URLhaus Database

You are currently viewing the URLhaus database entry for http://www.jalanuang.com/wp-includes/cerrado-seccion/9tp-5h4-9tp-5h4/67ycs-nslr8ekI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308888
URL: http://www.jalanuang.com/wp-includes/cerrado-seccion/9tp-5h4-9tp-5h4/67ycs-nslr8ekI/
URL Status:Offline
Host: www.jalanuang.com
Date added:2020-02-05 10:05:34 UTC
Last online:2020-02-08 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-05 10:06:07 UTC to abuse{at}linode[dot]com)
Takedown time:2 days, 18 hours, 21 minutes Poor (down since 2020-02-08 04:27:47 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-07Contrato 02200871.rtfdoc fd5216cbae4012683b6e2c8485107a45d76219010e0fe331a3cdc4ad94c520d4Virustotal results 24.59% Heodo
2020-02-07OFERTA-02_07_2020_E267235006.rtfdoc e3adf368b634569aa1ca2545bb340ffb5df4c918cf629e3afec00b6f43d444fcVirustotal results 24.19% Heodo
2020-02-07Contrato_696m6m8mom.docmdoc 4d46d038cd9f2a48555e70846240d75457b23f0c3a192d9a9bf8a498ea35e2ceVirustotal results 23.33% 
2020-02-07Contrato 7U95076-15447592.rtfdoc 5480139ad1a7d156879a92736b3feda1f6e9bb49c6b7bd8b92471e76e92fa60fVirustotal results 43.55% Heodo
2020-02-07oferta_6410688.rtfdoc 45460794b9f09c81f86ec924d5e4d685810a07f8536e4984b02ab6cb86557b19Virustotal results 44.26% 
2020-02-07OFERTA-02072020.docdoc 4d968c78fbbe35761183c26176b2cc44e82409b1a759cc410e11e8a4bf5f042cn/a Heodo
2020-02-07OFRT_3962019.rtfdoc ed52942baf8ed14a9b9da31174f471dd978344583c83f0851abbbfa219f15167Virustotal results 41.94% Heodo
2020-02-07Contrato_02_07_2020_5919010.rtfdoc dda86e610dc7cd7c6dc32877c7933dc7c341e6e57f35219c82c674fb4f85f7b4Virustotal results 35.48% Heodo
2020-02-07Contrato-02072020.rtfdoc 9707abd47ef72798f3d0aa3c5f58c076f401350bb34bef7d5c7660108eab8e42Virustotal results 32.79% 
2020-02-07Oferta-9407709.docdoc 24cc00288998f8deb1ec06f90b3dc247584cff225033e281607b281525f98c91Virustotal results 30.65% 
2020-02-06Oferta 95334447884.rtfdoc 4810daa4ccbb49abbb0e59e495561bb59b892d44fdb400afd61c2b9b78e047deVirustotal results 29.03% 
2020-02-06CONTRATO_02_07_2020 B37884623.rtfdoc 76ed65f4166ab70a504fa0c58b5fa4d5afbbdf92c3b7770185b137ac87aa37edVirustotal results 29.03% 
2020-02-06Contrato-o9m26n498.docmdoc 0f9546ef0fe98af36e43a06ae58080335e7051c19f85fa72157d75d7e85f12c1Virustotal results 26.23% Heodo
2020-02-06Oferta 02_06_2020 F426189.docmdoc 69caf04e8e1e56614bea23015c10066190147415d1c1699accdc79c49531cedbVirustotal results 29.03% Heodo
2020-02-06CONTRATO H489206_52950130.rtfdoc e62205f9ad8ce110e6f628a4622e7f12d9db3b4c2cc100e1d464b06f2a2b0afbn/a Heodo
2020-02-06CONTRAT_1796018487501-66849420007.docmdoc 548c32e1f7c11d658a1b45cc341ea2480b28c86e352baf366289aaa70a9e9292Virustotal results 29.03% 
2020-02-06Contrato-02_06_2020_E7310676523.docdoc 7f536bbea678ea8894392854b2929ca6860dece9b1acc42df0913613035b682cVirustotal results 29.51% 
2020-02-06Oferta-WPZ0316.docdoc 33b5e2a31a3000b7a3251be5436e451986568c1a93ace24fab40817786f5a2e5Virustotal results 27.12% 
2020-02-06Contrato_MB6662.docmdoc 3c9d9f7c089af3d74e37371950a676a966f7160c531930a218fcefda342beee9Virustotal results 26.23% 
2020-02-06OFRT-2028179_535924.rtfdoc 20a0926fb970d58fb5681385d5b8bbc67f1abdfe2e240c721e1034857c14cb9aVirustotal results 24.14% Heodo
2020-02-06CONTRAT_n6p08415o36q5.rtfdoc 6b1d90ff1212f95e6fb72180e90a64d316ee24b22f2803c46dedaca64ca09914Virustotal results 22.95% 
2020-02-06oferta 5616p5133o.docdoc 5c65f21a3869e1e15433c2263d8dff3827f622520c972b12f4686250b8e68018Virustotal results 23.33% Heodo
2020-02-06OFRT-1op89m3.rtfdoc 6359275fa65b551a691c324e03fa5c3c73ace835ca4f3d90087dc3332f76ececVirustotal results 22.58% 
2020-02-06OFERTA-02_06_2020 8F9290204.rtfdoc d0ba1020328bfa59129c6d94b6bfd8979bd652574b24407bcfdadc75fcf28fb4n/a 
2020-02-06CONTRATO WKE079757-332400957974.docdoc c163d2a385feadd582c11612d2692072b57c78c665520df24672437a2bd549e1Virustotal results 21.67% 
2020-02-06OFERTA K6123.docdoc 9bf2c6a167cdca17cacba485a4e8dbbc600518a91fb3286401f7b387123b2944Virustotal results 32.79% 
2020-02-06OFERTA WFF974473485 252662987.rtfdoc 346d01cf657414934f8c87af6f0ae07d23875f613db84e483f2174b6353ab405Virustotal results 33.33% 
2020-02-06oferta-02062020.docdoc 84e6bb18fc4d5994987feb9edc02eaaec7cc0988b27845fb8735d3c45591e5cdVirustotal results 31.67% 
2020-02-06OFERTA 02062020.docmdoc 9e7490ea59c003826b03252f70bd3fc3a4c910d44aa5c1cf377a0cb24491118eVirustotal results 33.33% 
2020-02-06CONTRATO-02_06_2020 E14909967.rtfdoc 74491fc6dd7ba85729f150a091baf5019a4a9cfcfa8e7bb6d450c9edf7762fb3Virustotal results 32.79% 
2020-02-06OFRT 02_06_2020-6B0200.rtfdoc 58f94895848e841464a8b36d26e332a50e9b082bd7df37c1c054168929b7b34eVirustotal results 31.15% 
2020-02-05OFRT 8938997782.docmdoc 061b77c1354bff1d5cafa4e10d903ee5feb16bb91c295298444e056ffefd1370Virustotal results 26.23% Heodo
2020-02-05Contrato-KH669632104655_42193.rtfdoc 85d825b74358c12b84824b2d46cf048e3dfe836a8c320d88d301331a46e62ec2Virustotal results 27.12% Heodo
2020-02-05CONTRAT 02_05_2020_5C596210783027.docmdoc 23f4a774007e2fc64a2824e5973bb695a64667d8d832fbc29806976dad67d7f7Virustotal results 26.67% Heodo
2020-02-05contrato-9490954711.docmdoc 47ca3de0e80a4e9571311ab0b2470ecc29d18c990b063b57aef1818e5a3c260aVirustotal results 26.23% 
2020-02-05CONTRAT_B48804492-19618.rtfdoc fe70cef82c0a8acabe3289f5863a62b3bdf8bbd476ff9c0536600c40fcbbfb9aVirustotal results 26.23% Heodo
2020-02-05Contrato 81839.docmdoc da0b1e331a89bd28e4338a886d224c01e9194a764a6ded30bac8b16670a589b3Virustotal results 26.67% Heodo
2020-02-05OFRT 02_05_2020-AH983253.rtfdoc 20b603562ad65e466c27733e3ba8368c3ed83caeec165555f4a935ed0cc6d4b1Virustotal results 26.67% Heodo
2020-02-05Oferta_C7353.docdoc e9de053b8046e662771b320b25a49cd709591ac896fb6bd4c324ba0b13f37b35Virustotal results 25.00% 
2020-02-05oferta-MXI834668039 7313079.rtfdoc 371850e54872c538a8464ca44e70aeab03d5b92f663761bff7af669a5de8fe5fn/a Heodo
2020-02-05Oferta_02052020.docdoc f6e0b5d91b15cc7860054d38d1b2cee458fe349ef370cbcb1064e91d8ad6d889Virustotal results 24.59% Heodo
2020-02-05CONTRATO-37mmq770.rtfdoc c8ec8d35b45aa7de5ffd6716eee33f7c55d2c77357732c5fe4f3377affb1859cVirustotal results 24.59% Heodo
2020-02-05Oferta-6857649988.docmdoc dbbe0d7dded778f388849d7ce83487c413292de6f83d4d8286e7b13bd8f5b981Virustotal results 24.19% 
2020-02-05Contrato-02_05_2020 6754762486.rtfdoc b92b5e4564b9f56cd6b9aa1f9d8f34918a892bde770d942aa98357a62c8e4756Virustotal results 24.59% Heodo