URLhaus Database

You are currently viewing the URLhaus database entry for http://cotacaobr.com.br/application/sec.myacc.docs.com/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:170766
URL: http://cotacaobr.com.br/application/sec.myacc.docs.com/
URL Status:Offline
Host: cotacaobr.com.br
Date added:2019-04-03 13:00:05 UTC
Last online:2019-12-19 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-03 13:02:03 UTC to abuse{at}hospedagem[dot]net)
Takedown time:8 months, 19 days, 17 hours, 56 minutes Bad (down since 2019-12-19 06:58:26 UTC)
Tags:emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-30n/ahtml 0ab227eef05588fcc147ae4eb2b25cbf8819c977eebcc5134ccecfe42c79a234Virustotal results 0.00% 
2019-04-032019_04___RECH_875056199___237833257448.docdoc 66fae3eb56aa085c40dcf7654478c3aad5920549570ea215759f478698e6efe8Virustotal results 29.31% Heodo
2019-04-032019_04___DOCS_41016228440___28472644819060.docdoc b83fcebd64496356242238dc45665aa3f96373f3514ec29c72facc5d140edb5dVirustotal results 30.51% Heodo
2019-04-032019_04___PZG813808398___74187542946703556197.docdoc e02539b1a6600b2f408ed5987c9440f63e8508e0a27cfd27c398dc05720974dbVirustotal results 32.20% Heodo
2019-04-032019_04___DOCS_3248295318286448483___8876442165213027426.docdoc b5f6d5e337fea754bedd12a8eaaf39413cf39a65e406d21406d5606ae8142f2fVirustotal results 31.03% Heodo
2019-04-032019_04___DOCS_98289448128___86003944400199944613.docdoc c57f69a1a40c66d76e6a858e0077c93fc2f7524e200889a71ddef057918f05b0Virustotal results 31.67% Heodo
2019-04-032019_04___INSTR_87287597071848___814886240.docdoc 1c999239e51e20fb29e22a59becec4906330e90532b16af6e69047c8eca06867Virustotal results 30.51% Heodo
2019-04-032019_04___PAY_941552962___693243325.docdoc 873d63a58151cd2e779333d915d1a2ec30da9fa119c227348f810708d86fb8c5Virustotal results 29.82% Heodo
2019-04-032019_04___BIZ_912134217655119242___180795796.docdoc de310033fecf3228c2e76b210befe1c10d2f8729fac19e61ad86585ddfe82b7dVirustotal results 28.81% Heodo
2019-04-032019_04___REC_3925212532081___795931248252.docdoc e255b02e13b1ab7691437859d4f2e0d14911eba0e22e3c50cf88f5b417160d76Virustotal results 31.67% Heodo
2019-04-032019_04___RECH_8197140249___47371068787.docdoc 380fe9eb910412fdba4b1f3b5a83fa97626f07a6887842596aa19a37428f50d9Virustotal results 29.31% Heodo
2019-04-032019_04___PAY_03369366157190___5548585614.docdoc 1580933f21c6cb61a4aa95b47caadee439fe2d6b2e9d32a10923ace4bdb2816cVirustotal results 29.31% Heodo
2019-04-032019_04___PAY_407318145077342024___362892731724203170.docdoc 5a25bc771de52fd4b40e90d788194e5b20d465606a2577321b10abba5df93b20Virustotal results 30.00% Heodo
2019-04-032019_04___REC_1992331659819707030___259647040399815908.docdoc b8c18a591fb3710afee4cd243489ea16f92e7d9d4fb0f77fe63954062fa816f5Virustotal results 29.51% Heodo
2019-04-032019_04___MK90593052340837___281336328.docdoc 15a4f1d4d1ae8af17b284e71a33668fba2a5aad27179717ddad62285caf1a778Virustotal results 29.31% Heodo
2019-04-032019_04___RECH_874962006475464733___5608000698874798.docdoc 62a4925ad26d393ce9675a7c8754a2dbcd3bafe2683b38ae9a6e953321a9ea7cn/a Heodo
2019-04-032019_04___ACC_2036073580082___359354927658.docdoc dea10b78972814eb7c996fb83f7bf9b0749cffaa83c6daac5d7aa12aa690109aVirustotal results 29.82% Heodo
2019-04-032019_04___DOCS_361506696687784959___68721271922792.docdoc ec52ac699447c94c3e6f92b9acd2a948b23f558eabc2e59c3b7cb8309fff28f1Virustotal results 29.31% Heodo
2019-04-032019_04___REC_87432882898___057140783.docdoc 86c24f31451ef09493682a898f2fae2ec0041920a034201903e60e0108d711c0n/a Heodo
2019-04-032019_04___BIZ_93398366920097012___1743313453649197917.docdoc 6b706516aa4a6c84d7288790bd311b5ff46812d716913cdb7e2868b7502eb5f5Virustotal results 31.67%Heodo
2019-04-032019_04___RECH_996543771223___3546369175792576920.docdoc ae275125e8892c96f7e1d17ade25c251402ce40c790e67f171e4703823c1e1daVirustotal results 29.82% Heodo
2019-04-032019_04___ACC_7788515607469908___434974488926419.docdoc 72d6fafd2207338c230ed1581d3d8721b50eddf6dd04ca85e427a68c06173759Virustotal results 32.20% Heodo
2019-04-032019_04___RECH_5127150741200___3541805579899082800.docdoc 16c7269bba293e77681057618f2a44cc22b1259b1e06576230fee8273dfc4d31Virustotal results 28.33% Heodo
2019-04-032019_04___PAY_046057331257580363___0120279265005768.docdoc 78a1facad713beecbc54297cdb1cb9f0c9b3e0ce5ecfea4552c8542a4a396bc2n/a Heodo
2019-04-032019_04___REC_6877797378505123104___94875295733964559.docdoc 2d84259bfdce75522fadba53461db4ada6d2ff955c78b183766f85a3c57bdf6aVirustotal results 26.67% Heodo