URLhaus Database

You are currently viewing the URLhaus database entry for http://elcastilloencantado.es/wp-content/frCFOI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:601913
URL: http://elcastilloencantado.es/wp-content/frCFOI/
URL Status:Offline
Host: elcastilloencantado.es
Date added:2020-09-23 01:39:03 UTC
Last online:2020-09-23 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-23 01:40:13 UTC to abuse{at}arsys[dot]es)
Takedown time:7 hours, 14 minutes Good (down since 2020-09-23 08:54:56 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-23VzpOsugY6Wr.exeexe 8dda8550a2df934773cc2b314329ad6c13004eb4f3537bf075fce7eaefe8186cn/a Heodo
2020-09-23Wrn1vKjFCabI.exeexe a47a98bb6e493bb5ef8d95356394b8a0fe9ee5a567c2a1271b77ae54565b43a0n/a Heodo
2020-09-230nnXCuZv.exeexe b235f78bf5634fc88ae1945a77626eeaffa4d2262f8345e415623095b3974addn/a Heodo
2020-09-23sr.exeexe c68a455561f985c8a4abdd9dddb07a3aa3668f032ff0e2524add1ad0f724c833n/a Heodo
2020-09-23hF26bO.exeexe 46b308c6a5441c621d9f8bf0ad32da16f96edd341f171063d8cdd799b44f869cn/a Heodo
2020-09-230Rns6CHcMqO.exeexe 507c6765a44454b96a55eec9d9c9163a829de78995b52f3248b9fa2800df7cddn/a Heodo
2020-09-23ftmi.exeexe 88c91ab2ca54a54b4cbe881a64d5dbe22b9f148c44b8fcbc47d3e399c37d7147n/a Heodo
2020-09-23RX.exeexe 167e21cde9e95d19ba7d48bb28a38295f801a3ea48cc38725db808c0dde25c45n/a Heodo
2020-09-23JBsgSvWUca.exeexe 1369882680e1a74f4425f9080709e1fba7c95561a28850945ea77599b16e1793n/a Heodo
2020-09-23DHpnf4DXfP0dIEzQwhya.exeexe 0771f4ab1975e2b6bb0a4fceb6501fb0fde810bfb522f31ce76b7a876aad1f46n/a Heodo
2020-09-23NuV4U2TIXeVCU5231A.exeexe abdc446d8d11b3b05284c96acfd4f03762be392560224ae85004cae252766129Virustotal results 16.90% Heodo
2020-09-23gKj.exeexe ca1dbd8fadb5ea3ebc3bf640a0a41ac622d55e9b56da583f872fe8f3e991858aVirustotal results 17.39% Heodo
2020-09-23TglzCoNVH7D.exeexe 9f464c0d5c14a871f84e1fb5554f331fdadb1e79919f15e239c0784df8151a45Virustotal results 14.93% Heodo
2020-09-23bdyXEUUX.exeexe 256b1be9dc307a6fbf7f42879fb438751c327f0ec97db58667909bbb227bfe5dVirustotal results 15.71% Heodo
2020-09-230XcASN2FMR1Kdu.exeexe 045f2050b5cd515a8ca99591bf21cb6a984ae6f6d10240eeb21a1e849ab7c30an/a Heodo
2020-09-235yXuY4VOpYyo.exeexe 544d25c84aaf478e9bd9c69d0100f76deb0af7c23aeebb8e47d66b2ffadf1872n/a Heodo
2020-09-23OP0Js654t2HwZpB3wT.exeexe 99e9504b709aeb4fc7b68394b83d7293e0a604710ff07b06d4a365de89204b4cn/a Heodo
2020-09-23GC8tWC.exeexe 083e12f3eb555ef3ed559bc311a20e61c7a4544cdc0e637e83de615407fd0961n/a Heodo
2020-09-23ZrdeK.exeexe 482e6f01701e1b476ace75307659f40a69248903a2c8216e86a068683801549en/a Heodo
2020-09-234IC6.exeexe 9922f4d8744826ae30198af488379d85266e67f2db1c69e42a07722a19aa8136n/a Heodo