URLhaus Database

You are currently viewing the URLhaus database entry for http://plenimax.com.br/Bestellungen/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:29634
URL: http://plenimax.com.br/Bestellungen/
URL Status:Offline
Host: plenimax.com.br
Date added:2018-07-09 20:59:05 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: JayTHL
Abuse complaint sent (?):No
Tags:heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-10RECH-QN-01173025/44.docdoc 4d909f80fda16d515cb3b5d45b4e9b868742de09c57282d015c9d44d3ba85d86Virustotal results 27.12% Heodo
2018-07-10rechnung-SL-07/35321798.docdoc d2beba142d02c877bfe71dce571348be5558b5ccebc5d32237e17948fdf7c756Virustotal results 27.12% Heodo
2018-07-10rech-ILR-04/5088565.docdoc 8a0676c5261a7272536b401161c015c9670abf423d65f9cc1f1bdadad9d4fd0aVirustotal results 29.31% Heodo
2018-07-09Rech-TTD-0709827-89.docdoc 7e3ea7a1e6f1e70cb6c2c85f4571fab88f27aec9677e0e1b1f070d617ef1ad3cn/a Heodo
2018-07-09Rechnung-ZLO-0270708/0.docdoc 14b38d7f07dceada9dcf142d1d36b40d9236b3f323fed45f8524563ba8f7843fVirustotal results 25.42% Heodo
2018-07-09rechnung-VX-03620552-7.docdoc cf4f7d4df892c7b837c64b2a73760f2c81082de9e609688bade85cf39061b192Virustotal results 25.42% Heodo