URLhaus Database

You are currently viewing the URLhaus database entry for http://www.liquidasalvador.com.br/Invoice/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:240
URL:http://www.liquidasalvador.com.br/Invoice/
URL Status:Offline
Host:www.liquidasalvador.com.br
Date added:2018-03-20 09:43:11 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@cocaman
Abuse complaint sent (?):No
Tags:doc emotet heodo

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2018-04-12n/aunknowne3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0 / 62 (0.00)
2018-04-03n/aunknown45ebbd6ee927e0ed890bbcc99e6e2418dd9609c7e49af53e06e8a24a92f330f7Virustotal results 0 / 59 (0.00)
2018-03-27n/aunknown45ebbd6ee927e0ed890bbcc99e6e2418dd9609c7e49af53e06e8a24a92f330f7n/a
2018-03-21Overdue payment.docdoc93f5a2dc8028138ddded0ace5f25f7c857734f05791fc3bbeac6caa2d17c1fd4n/a
2018-03-21Overdue payment.docdoc508ceeb4a333642eeefb273327bf95dbde45ead5256271f41f5baa2e60adfd53Virustotal results 8 / 57 (14.04)Heodo
2018-03-216 Past Due Invoices.docdoc15338ecd535e3346ff528de6c2dc450ac0066698cc8f1d6f8468892b159b18aaVirustotal results 9 / 56 (16.07)Heodo
2018-03-21Past Due Invoice.docdoc997be5615604d32ee64c9a3a64006e6143a6c698dc17c6fe093eca42dd1cb512Virustotal results 6 / 56 (10.71)
2018-03-21Question.docdoc5655dae4f8a1647d50f0a581c16947eb4fd3fa83f99192273e94ca4742cdb820Virustotal results 6 / 56 (10.71)
2018-03-21Open invoices.docdoc67064918016cbd0c9c34620bb848171b81212ba146efa5d79dcdf5b815b5f1b8Virustotal results 8 / 55 (14.55)
2018-03-20Invoice for w/m 03/20/2018.docdoc0b82ff1b07aff21b5ce1e8fe2766f5343fca5a93eae02080d3fb1c059d0da7b4n/a
2018-03-20New order.docdoca7b209694eda491f62f71dbd90db584450de44bff2df46cf0fad6a4d1bb9e105Virustotal results 6 / 55 (10.91)Heodo
2018-03-20Sales Invoice.docdoc04c214009888c5f8c9959a40fecf26e93c2a045175bca10ecd4ab2bac22c204eVirustotal results 6 / 56 (10.71)
2018-03-203 Past Due Invoices.docdoc2320f2ac0c5383feb40e365eece401499b7d8a8d633b064371e1e92e96f24306Virustotal results 6 / 56 (10.71)
2018-03-20Outstanding Invoices.docdoc0927e589c072394791aeaf0951e4e23e876b1fd9a3684db52c088a77f8c0f1fcVirustotal results 6 / 57 (10.53)