URLhaus Database

You are currently viewing the URLhaus database entry for http://www.chapada.uefs.br/wp-content/languages/protected_zone/security_area/3DKP7OVR_JxipmIIlec/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:293714
URL: http://www.chapada.uefs.br/wp-content/languages/protected_zone/security_area/3DKP7OVR_JxipmIIlec/
URL Status:Offline
Host: www.chapada.uefs.br
Date added:2020-01-21 15:19:16 UTC
Last online:2020-01-27 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-21 15:20:22 UTC to abuse{at}lacnic[dot]net)
Takedown time:5 days, 18 hours, 43 minutes Bad (down since 2020-01-27 10:04:11 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-23INF 2020_01_23 Q1258.docdoc ebc6068bda6fb60c283e3c691e7c409f06b0044ea66b5aa500b319a2ebf1ddffVirustotal results 25.81% Heodo
2020-01-23List_20200123.docdoc 8854c592155c1bd835e9edee147c7fa3714ba319ad138943dae4aa94a01d2adfVirustotal results 27.42% Heodo
2020-01-23mes ZBR663645.docdoc 1b2a8fa233d738505dc4538a43ab60d5f61cc7e52dbb8d6314510cb80a96e044Virustotal results 28.57% Heodo
2020-01-23rep 367.docdoc 3f09c758e4c162f34e2f6b69f771874cdbc4aa5d6db3da039ae979513e76ff9aVirustotal results 26.98% Heodo
2020-01-23Dat 20200123 AT801962.docdoc 4b10f942d9197454cbd1e18eb87d18ab77fab4e78186b0157e96404d3ae11a3cVirustotal results 20.97% Heodo
2020-01-23File 2020_01_23 LMR937342.docdoc c1c73003345059b14e18e971fd753f7a761e9f56eaca3d63a0af96a9845a03c5Virustotal results 20.97% 
2020-01-23Arc 20200123.docdoc 0602a260f7babf69b17ea0c106902e0aa1210f18240011382c3d1b89cbf2a78fn/a 
2020-01-23mes-2020_01_23.docdoc cb8f7b473f1c200a59f57ff19de1171c4931c3264b691ac05aa63c3d33f37fb6Virustotal results 21.88% Heodo
2020-01-23MES 20200123.docdoc 129967e7908c933478dbe958d62c4d0edc10802a33da0f9055d834958c0257d6Virustotal results 33.33% Heodo
2020-01-23inf_CRQ2185.docdoc 391cdfda17669f8646d016ccbed5a280386e0ee0d329337ceea01aec817a30edVirustotal results 33.33% 
2020-01-23dat-2020_01_23-KL47687.docdoc 538059ab61604832e49b7f0de789e0910c15547f674bdc32b27fb19cf4acdd7bVirustotal results 36.07% Heodo
2020-01-23Dat-20200123-75015.docdoc a5b40116b0e7fcee6fbf05e3425ae17e7812e5a1bfa387e8588f0002fff8911eVirustotal results 35.48% Heodo
2020-01-23REP-2020_01_23-B794545.docdoc 35e9ccfe2fb736ab494d113297f3c7069e131c28b9996efe0623d6f6fa2e2644Virustotal results 34.38% Heodo
2020-01-23INF_RDJ915.docdoc 88ff8c8ef536a4e8b31a9600abf42ca11d5082fbbfaf8838707b37877b3c38c5Virustotal results 32.26% Heodo
2020-01-23dat QFR0159.docdoc 69b84b05ec0630dc6b8f253c178290fb5aa0dfbf319f03bff2ce5d49f84adc1fVirustotal results 30.65% 
2020-01-22List-2020_01_23-244976.docdoc 44bf0077af152d7d892947c473b68a731a7341fc10cc40505a6c2d624b77c17aVirustotal results 31.75% Heodo
2020-01-22ARC-8102.docdoc b3a1cdb8288e369fec04ec55e099c9bd7e8593d24da31870c3a782a351d98ba0n/a Heodo
2020-01-22dat 20200122 OM821.docdoc 94e08c0bae9bdef279f8e2b9c6b4f5315c766e6d9dd73b9fd4879ddd3520bcadn/a Heodo
2020-01-22Inf_20200122_5753871.docdoc 346b0ba9684b9fdc8dde08af0ab486c86cbea5347a32be77aaafb0dc9034f2e2Virustotal results 28.57% Heodo
2020-01-22LIST 20200122 W7308.docdoc 09c16304c3e1aec3c34700ba9ccc3b60a96824e6f17b99ada9f1ddfc84e20d06Virustotal results 28.12% Heodo
2020-01-22ARC 20200122 ONI008367.docdoc 6eb3a1de5779c87ba943671cbe8f29213ae390f189e8bd35f9520393e1edf6deVirustotal results 26.56% Heodo
2020-01-22Inv 2020_01_22 3696.docdoc 6f856fad86610f5644b41a0dc88a0000f40345a6a534d4cde004dc0c144be8d3Virustotal results 26.15% Heodo
2020-01-22file_20200122.docdoc 49e5a80e1cca26881338aa66ea50845698f2159cb262cdaab711ae01e93435d9n/a Heodo
2020-01-22Mes_2020_01_22_X732033.docdoc 6dab6d9bdad5fb8c6564493c3c06f10835f916e3980e4937d8c55f4c2f1f1a01Virustotal results 30.16% Heodo
2020-01-22arc-20200122-G7146.docdoc 9dadd4813995b8d41824d1d85894c1b616ea0858053f4f80ac1ff1e7a14587c4Virustotal results 31.15% 
2020-01-22rep-2020_01_22-O0157.docdoc d5d9a7450867f6c951b33c65e5c363becf43297041b078e61259006714be9da2Virustotal results 30.65% Heodo
2020-01-22mes-JGP0322.docdoc 27a95f049070cadbefa3c02a756a3b031f62b48a3fd6b2deadc601e88c1e2defVirustotal results 27.12% 
2020-01-22doc-2020_01_22-HPO223.docdoc 8393ee813a355aa5e024722cc7c1bc220c91fb4021acfea3fef9486d634ad125Virustotal results 27.42% Heodo
2020-01-22INF-20200122-C6934.docdoc f215874c38b91208764829b0950f3658cbed0e5931060ec4d658ff212f019642Virustotal results 19.67% Heodo
2020-01-22INV-2020_01_22.docdoc 341a4a0cdb85208a1f3f1b5833e5b2185b070bd8c861287d878b179978f98019Virustotal results 19.35% Heodo
2020-01-22doc 20200122 528.docdoc e32b84c7d967bd21ca4def6c66ed1441afca25b720e896b926f4c01906891918Virustotal results 19.67% Heodo
2020-01-22Doc_2020_01_22_XNK81187.docdoc 822cab01673ebcd4b1d6de1afd0e2cba9d227f59b4be13c5df84c1427ef64389Virustotal results 20.00% Heodo
2020-01-22list_20200122_05228.docdoc 55e7c45b115a1b3f5841cff784e524e1a7db1007c8b7dab6c0ac641891d18a4bVirustotal results 20.00% Heodo
2020-01-22bl-20200122.docdoc a6d88c45a2db468584d02f98537fa9948fb89553ecdb4a9ed46bd92cbc43d863Virustotal results 21.31% Heodo
2020-01-21list_2020_01_22_T306.docdoc 9694a4c6d10eb061dd240367cc5d98afa97954e04e12427d65332c4de96887fdVirustotal results 20.97% Heodo
2020-01-21INV-20200122-OTC1300.docdoc 48dcc7b6fcac5eb751b1b33aa2eb59cfb2e94b0e0a5cdab668b4bec913df421dVirustotal results 19.67% Heodo
2020-01-21PAY 20200121 985145.docdoc 7250005eae7b7bd9c5a672a17723ff13212adbd19f94e1c653d3030e1b4a53d0Virustotal results 19.35% Heodo
2020-01-21doc_X83190.docdoc 264ba2d156f00aec06d41e31787c8f1f3dcb3b1113cec329f323ce499b392ec0Virustotal results 19.67% Heodo
2020-01-21REP 047625.docdoc b4e481870d5b34452867cd626da86dd0635b1815fd151dc7df4075e2366f7b94Virustotal results 20.00% Heodo
2020-01-21pay_UQ7276.docdoc fad54acc0e3baf2d4988317c0be66ea88fd31db8e68ba83ccacba57edce1385bVirustotal results 19.67% Heodo
2020-01-21list-2020_01_21-XKY72838.docdoc efc46cd918cf15f33ef115a3fd061b6fd1171d955c6de891fe16e66e9f47ff13Virustotal results 20.00% Heodo