URLhaus Database

You are currently viewing the URLhaus database entry for https://cascavelsexshop.com.br/wp-includes/Reporting/a86rn1g/yevrp507617932rurxjjvb28svfv5uu6ul/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:306822
URL: https://cascavelsexshop.com.br/wp-includes/Reporting/a86rn1g/yevrp507617932rurxjjvb28svfv5uu6ul/
URL Status:Offline
Host: cascavelsexshop.com.br
Date added:2020-02-03 14:08:05 UTC
Last online:2020-02-03 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-03 14:10:03 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:7 hours, 23 minutes Good (down since 2020-02-03 21:33:32 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-03REP_WMTRZEG.docmdocx 1787233e224423612ea55da7cdd95d09717dbe4a65b4625584c019e6be6b59can/a Heodo
2020-02-03BAL_KQ3071983323KG.docmdocx 66b4c1812c14e4205db933d71228ab440bef65713c61a7fb1f86378c0d45a943Virustotal results 33.33% Heodo
2020-02-03JOU_020120_WBL_020320.docmdocx 09996febfd3f32069757a2793f83b02d207a488e09c79334969090485bfc7a12n/a Heodo
2020-02-0315239268.rtfdocx 973a1cb5a188c0da391635cac891cbe784456c90858cc4538a30b46d10821e0en/a Heodo
2020-02-03W_PO_02032020EX.docmdocx 3bfccf265670f48debb6c84d0a9f244f5d28c8abc8d097c8accf5f88ba778448n/a Heodo
2020-02-03FILE_77558208.docmdocx cb86586b428fc416f5a411ad24448f76455e47f0a1b5cbe45da44bf587a33b19n/a 
2020-02-03A94RXUOC1Q.docdoc 6bf43243ef28c065b7f294a1fa965a1b19ca7bfb73c15e9dfcbd186d042cc1a3Virustotal results 28.57% 
2020-02-03BAL_24076760.rtfdocx a03848f8c010b9f74e925e1bd2b047d3fc56fa6b5524ff77ad689219aa05be58n/a