URLhaus Database

You are currently viewing the URLhaus database entry for http://dev.cotidiano.com.br/wp-content/9GS8-BVrAgh3b-array/close-forum/KpcwAebSIP-g29x2eIK5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303578
URL: http://dev.cotidiano.com.br/wp-content/9GS8-BVrAgh3b-array/close-forum/KpcwAebSIP-g29x2eIK5/
URL Status:Offline
Host: dev.cotidiano.com.br
Date added:2020-01-31 02:21:34 UTC
Last online:2020-03-06 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-31 03:16:03 UTC to abuse{at}lacnic[dot]net)
Takedown time:1 month, 5 days, 10 hours, 56 minutes Bad (down since 2020-03-06 14:12:25 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-02List 2020_02_01 3161295.docdoc dda76af8d395dccbe545d1229617376570b747b0bacfe5582b646f42937eb732Virustotal results 38.10%Heodo
2020-01-31MES-D9482.docdoc 98d4100547490c9809f92a82a3afc57c4927ce1e84664bad304d005b9754a02fn/a Heodo
2020-01-31DAT 2020_01_31 LY137168.docdoc e7863425cfe23c40a2c40e179c1bd67eba047602a382158bb9458b1f52cbeec4Virustotal results 20.97% Heodo
2020-01-31Doc_2020_01_31_EIU783804.docdoc 9fb0a6fe332aeb878af094ebb838b45e25773204f45c299a2c31fa1070c7d80bVirustotal results 20.63% Heodo
2020-01-31DAT 2020_01_31 R5098.docdoc 9ab30abebfdb3619b5253d44a3e4b928ad5d7ae3a1af4c5634f3b1faa7e675a2Virustotal results 20.31% Heodo
2020-01-31Dat 2020_01_31 VSP89384.docdoc 1927c895365ce9eb0b850ccab2180fd7d46e42b647113981b953bd353c6edad6Virustotal results 20.31% Heodo
2020-01-31DAT_20200131_Z45816.docdoc 3ad1ce31e5fd92383ef10bfd1ef62d5163e305c89f3b23ec9a266a18cd8a0fdaVirustotal results 20.97% Heodo
2020-01-31File_20200131.docdoc 46a180dbbafaa9ec4b0e37da1c2d0cc6ef8833d830966504ec7037e7f69b35f6n/a 
2020-01-31ARC_20200131.docdoc a5a1cad504ed2881f3206bcc602f7e379d15cd59082cac926f2fd286257ca9can/a Heodo
2020-01-31Inf JT6206.docdoc db5ec50aa0307b01efda63c0c839ca56003ecb0cf9e97153c79a15f8c7954de7Virustotal results 41.27% Heodo
2020-01-31INF_20200131_QE380.docdoc 8cf8b5bd984c809a86c9c425d500393b50115233149a953678de79dca4bdc223Virustotal results 35.94% Heodo