URLhaus Database

You are currently viewing the URLhaus database entry for http://ghostdesigners.com.br/senna/aPvJr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:287608
URL: http://ghostdesigners.com.br/senna/aPvJr/
URL Status:Offline
Host: ghostdesigners.com.br
Date added:2020-01-14 01:16:08 UTC
Last online:2020-01-14 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-14 01:18:03 UTC to abuse{at}hospedagem[dot]net)
Takedown time:14 hours, 23 minutes Good (down since 2020-01-14 15:41:35 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-14invoice KV368_70.docdoc 4ea787c535cc1b104a564ce9f2d486ab607566bc93f9eec342a6df99cceafe18Virustotal results 16.39% Heodo
2020-01-14Invoice_GMO87_8310.docdoc bff484c3a259993eded74499820830eb2da53828fcc763b8f600261572c42b98n/a Heodo
2020-01-14invoice-F83_89913.docdoc 1d56a829a8b53c984eda84373182767912fbf9d5211e5c1cbd839b753410172bn/a Heodo
2020-01-14invoice A466_73.docdoc 34808b889d159c685324dfa60012edfd13eba370971ce74e0e9242fe3c170ebfVirustotal results 17.74% Heodo
2020-01-14Inv FM11_67621.docdoc 61ef44b898c732da0b07cc34493e971778b8835edd28386161473dd228025581Virustotal results 18.33% Heodo
2020-01-14Invoice-JF45_9252.docdoc 9f430cba9753330bd2dda6221bdcd057c6e188e12c984e211d0d1eee54636c51Virustotal results 16.39% Heodo
2020-01-14Inv_KZG352_22.docdoc fae7e292b443e97b48949f711e94e1ee3c23e5e01cdcb3d890bb6c20d459d756Virustotal results 38.71% Heodo
2020-01-14INVOICE-Z538_77.docdoc b39987017e022d0ba9deb280486992ee0ee0338e50e564915d25a97a777af0faVirustotal results 37.70% 
2020-01-14INVOICE-W26_28784.docdoc 798e683b42e879ed7745f11f5aeb1347ea9e66f2e64dd97e32d0b489332d1195Virustotal results 31.03% Heodo
2020-01-14invoice IZR409_57891.docdoc 89a2ef5e668daf534cd630411152090cf384a68ef14c33c77abad76dfef04640Virustotal results 29.31% Heodo