URLhaus Database

You are currently viewing the URLhaus database entry for http://cinemasa.com/a53gp/YUBBOPs-ncQuHpFwMHqrHC-array/corporate-profile/vnqo2la7712910-93w971337803/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299400
URL: http://cinemasa.com/a53gp/YUBBOPs-ncQuHpFwMHqrHC-array/corporate-profile/vnqo2la7712910-93w971337803/
URL Status:Offline
Host: cinemasa.com
Date added:2020-01-28 02:38:17 UTC
Last online:2020-01-28 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002281075 created on 2020-01-28 02:40:07 UTC)
Takedown time:12 hours, 35 minutes Good (down since 2020-01-28 15:15:50 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-28INF 2020_01_28 343361.docdoc 45f4837dd3c4164db2df0fc600696eb225eff9a66e0dadffa9ff07c9f797a8e6Virustotal results 22.58% Heodo
2020-01-28file 117.docdoc ff3030128824873fe504c15ecf0cd7b700b36b02bee75fad21ac9d45ea20fa58Virustotal results 30.65% Heodo
2020-01-28List-2020_01_28-12306.docdoc 267aa23c9031b06e6dc7fac45daca30a65d4f08843fe0976c2ad7201d9646dafVirustotal results 28.57% Heodo
2020-01-28Rep_MU7619.docdoc fccf3876128e78c8d3a6385aa312b1333c822a2b9efafb26daf1d2ffea296d59Virustotal results 25.40% Heodo
2020-01-28List-20200128.docdoc 68938178a947046088472c9c687caf7843271233fbba2b888ada13c2bb5a5e5cVirustotal results 22.58% Heodo
2020-01-28MES-2020_01_28-GVD051998.docdoc c5666d80df3d2361122568d511e336c58a58b27576a1cd78b434c425d8b2e809Virustotal results 22.58% Heodo
2020-01-28list-20200128-105673.docdoc 256954bf735b73749d5fd67afbf6e789abb356f02cec192954e129996801d642Virustotal results 22.22% Heodo
2020-01-28REP X8861.docdoc ae1c2a1ebc838f4092123a0fed626a10f1325e7796629f6d370111fd50d8154dVirustotal results 22.22% Heodo
2020-01-28ARC_2020_01_28_074.docdoc 61d0d2aa3f2b0af2db0d2e4037ac0753965f1d03e0231b17a3695337b66ddd79Virustotal results 40.32% Heodo
2020-01-28FILE 2020_01_28 332.docdoc 20cdcb97c92b8c58397ab1170823f96ce0db2c3e93d4859bd06fb23302687d30Virustotal results 41.27% Heodo
2020-01-28dat_R5678.docdoc f79992105131cff7dd4570db1648129b246323085d2843087e402a966d52503aVirustotal results 41.27% 
2020-01-28doc_2020_01_28.docdoc 6ad17ae6699cc9936b448b914d775c0418010f284e1e2d7e680e6b64caad1740n/a Heodo