URLhaus Database

You are currently viewing the URLhaus database entry for http://negreiros.com.br/bin/zoZb which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:37784
URL: http://negreiros.com.br/bin/zoZb
URL Status:Offline
Host: negreiros.com.br
Date added:2018-08-01 16:16:27 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-08-17 09:26:44 UTC to abuse{at}hospedagem[dot]net)
Tags:emotet link exe Fuery heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-037721.exeexe 4e632882ebfc93f81db6c5714c7de37b4e0118cb828b87ef2a4f107ef3d8b5b2Virustotal results 35.29% Heodo
2018-08-036972903.exeexe 86d013ec4f6e563c73a9e880605f5b364b9bc53cdb9b4fe717d56f8728c537bcVirustotal results 26.47% 
2018-08-0370777547.exeexe 74d94e31b3d7cc6b1d574e4708cbfcacbed26734ca47c02c78c5b13319d11ef0Virustotal results 27.27% Heodo
2018-08-03087806.exeexe e6d7930019a05b43e235856b3a43e8b6111f9dee5487447864a9f8ffce3713bfVirustotal results 27.94% Heodo
2018-08-031.exeexe 556bf347d190eb16ef2b5f66b8775a449d94b6af12712503f507b71c4a83de4an/a Heodo
2018-08-0283.exeexe 99670f40b3b0b205930456ba9ecd70e6d5c2e493d59bda59b3cfe6e5bd2ca336Virustotal results 25.00% 
2018-08-02872983.exeexe 577a6826751e37661d869a918e5ee4bf9614a2793250400362a43a6ef8b01ca5Virustotal results 25.00% 
2018-08-0262709837.exeexe 97532c8a951c3e5e7808009a16ad5a35a97aa21dd121273364b5b3ccf8b5bb3eVirustotal results 18.46% Heodo
2018-08-0286173642.exeexe c878b37b7236aa3a230b9e4b613dee0538182ff043944abcebadf78b08cfc426Virustotal results 19.12% Heodo
2018-08-02386418.exeexe 5962f42dcb66ab283a9a9d407b3e90f3591c151e0d77afc5c1bca68e6befbfc6Virustotal results 23.53% 
2018-08-02030883.exeexe 204f2ae5a8959ca4ca9a5c287501f36f31d1256a419b58ac2759858f518a6c16Virustotal results 25.37% Heodo
2018-08-01289.exeexe 11e3285835acaf3c863a0e4228920b8b2474d1926a0f2f700a30498a9d3a1bf4Virustotal results 25.00% Fuery
2018-08-0150.exeexe 15f820211b333caab179238ff3a1dfe113f1205faca87a8c158075eabc08b91fVirustotal results 22.06% 
2018-08-0168507309.exeexe c8c02b3ccd34e4377f145b8b575ed99912e91a19d84462274e2d55cec28fb846Virustotal results 30.88% Heodo
2018-08-0149.exeexe 98939c5b58ac31aea41d48aaf59dfe9a68f46d262049d7d1202704af395cf1dcVirustotal results 32.84% Heodo