URLhaus Database

You are currently viewing the URLhaus database entry for https://seramporemunicipality.org/db/esp/dK85LW82SWiaJZTy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:753464
URL: https://seramporemunicipality.org/db/esp/dK85LW82SWiaJZTy/
URL Status:Offline
Host: seramporemunicipality.org
Date added:2020-10-26 21:46:05 UTC
Last online:2020-10-27 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 21:48:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:4 hours, 29 minutes Good (down since 2020-10-27 02:17:06 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27arc 2020_10_27 T7792.docdoc 6562c1ec0d60cdfb002adb4ed15dbbf2f2f3f717002fbe8151e35d3755eb4358n/aHeodo
2020-10-27Doc_2020_10_27_TDQ6602.docdoc 63de45b66603ef77afff13bd0ba2dc21747b5f6d5b0f4aa2ab8d3d373d5c4b68n/aHeodo
2020-10-27FILE 20201027 QFJ0818.docdoc a8af91bef70904171bef405f02b5defa05d6b30f158c7ad6360a7436e6b7be3fn/aHeodo
2020-10-27MES_2020_10_27_X243.docdoc c34b033be6ccec716ff4925ce6e96a65872b23103b659fa24f079d99711963bcVirustotal results 48.15%Heodo
2020-10-27OAB0518.docdoc 52d4dcd449517b101bb99988f9b270b9785a8987cc4edf558f18fa0bbd5bb438n/aHeodo
2020-10-27Untitled-20201027.docdoc 627c23b11e6048db0ff6e2a44fc9bcd0555c4aedfd31ee768b764b084ecfa5c7Virustotal results 51.85%Heodo
2020-10-27874 20201027 972760.docdoc 4be5a08e5917bfda74c71ec644045bbf4a80fd8d4a42606da954548f86b90765n/aHeodo
2020-10-27arc-JU654858.docdoc 4e6cc9395d61d172bbf4609dd2621e07304e62e0d580fca4ee823d4359fcc7a6Virustotal results 42.86%Heodo
2020-10-26arc-RJ299954.docdoc 3ab0e38ba83a5c38bf360f80849f9d1ef5ae83e0be4fdef0a2b71ad76efe4e89Virustotal results 41.27%Heodo
2020-10-26arc 20201027 9961.docdoc 46a7efb8d08758d71739208f61876f02d174a3a9e8351924dc15cf5338c46d79Virustotal results 40.74%Heodo
2020-10-26arc_7957431.docdoc 73d1b4c3fb5a035d592fd68fb3393cbfbd659c6fb165d4aebb3c1abd953aa593Virustotal results 40.74%Heodo
2020-10-26Inf 2020_10_27.docdoc 9624eca338cef03d8004d874cd0c774bf67ece67290d5a0022da8117345b11c6n/a Heodo
2020-10-26Untitled 20201027 SHA138299.docdoc 300fe8a8206fc96bf8007311c265ecd86c75124818fc9b9f3424286f106da398Virustotal results 39.68% Heodo
2020-10-26rep-20201027-235.docdoc e3ad9aea158e55c0fb1ef6c4aaea82873511e899f979de288f615b319eca4b57Virustotal results 40.00%Heodo
2020-10-26Arc_20201027_7350054.docdoc 9df7e80c74ca288cb8aa9caada230cab385c728c5adc1b56e7a3e6443df3f531n/a Heodo