🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://portugalbyheart.com/cgi-bin/kd3b-ji-14/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:266305
URL: http://portugalbyheart.com/cgi-bin/kd3b-ji-14/
URL Status:Offline
Host: portugalbyheart.com
Date added:2019-12-10 18:27:03 UTC
Last online:2019-12-13 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-10 18:28:03 UTC to abuse{at}ptisp[dot]pt)
Takedown time:2 days, 15 hours, 32 minutes Poor (down since 2019-12-13 10:00:24 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-13Invoice-XZQ835_4019.docdoc 15fa38a2faf12d33606ee65c183e3fbcb4391fa8645758f4243470bce6aa869aVirustotal results 31.15% 
2019-12-11INVOICE-QM79_958.docdoc 62c12303542b74aa5cc546713a55af73a6d4567ca2fa12f79875fcd1840fbe37n/a Heodo
2019-12-11Invoice-RFO778_404.docdoc 4ee0bf78e3b0a06c35fed0f912db6fabbb5fae13f838cd4132634359ad0d24daVirustotal results 39.34% 
2019-12-11Invoice UM080_7225.docdoc 598ca34558e9464124f85cef62e3ee262da4544695fb430fbf3989b5f23a62e7n/a 
2019-12-11Inv-BA022_64236.docdoc a60c7102286fc773ec8ada02318ac04bc6b9e5c4d835d4465fee783df6afe81bn/a Heodo
2019-12-11Inv_NF003_1324.docdoc 034a04bdd56a112cacfb766436ee3b4b0abdc5759c758ba75bd3102a5438a610n/a Heodo
2019-12-10Inv-EXM53_40312.docdoc ff98f96aed445e123b958aef79aca1b99e1fbbf4fe7e96b9387f633762919f2dn/a Heodo
2019-12-10Invoice_JA508_35511.docdoc 051550754f4111f726e6863ffa836f9ecf5caf432ecac1a7643c874ce42771c9Virustotal results 29.03% Heodo
2019-12-10Inv QSA109_650.docdoc 91167bef3bc48293d11a8ea55c9d6d8cefbc1771266b70175ad77d3673e88774Virustotal results 26.23% Heodo
2019-12-10Invoice_EV74_2922.docdoc 0f81e86948f355a7f00d13804a2c0101a3fea3039019232a3c82b69ba71e8579Virustotal results 26.23% 
2019-12-10Invoice K18_9799.docdoc 2a84f4ef5c7f01a1dd09d8f8530e98c35b7c76d0dba58bef2a4360fb17776986n/a