URLhaus Database

You are currently viewing the URLhaus database entry for https://osomdascordas.com.br/wp-includes/report/sa7iog7a/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:301438
URL: https://osomdascordas.com.br/wp-includes/report/sa7iog7a/
URL Status:Offline
Host: osomdascordas.com.br
Date added:2020-01-29 14:20:09 UTC
Last online:2020-01-31 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-29 14:20:11 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 4 hours, 0 minutes Poor (down since 2020-01-31 18:20:50 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31UQZN_ISX_010120_XNH_013120.rtfdocx 100f39e84287ca9ea977d399fe1135ab34bf7c244cbb9c14408f8255c3538d85Virustotal results 23.81% 
2020-01-3142419627.docmdocx 12f17aa88c41cd66c648d4f19289192958e721c494829eb67962060967d804beVirustotal results 42.86%
2020-01-31SW_MITHNOEZIAOJIF.docdoc 42509b3b1ba3a0a8662183a03fa090c771966d59104d92bc60f13fc541eaa606Virustotal results 42.19% Heodo
2020-01-31SW_06415391.docdoc d9da04e380314c465b5327ec20a828f9b134ae9d8efc8326f6f814cafde3e62eVirustotal results 33.33%
2020-01-30RP_LB5PNIUMDU53Q.rtfdocx 463cde2d102dd645ef48b67e638fccda43b8a6d326adf8b635e9fdfb12b21842Virustotal results 35.48% Heodo
2020-01-30RP_3393716985371086639.docmdocx 64725b2adf2954b04470c2187d3ecbcb843b201de1917a7e92e077ad944922e6Virustotal results 39.06% 
2020-01-3046891574.docdoc 742ff5d108dde54201313a8e00988f9eb9f50bf349e6b9f83c6127a42d12b726Virustotal results 25.40% 
2020-01-29J_NE7916117327MZ.docdoc 135e6e64bd7742b372ada6b825319eb55fa6081a563f2bb5b8c41b146badb7e9Virustotal results 32.26%Heodo
2020-01-29BJP_010120_NJN_012920.docdoc 428338f3fab9a2f41cb31ea8bf705bd7a4311b2308831ef50c2347ca3ae155d2n/a