URLhaus Database

You are currently viewing the URLhaus database entry for http://comunikapublicidade.com.br/sitemaps/DR_Q/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:174201
URL: http://comunikapublicidade.com.br/sitemaps/DR_Q/
URL Status:Offline
Host: comunikapublicidade.com.br
Date added:2019-04-09 18:10:08 UTC
Last online:2019-04-10 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-09 18:14:07 UTC to abuse{at}unifiedlayer[dot]com,ipadmin{at}websitewelcome[dot]com,abuse{at}hostgator[dot]com)
Takedown time:1 day, 4 hours, 17 minutes Poor (down since 2019-04-10 22:31:24 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-098jS_0Q.exeexe a1ab8e760cfd3d4313fda7afbc1617dccbe3d059b4678e90bdf6f8d97d218bf0Virustotal results 28.36% Heodo
2019-04-09A6M_tM.exeexe 9b06b0ea8ebf444d1dc351aafb0ce7977c4233954a9833e607f3f87e7a165ff2Virustotal results 28.79% Heodo
2019-04-09U_YOA.exeexe 185097ee93de81050d99f2c2c5e629843e09e33193bf2393752c86af3e083f30Virustotal results 30.99% Heodo
2019-04-09uBc_k8.exeexe 874c6d4bec3d576eac6c8fb5b6f17cfb1088d15aab2b2652571edbe2f767d23bVirustotal results 31.88% Heodo
2019-04-090_e9.exeexe 49d8ef5b0aa9e36ef72330fd901a59b352537c5ce96d0ca9d0a1416579cd6f50Virustotal results 29.41% Heodo
2019-04-09Eb8_rty.exeexe c39a5e2bb3928d862bcb23f0b66833318212f584778e9a669db05dd2df5993f3Virustotal results 27.69% Heodo
2019-04-09m_zol.exeexe 634850b79c753eaf68f5b520e1c353988e0c4a580eb08a635fa27fcbd4c3766bVirustotal results 31.43% Heodo