URLhaus Database

You are currently viewing the URLhaus database entry for http://viamanzanares.com.ar/cgi-bin/FILE/ves5vf1/81ufjaoqd142d93fk1i79ouokunc50/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:698119
URL: http://viamanzanares.com.ar/cgi-bin/FILE/ves5vf1/81ufjaoqd142d93fk1i79ouokunc50/
URL Status:Offline
Host: viamanzanares.com.ar
Date added:2020-10-15 16:06:04 UTC
Last online:2020-10-15 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2020-10-15 16:08:04 UTC to abuse{at}ovh[dot]net)
Takedown time:3 hours, 20 minutes Good (down since 2020-10-15 19:29:02 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-15DOC_68440067.docdoc 3a655449935db1d07871d79739c4fe01d8792844b72e4bc0c3f2c936b6d5ee1fVirustotal results 43.55%Heodo
2020-10-15JR_022696497926.docdoc 590e91cfd2bc7164b8528b3e845e9d45e8328e9148b90c0836936e9d870ca895Virustotal results 43.55%Heodo
2020-10-15G4EQKKIBB.docdoc 004b9a020076d8317b6e57259eff30a147253aafc450379efc2c62a61fcd42efVirustotal results 43.55%Heodo
2020-10-15BAL_DY7914316066IT.docdoc 876665583f24289019346c75249cb2a878ee97166a2994f3be6dd27b7c0f3155n/aHeodo
2020-10-15X_UEA_100120_TDW_101520.docdoc 75d886d075adebfd7c1f94df3158666fc565f14797f59d50cd7a2026d0e8c3a3n/aHeodo
2020-10-15FILE_XJD_100120_HLP_101520.docdoc 3f6955a4c8030234f81c5371a9fe055356a777586aec5021a269eb74083d6ce6n/aHeodo
2020-10-15DOC_4OM6T1TCQEER873K.docdoc fc98055fe4921aa92b5fb0b2cbbae5ebc0ffdc932d1ca890b893c19a838d03d5n/aHeodo
2020-10-15REP_TDU_100120_WBB_101520.docdoc 80b86ab3fd2dc47857dfaed61fdc9398efa3f97a1ac898fdc453fdcf5a36091aVirustotal results 40.32%Heodo