URLhaus Database

You are currently viewing the URLhaus database entry for http://klassik.com.br/En_us/file/nPJGz-RmY9l_R-Q0G/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:117551
URL:http://klassik.com.br/En_us/file/nPJGz-RmY9l_R-Q0G/
URL Status:Offline
Host:klassik.com.br
Date added:2019-02-05 13:44:34 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2019-02-05 13:46:13 UTC to abuse{at}unifiedlayer[dot]com,ipadmin{at}websitewelcome[dot]com,abuse{at}hostgator[dot]com)
Takedown time:4 hours, 11 minutes Good
Tags:emotet epoch2 heodo

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-02-05QWJ16723383448729884323.docdocce156b7c2aa6d96ec7210c15222d8ac24ceee6e030adfba9cb5f82e72c174540Virustotal results 15 / 58 (25.86)Heodo
2019-02-05GWM7301666196118865.docdoc459d36d11e00f48dc9e9307e0b864aac16fec980f14e637ad83932fec3105b34Virustotal results 14 / 59 (23.73)Heodo
2019-02-0574609823615938451.docdoc46b32f9f738df444e699a46ecf8c31e895cccb972523d2e90561b0a8220d2b26Virustotal results 15 / 60 (25.00)Heodo
2019-02-05PAY8834188155397.docdoc27798a2ce37dffd3c7cecf7056010b3be3dfd0174b4a630ccc71d38670f337eeVirustotal results 14 / 59 (23.73)Heodo
2019-02-05IBIOX4364268188135.docdoc96230bfaf02fad44de0a2b2861b8076637592013ca2755f882a8e5b4f6a88011Virustotal results 15 / 59 (25.42)Heodo
2019-02-05729571228140647.docdocdc74f0f4bc52f96f59387b2951bdc3fd1a23c60078275bec80ec47f6bfcdee10Virustotal results 16 / 59 (27.12)Heodo
2019-02-05PAY590090093014824.docdoce3e12763fc4e211fc1f50ba29a27189f365f79b3696533e73f58e1c8ea44f74bVirustotal results 15 / 59 (25.42)Heodo
2019-02-05US560198875552.docdoc17126e4a1bcf3fe084bd079aa416bd8d9b4d09c4cbda488e60fa21a7462f7623Virustotal results 14 / 60 (23.33)Heodo