URLhaus Database

You are currently viewing the URLhaus database entry for http://californiamotors.com.br/site/ffsi-ckg5x-hqphz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:157937
URL: http://californiamotors.com.br/site/ffsi-ckg5x-hqphz/
URL Status:Offline
Host: californiamotors.com.br
Date added:2019-03-13 07:00:19 UTC
Last online:2020-02-04 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-03-13 07:02:16 UTC to abuse{at}locaweb[dot]com[dot]br)
Takedown time:10 months, 28 days, 12 hours, 15 minutes Bad (down since 2020-02-04 19:17:59 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-13ACC5471272357601.docdoc 8ef79e33fc1ebf640f78cebe13485489f85caf08fbf4cee696aadb977f21d6e7n/a Heodo
2019-03-13URT4876261497417805.docdoc 1157bbcfa2438b4142bc1dc163952714ef2e084cd27698f5c2f78193367f8033n/a Heodo
2019-03-13INSTR30193055053744407599.docdoc e09474de88f323075c3ef4ba54c458e3275ee102b72a2bfc4894e79a9703c542Virustotal results 23.73% Heodo
2019-03-13US85916421298.docdoc 3eaba85e842d0ed0489d430cb1bc37d1fca702845ba478a0e290115bebfd8827n/a Heodo
2019-03-13US280754581616.docdoc 47f3f87bc57341c15aaf9fc6736ed513185e8347dcd6bed30b3248a5bbec92eeVirustotal results 26.67% Heodo
2019-03-13ACC804358352361583086.docdoc 7bc5adcbc4a6b78f2ac46e65a760ea4f1eb71a3e61a7e03542b300de351c582bVirustotal results 25.00% Heodo
2019-03-13PAY49088451932545050.docdoc ea4513e22bf373d8dc75abb1db7f176816eda88750d38902d9cb27191c9dd20dVirustotal results 22.41% Heodo
2019-03-13ACC337420540447413996.docdoc 0c4646cd74ba4e2679effe7eac5501cc5652f7be7068a0e3b64029c622b84a09Virustotal results 19.30% Heodo
2019-03-13US678697714247195.docdoc 7769b1c45fbc460c5b14a5b623d82dbdd22535b80a99d770933132253cbddc20Virustotal results 19.64% Heodo
2019-03-13PAY94564111752253616482.docdoc 062080a241916c13988d1be4196e03855c473fcc3cb370bcf988643a84bf36c4Virustotal results 20.37% Heodo
2019-03-13ACC3973287400564640.docdoc ca1dd75b2b289e24966828108846664b2a0c664ccf1a992f15edcadd73c11c34Virustotal results 24.14% Heodo
2019-03-13ACC05688279092633727.docdoc 97f1937fdb3e3352a8d543d9fa888f317342469159f447909a32fdcf12ef2375Virustotal results 20.00% Heodo
2019-03-13PAY387668081599.docdoc 97d756aa53ffafd6ee88e1e873d9476014bea132e6e8922e001eaeafde70d1a7Virustotal results 20.69% Heodo
2019-03-13ACC4371828232667783216.docdoc 54d8c502a0b6326dc098a1ff932662a1f394f28c8392f30143bd08084ae87addVirustotal results 18.18% Heodo
2019-03-13ACC718625083.docdoc a07fd7d2cdae5fbf0001cae6c854480647bfdd147e82a79de54d0b142fd09a75Virustotal results 17.54% Heodo
2019-03-13PAY9088122089593.docdoc 105adeff0a2090e95c400094a1f1ae53e4ff2b57677c771e5e10291e81b5d9bfVirustotal results 18.18% Heodo
2019-03-13PAY427629309165930.docdoc 19bffbd1d63574f440e9ccd70a2a188558010d8a1f34fb175b1cef2f6f13e2a9Virustotal results 18.33% Heodo
2019-03-13US759463111950.docdoc 9035f9ec39078357560ee6c86e41c62fedcd755433235d0563dd91715d61371fVirustotal results 16.36% Heodo
2019-03-13WYH3520336398.docdoc dd8f42677463d31afea67c4849c85d1e6b44c47dbf6e6dd91d51bb5f8506712eVirustotal results 23.64% Heodo