.72% 
2019-12-05ctv_2495278.exeexe f9c44a3c4c06fca43039a5b98749c040fe180241dabf8c15701951812d92c6baVirustotal results 18.06% 
2019-12-05zxba_051192.exeexe 6ea38a6a123a8b561880d3dff9a390d10f3afc0a4e78056ee3d6cc2a16e85ce9Virustotal results 16.67% 
2019-12-05mtsu8i8_5.exeexe 226d8dcbaca2a05edd1df9d168d88a2015c5a9a8818b3ca724e99b112f935172n/a Heodo
2019-12-05yr_348437925.exeexe be3551fa651a65c1813b4b1f984b18ba1d6e269d83588a67dd7c5514cd2f540aVirustotal results 14.08% Heodo
2019-12-050vj7_90020403.exeexe 86d0e85249cf1d24a43391dfd391d26acdd88a07a57d976b136b3ae12c962967n/a Heodo