URLhaus Database

You are currently viewing the URLhaus database entry for http://www.facaf.uni.edu.py/wp-content/OHmrelWfO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299534
URL: http://www.facaf.uni.edu.py/wp-content/OHmrelWfO/
URL Status:Offline
Host: www.facaf.uni.edu.py
Date added:2020-01-28 05:51:06 UTC
Last online:2020-02-03 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 05:52:03 UTC to abuse{at}copaco[dot]com[dot]py,abuse[dot]backbone{at}telefonica-wholesale[dot]com,postmaster{at}ns1[dot]copaco[dot]com[dot]py,ipadmin{at}copaco[dot]com[dot]py)
Takedown time:6 days, 12 hours, 9 minutes Bad (down since 2020-02-03 18:01:07 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29invoice_RJ01_541896076.docdoc 3bdbcccc69e55ca69203cb80868675eb9aed4e2e9f880d181e51bb341905b8b7Virustotal results 28.57% Heodo
2020-01-29invoice-E875_636487.docdoc 72135c6d015b299b10f9a4f9810b8e217b43a66581dbc869d2562cbec3de54d0Virustotal results 29.69% 
2020-01-29INVOICE_D0281_725619146.docdoc 4ebbc029641c276924244405d1b630b683f1fd7b23da40587548e7afcf5bfda8Virustotal results 26.98% Heodo
2020-01-29INVOICE-D015_155535514.docdoc 8818a20402dc42c2d1240599c78d231d98ca26c9ea369787386b2a10d8b5a109Virustotal results 26.98% Heodo
2020-01-29INVOICE DCG867_5546601.docdoc 67180fabd5a9287998057cd7666b1b8896941d37ba3bca1e197e27b447edec6dVirustotal results 25.40% Heodo
2020-01-29INVOICE BAP9987_52157674.docdoc b14d70827d5d668aeb31e94be512fea9fb38ead8ec12cdf7617616801c76b6e9Virustotal results 32.26% Heodo
2020-01-29INVOICE-FS8781_222291432.docdoc b49c9eba58537f8d856daded80bc9493a83c508d73423b98686d4e8b232d61c3Virustotal results 32.81% Heodo
2020-01-29Inv-AV4644_0223237.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29INVOICE-QGOI035_3886025.docdoc f51d2aa766b1b07701a52e866f50132c0fcfaad288c1aaf13c781a66db3168daVirustotal results 47.62% Heodo
2020-01-28invoice UOE97_9508328.docdoc 938b02d03385b7b742362b826d31702182c425bf6fc4857635406f581b258fa1Virustotal results 39.29% Heodo
2020-01-28invoice_CY5_78134626.docdoc 9dbf7690bf328942e99f61b0eae8db502e74c272b7499da4342e6ee7d915bda2Virustotal results 40.32% Heodo
2020-01-28Invoice N09_80570345.docdoc f635c4a870ec9061d6d0d75ad2909b9c7ebe4f21dda6a4c359211fe146df925aVirustotal results 32.26% Heodo
2020-01-28Inv_78_572134295.docdoc e8c780bbb1f9fd071b00776b138b3cf27c3815c7203593068e78774d4dbdb36aVirustotal results 30.16% Heodo
2020-01-28Inv-G6217_04833929.docdoc 92c3a1a03abdc8976c1b9e1b200a2b08e114d2e6dfa54566f81f16a2671e9735Virustotal results 26.23% Heodo
2020-01-28Inv-DR598_126056592.docdoc ff71f06910cdebceb665fef3861262fbabd9f92ebd7285926a1b3d4ed3a7c166Virustotal results 26.67% Heodo
2020-01-28Inv-RYBH2810_43183748.docdoc c72d3a18baf0023ac80353b06452c4fd43e003247f97c3aa98cee47b2f4bc27dVirustotal results 25.81% Heodo
2020-01-28invoice-W9826_88831967.docdoc 58cd4f0ffbd2cfb01f153efd0e8560a2475bc3f98abaf8ed787f8fe17166524bVirustotal results 28.07% 
2020-01-28Invoice GXSV62_484571524.docdoc a6b9f25b3f632a071e548d1e092d8557eedd074094e5e1a2dd684a724fb07fe6Virustotal results 26.98% Heodo
2020-01-28INVOICE-59_292696289.docdoc 32a27468a4355d462e5de6e29290189f023ad6b51836d3134dcb19a74f615f51Virustotal results 25.81% Heodo
2020-01-28Inv_FYJ4325_723179571.docdoc fad431f81e098efc657ea4c9787427f6080e70ef1ea7631dbf51f35578e79438Virustotal results 26.98% Heodo
2020-01-28invoice_UVCI9_75933276.docdoc fcdf9154d769d5e1f3935355b39b57010d978fd2dc9ad24a1df12131f7d34155Virustotal results 26.56% Heodo
2020-01-28Inv-IXMI65_999446.docdoc 42cf3dc2c05800ee63913c2437b824f17dc2999d761edc2c318a7b94fd9ac4a4Virustotal results 22.22% Heodo
2020-01-28Invoice 368_537930732.docdoc e2f79bb91546dd1f490246654ac162545742859643fa265ecd57dc4d225a6049Virustotal results 23.81% Heodo
2020-01-28invoice-MYP15_3033192.docdoc 37f7008209b0cf19267afa8ccdab629b76f4bfa992d7f77ce2c098e5e473c8dbVirustotal results 40.32% Heodo