URLhaus Database

You are currently viewing the URLhaus database entry for http://www.latinigroup.com/bin/lm/dkz9q6gw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:294099
URL: http://www.latinigroup.com/bin/lm/dkz9q6gw/
URL Status:Offline
Host: www.latinigroup.com
Date added:2020-01-21 20:16:07 UTC
Last online:2020-01-27 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-21 20:18:03 UTC to abuse{at}hospedagem[dot]net)
Takedown time:5 days, 21 hours, 37 minutes Bad (down since 2020-01-27 17:55:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24D_5GM3OF4HROSCEOD.docdoc b23494efa852765f1cdf9075cb670cd519afbea68362114c5951c723413f82f6Virustotal results 19.67% Heodo
2020-01-24n/aunknown 59b038edebe7aa9284d1a14d0256fd769d98950fc86a7e6fc377dd87a3166ce6n/a 
2020-01-23FILE_5393572682788965104756.docdoc 3334a6d8c260f512f9a150587bcef454adaf5ff83ba3f9c7c5daaa736b1e91a4Virustotal results 33.33% Heodo
2020-01-23986267407343751406.docdoc be6c0143e369040588ac032db356bb21b70bda2cd730cee53440f1a52186b25fVirustotal results 30.65% Heodo
2020-01-23PAY_FHP_010120_BFM_012320.docdoc 0854d5a8ba17e65aef32385c9680d29b0bf5f82a486b44ffb80fda5c8fc8fb77n/a Heodo
2020-01-23DOC_793960978568314.docdoc 6b852e2457846b25fbe15b2679508ae82057f6e75873b3347b26c395ea2c3dffVirustotal results 31.15% Heodo
2020-01-2337745238064058.docdoc 85710b5d01d3343135329bbca4bcae8283cf4b309bfd007540b7c9c42be78370Virustotal results 29.03% 
2020-01-23DC5854364666SM.docdoc ce43998d0af42cb9a17bf220f9fe9418948e1e05c4b007cc306bfd2d4580d2a8Virustotal results 27.87% 
2020-01-23JMS_010120_HXC_012320.docdoc 667a70d5b2b7840b6e7668f011e10182bbd2103b7885111ed07392813d2af6d4Virustotal results 31.75% 
2020-01-23QUOJHTIDYH1.docdoc 8f57a1a62bed296020fc8eccb69e151133940788c6b8b87ceb2d95273dcae200Virustotal results 31.75% Heodo
2020-01-23FILE_O2T6EY4YKT.docdoc a340d8ba5f7367085e1773a5d0349ecadd71bd43d775d96d697126bf76b76d4cVirustotal results 25.81% Heodo
2020-01-23CIMW_DX0CEF1R8N.docdoc 3d01b5634985350eb0753da8324f05a468b2e27cfb4e7d5911f3005520bfd2f2Virustotal results 22.22% Heodo
2020-01-23DV3039701828QD.docdoc 9606d8dc2f0dfb10656d44b2cf56d6e4c37ed143602cda16cc87ca46ac0f6405Virustotal results 20.63% Heodo
2020-01-23NAQ_63581049.docdoc 87375ae81a73bb3dc7f704b3e7e62e3e496b286fa24c145831637953f4bcd132Virustotal results 20.97% Heodo
2020-01-23Q8HO8J6BFTU.docdoc 7d7dbd503462905ff0336f5bce30008d5e60a05850e892b91e1b5ecdbb220854Virustotal results 22.22% Heodo
2020-01-23EA_02080098.docdoc e50ca42cece8459c5ed1bf0713f580775a5bea5fd9384b1e5f284e52f2db08b1Virustotal results 20.97% Heodo
2020-01-23INV_PO_01232020EX.docdoc 9af2280771f435166b53ce4682f2cedf9072877a0fd338920e1a7ae4434c47caVirustotal results 30.16% Heodo
2020-01-23431804731633048562397913.docdoc e63aa1c3401d847d86e7d7a0183b1b09932060991feb79d6e2b775a27f30c36bVirustotal results 30.65% 
2020-01-23FILE_70317437882273278716.docdoc c78e3b88c08a9425cc9d6043a9d20e85c160e556a37f57f3f2515cb894c33316n/a Heodo
2020-01-23RP_314690406855741696.docdoc 57f80688fb69b44c38dc1526796d523074e95761263f1c762f83cbb491b369a6Virustotal results 28.57% Heodo
2020-01-22SW_BKJ_010120_QIB_012320.docdoc 62fb677b5e795566ed8b06713d070488a08cffaccd527993f327cb931929ea2eVirustotal results 29.03% Heodo
2020-01-22DOC_QN2377511759BM.docdoc 72bd6822c6587d7476c2bce9cbb767b7f392c8c960c6a5f08b75f5ef154f6a2aVirustotal results 27.42% Heodo
2020-01-22X_5WNFL304Z00H.docdoc 9e8f3c1221d4f90c920d8987531fcef5c6d5ce9582ebf6769e4591d8ad4fe3bbn/a Heodo
2020-01-22DOC_94935047.docdoc 0fed8a6d0f31e05943d5e786c31313260f8187f838e8ee21b42c285e41df16cbn/a 
2020-01-22FILE_132322982291248955.docdoc 760da2cf865d8c30de733432733cd907c4d3473c8c956b337785f76899801383n/a 
2020-01-22BAL_PO_01222020EX.docdoc 6e83800a3113b103e6b34bfccaff8104496a1c725441de7bddba38b757458efen/a Heodo
2020-01-22PAY_QOL_010120_XMZ_012220.docdoc 76945e1b8c864c6a733fd32287175ef1d964299180918949c4bfcfb1566e53e1Virustotal results 27.69% Heodo
2020-01-22AV5499488545PO.docdoc 478f1dc50e192ecb20ebcdb9a37e7c312e9a8cc20766a5f86f95b3d9c09cc0b3n/a Heodo
2020-01-22DOC_PO_01222020EX.docdoc 5be3e93b04906a447233525f99dffcce0d42f3559aa4ecfb866c92b5fc7f6671n/a Heodo
2020-01-22ST_16473995.docdoc ef44a3288d7ae90b174f66d99d6157dace138152521b46b1affc482b2ffe349fVirustotal results 31.75% Heodo
2020-01-225Z270QU.docdoc cd1d589c80332498c1497b75ec3532ce643fa739a27ce32fc53e53551562361eVirustotal results 30.16% Heodo
2020-01-22BAL_K3MHOD1IYCNP7T.docdoc 8866f17525978f2cec2f21518499d6d84bd654adcc1bfc22f90d7fc47eddd406Virustotal results 29.03% Heodo
2020-01-222565982785174606849672.docdoc ae732e2481c442c721b9c70bbbafde35384fc2d9c8e8426e67eabd9863b3e009Virustotal results 26.23% 
2020-01-22FILE_KON_010120_MKM_012220.docdoc 65a1628ef9bc3362fb43fdae7776948360a3fe80ae3fb6f8f03a5d2a68e8694dVirustotal results 27.87% Heodo
2020-01-22ST_PO_01222020EX.docdoc 336ab3a461e1a9206d529c38bf94f01e340884585fe63edd765c3fd0821f68e6Virustotal results 29.03% Heodo
2020-01-22H0WCCBA8FA8GA.docdoc a85351653bf9a0c8c76db9f4c1076418ba4fface5c3a7f373d29186bf46732e0n/a Heodo
2020-01-22PAY_PO_01222020EX.docdoc 6386c6fdd8a1eb4f6fc7bf14c51236c53a6d7dc8419ff7add51d3a75c46d3610Virustotal results 20.97% Heodo
2020-01-22BH8S72G2D1VZK.docdoc fdd88907a8d15214b40b8d8d5a50b95f2ac0fe7c950ccf237001170d54d9901fn/a Heodo
2020-01-22PAY_PO_01222020EX.docdoc 4608dceeebae9faa5e9e2416bee85509b67e80af4422fb61baec34056ada48d8Virustotal results 20.97% Heodo
2020-01-22YOG_IDY_010120_OYP_012220.docdoc b913bcdc497b6b660c83a30cfc62dd393c53c9a867f3fab997e326e3c8b94a73n/a Heodo
2020-01-22A_MLV_010120_HEO_012220.docdoc 6321d13c864a5af9a0a39e72120db0999714232489e7bf8461b8a795db19a222Virustotal results 19.67% Heodo
2020-01-21REP_CCH_010120_LHQ_012220.docdoc e7cfcc5924207c0384febd2ca4125ab12dc6c893443adf4fecf44f056f3e243cVirustotal results 20.97% Heodo
2020-01-21PR2295313953UL.docdoc 7dbe6013d43f4768bf95db5c34307dc03772c63cb3271426a1ff60b77951e7den/a Heodo
2020-01-21BAL_IHIVPNRVS5H4.docdoc 5fd6ec312654d263689e335748f1296c2e1cc8b5d84f2f28e4f0af1686d55715Virustotal results 19.35% Heodo
2020-01-21BLO_010120_CSR_012120.docdoc 3971d2f8dad1df7ae025551c02c685cf456405eb7ba164f380e38518f2d228eaVirustotal results 19.67% Heodo
2020-01-21SW_3386074788251098224.docdoc dec6a90824213474511fb4e36ee5ba457def1667a64c6ae162e37b525100ae87Virustotal results 19.35% Heodo