URLhaus Database

You are currently viewing the URLhaus database entry for http://lsouza.com.br/default/En_us/Change-of-Address/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:39791
URL: http://lsouza.com.br/default/En_us/Change-of-Address/
URL Status:Offline
Host: lsouza.com.br
Date added:2018-08-08 05:08:50 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?):No
Tags:heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-08Invoice as at 08/08/2018.docdoc 4f2fcb83fe623beaf68003bda7390bf8365d6f3ced0bd5168da9078833c1e108Virustotal results 32.20% Heodo
2018-08-08Final notice.docdoc 7719ffce9acd3c3db888dc04273188fb87b1b3e5e1fafc65e8e47f61f56b254aVirustotal results 36.07% Heodo
2018-08-08Invoice Query.docdoc 3a28112cb77e2055039365cfbef5b3f829a5a504bc4add97f507f000039041e7Virustotal results 36.07% Heodo
2018-08-08Invoice # 013Z77537.docdoc ca90ee3ceb6b5f53c97e5621978522340940c65ff05b26248b391c4971d098a9Virustotal results 36.07% Heodo
2018-08-08Money transfer details.docdoc 904171c20a36669fe9ee06fac73eb36dd9d390361e3d7f490e502c370f72cdc6n/a Heodo
2018-08-08My current address update.docdoc aedfdb4ee0961b847d3168b5cc8cb983a1b1f0ff75d79c648a2e82c4f227186aVirustotal results 34.43% Heodo
2018-08-08Details to update.docdoc 1925b795206b4791b5d89bb8ece497e16807c9d6e5d031778e6462dca775eb2aVirustotal results 36.07% Heodo
2018-08-08New Address and payment details.docdoc 7eb5c67145e3db0d435c694758a91832063a714713a095f207643c3146264df6Virustotal results 34.43% Heodo
2018-08-08Address and payment info.docdoc 79d1e8a4a1b0c29b5a59a0b1b3e1f579e4f040c42fdb1ac0705ee8167d060dabn/a Heodo