URLhaus Database

You are currently viewing the URLhaus database entry for http://cdaonline.com.ar/wp-admin/FILE/x7Z9wBk77Tt6v9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:554647
URL: http://cdaonline.com.ar/wp-admin/FILE/x7Z9wBk77Tt6v9/
URL Status:flame Online (spreading malware for 5 years, 2 months, 27 days, 7 hours, 57 minutes)
Host: cdaonline.com.ar
Date added:2020-09-18 12:32:04 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2024-12-20 07:37:56 UTC to abuse{at}hostmar[dot]com,abuse{at}dattatec[dot]com,pablo[dot]pepe{at}adinet[dot]com[dot]uy)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-19Attachments-2020_09_19.docdoc 67cc9853ec0a3e3d1283d0ccc57907b9c5c60ff1359dab4e9456b581a3ebc3bdVirustotal results 22.41%Heodo
2020-09-19FILE_20200919_E9907.docdoc 0a30c4b942b9c613a9c5df445b932e1468358cbd04d1ecd613fd547da4ec84edVirustotal results 22.03%Heodo
2020-09-19inf_G374.docdoc 0b58ba1859d47221ab95122240157d9d4bc885723fb94b700f1c36cb28edf3c6Virustotal results 22.03%Heodo
2020-09-19Attachments GVD0405.docdoc 23c8490e131915effd12a2adf737b6fb74515b1b54759d0bb237eb7392338c08n/aHeodo
2020-09-19Rep 2020_09_19 563.docdoc a6d4e72568e642cf4b7ebface0d1efd59bb14b348af845c74bd132af71733f53Virustotal results 22.03%Heodo
2020-09-18file_2020_09_19.docdoc 2a3e7c662c026f10d65fedffc2f513a8683860a3448c822016d34579120dfb36Virustotal results 22.41%Heodo
2020-09-18DAT-2020_09_19-765.docdoc c23cc89488404b578a22052d1d946ea0e421961bb77a5c4b002d890506c2aba6Virustotal results 22.41%Heodo
2020-09-18Arc-49760.docdoc 33ce6293593a02d1b88213d5e0bd0fcc3667491733ce5009426e8fd5c2e6dc50Virustotal results 22.81%Heodo
2020-09-185494-20200919.docdoc 9ad2fe8f74ea62256c9ad4c199d69c91b8c76f9a605cb5c038fcbec9d0e85054Virustotal results 22.41%Heodo
2020-09-18UNTITLED_20200919.docdoc 03caf29484a047db9c68e15e6117f665c59b1cc6ea7cdacba9042f80149861b9Virustotal results 22.41%Heodo
2020-09-18doc-2235.docdoc d28151cda4058aa8e8c1175ab6fea760c7c6812f758570a50fca1ad2b52eea2eVirustotal results 22.03%Heodo
2020-09-18MES 8227271.docdoc 8aef0f99e6ad886e7a947f5a99fd0b0016cfdd32cf2c62ad525364452c8c7c41Virustotal results 22.03% Heodo
2020-09-18list_SBP569987.docdoc 5f947b8388016997bed38166706bb096d920127a6a8c7823ff7dcebcaba8f81eVirustotal results 27.12%Heodo
2020-09-18Rep 20200918 Q396.docdoc 94cbcca1d095e7f389dc8a63c2efe17bf54bbbdab3b2ae794b6093bd8d65e9cen/aHeodo
2020-09-18arc_2020_09_18_7097.docdoc 47eda5a9b722f901be7f188137feed9a83fe055f7ed73139af4b680f257a2e1en/aHeodo
2020-09-18list ZR0947.docdoc bb7673a01670e7e6892859b4f6829f63fc3d17a92a52cf3da83a1d984c42aa7eVirustotal results 30.51%Heodo
2020-09-18List-20200918-OPY506295.docdoc 1e68ebd904cacf30d35734935dc212a7484e063e1a3519783249d890572a19ecVirustotal results 30.51%Heodo
2020-09-18rep-20200918-24635.docdoc 25c51061c2d3618e6fe43b51487ff7abad46d648b8d3b9661d757ab481a3a4f4Virustotal results 25.86%Heodo
2020-09-18622_L704748.docdoc 54ac560845b09ce00a48b604ac7c440331cbde4362839a3dbf14c378230bee21n/aHeodo
2020-09-18doc_AZ437784.docdoc 65603b499c24d66104493036513a1bdaa69eaed1280c65bbafdbc9f26c35a502n/aHeodo
2020-09-18Attachment-20200918.docdoc 459e35015e9a3742fc691cacea980bb8ac5761944e9b5b12eae483826aacc1daVirustotal results 25.42%Heodo
2020-09-18FILE-108354.docdoc c3b361e3ab7b82eb20f5af057abff8f96c2369d0dbc47472ab1430390ae8de1an/aHeodo
2020-09-18Dat 20200918 LP365.docdoc 77dfe2eeed80414b4e3a1702fd0d7443e23a4b8ea93460bef56458aac2b2983dn/aHeodo
2020-09-18QS323_2020_09_18_E59285.docdoc c6f91ca4de4035eea0cee737bcea230c3a1fc1b9bc3e0b8e59e1b0cb2c212dc8Virustotal results 26.32%Heodo
2020-09-18inf_2020_09_18_U789924.docdoc a5ce864f2c3bca89c24abc1fa1068e590b7df70133a6f8d4ddbfb26f3f72a85bVirustotal results 25.42%Heodo
2020-09-18inf 20200918 522506.docdoc b2bff83e324b221fb399d81c45adc6aa217cf5c97c2b7cacd5d92e8fb8757373n/aHeodo
2020-09-18Arc 20200918 85128.docdoc c78b6fd735feacf05ab8254985b5a5f154b52b13e5c0033b566d90c3155c915an/aHeodo
2020-09-18File 2020_09_18 GI3891.docdoc 8324d40ef076e8e466b29e34e3a2698d09d6f2010995094954cd4fe65e6a5e96Virustotal results 22.41%Heodo
2020-09-18Mes-887562.docdoc ceb0ab5a4fac60cae54222c2db10571693e9aab0a23fbe42bfdccde11f0a5b2bVirustotal results 23.73%Heodo
2020-09-18Doc 2020_09_18 978.docdoc 4e32005b1ea54f5b7a05f50fa7630e992190edb459666a026ebb506c2e1a2c8cVirustotal results 23.33%Heodo
2020-09-18Attachments_WE4911.docdoc 15516d337875587c5b3c679d8c166d4e00d5da295727956ddb935e5972ab2aa1n/aHeodo
2020-09-18Attachment JZJ3468.docdoc 34641ff2a1fcb443dd5ea8990accecd6e3888c6054c887697c1bc99581c794ccn/aHeodo
2020-09-18UNTITLED-20200918-58037.docdoc 7962c53412619716d3f3c55bd0ec83e7678990f635cfa95e918f3cf6ae33d5ccn/aHeodo
2020-09-18Attachment_B047.docdoc 0145a12527d52916e2a2ef2811d0b86f90834caffdbf0b03bc8425f94d686455n/aHeodo
2020-09-18rep_2020_09_18_26873.docdoc ca63d9c9e846ae66ae0030d7a8ec4041674dc2b6189b86eefad806122c65a092Virustotal results 20.34%Heodo
2020-09-18dat 2020_09_18 945776.docdoc a980ad21eced39ab6179666648e571be61547ca21fc8dfca1d016158af5036c8n/aHeodo
2020-09-18List-20200918.docdoc 8e4b5c75dfd8ad1acefed08603f4a69c435e29f076db8183c17703d238ea71e1Virustotal results 20.69%Heodo