URLhaus Database

You are currently viewing the URLhaus database entry for http://union3d.com.br/twitter/Document/1KprAfdWOkME/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:182244
URL: http://union3d.com.br/twitter/Document/1KprAfdWOkME/
URL Status:Offline
Host: union3d.com.br
Date added:2019-04-22 17:37:19 UTC
Last online:2019-12-04 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-04-22 17:38:10 UTC to abuse{at}hospedagem[dot]net)
Takedown time:7 months, 16 days, 0 hours, 6 minutes Bad (down since 2019-12-04 17:44:32 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-30n/ahtml 8cfe3f54b1f0e135149cd5c626d0f2569f8257ff3fb32eebe4723af168d17cfaVirustotal results 0.00% 
2019-04-22SCAN_60883966258US_Apr_22_2019.zipzip 9333d2f44df8c5fdab48ec55bc93bcf22623f411e05d1dbac4779e338660d392n/a 
2019-04-22LLC_1106435601US_Apr_22_2019.zipzip 5e401204fc1f48d940e57ca00322b346c8b628734ffb5357cf77ef154aef0c30n/a 
2019-04-22INC_043628919134US_Apr_22_2019.zipzip c84863fd226f16d2922d5d54b6543d31e44388e77cb66b18df053ee34a946cf7n/a 
2019-04-22DOC_8237394218US_Apr_22_2019.zipzip 0e2bfd5f6d976e80a747726dc82f6cc711d2cf7c5ce0c72b52abad08f8d004a1n/a 
2019-04-22INC_832370087070US_Apr_22_2019.docdoc 9dc61237288f3407e9f04701982e9ebb6936df3bc7fb824e790cc70e0157bf3cVirustotal results 30.51% Heodo
2019-04-22SCAN_998931629768US_Apr_22_2019.docdoc 24c9b5f4946f0f3caf3aab3794791e0c887a5720d5455889a2a527231e5a143dVirustotal results 26.67% Heodo