URLhaus Database

You are currently viewing the URLhaus database entry for http://infraprovedor-teste.com.br/cgi-bin/multifunctional-section/external-cloud/hojjm0ewtpzlwl-w247z14y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417839
URL: http://infraprovedor-teste.com.br/cgi-bin/multifunctional-section/external-cloud/hojjm0ewtpzlwl-w247z14y/
URL Status:Offline
Host: infraprovedor-teste.com.br
Date added:2020-07-22 15:28:39 UTC
Last online:2020-07-22 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-22 15:30:04 UTC to abuse{at}lacnic[dot]net)
Takedown time:3 hours, 10 minutes Good (down since 2020-07-22 18:40:41 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22dat 20200722 OKJ13066.docmdoc d516375ff9a645547e27b1359395936c1ba1c5725795a78864b281f8a8b426d3n/aHeodo
2020-07-22FILE-20200722.docdoc 8377d8c4302ad8a31a44fa320938d524ba143b4b076ad91fda4c5c1b73aa804bVirustotal results 36.67% 
2020-07-22ARC-20200722-FE978760.rtfdoc 4e537fac2f1b71c8466b55b1539006dfebfcb9d8d01c793df2ba1198de425f12Virustotal results 38.33% 
2020-07-22Arc_2020_07_22_4023787.docmdoc 5f934443860f4ada8773989bf4ef1a4f9b25d5b0b8449222afdcc5ed0f44748bVirustotal results 37.70% Heodo
2020-07-22Rep 2020_07_22 UR94155.docmdoc 3cdc4b152007b8583277c7ae4ad9e2df4b455d70ea68db4e16537a0354c97362Virustotal results 38.33% Heodo
2020-07-22DAT-2020_07_22-1830314.docmdoc 00f9030cbfb095139a4e8f6fc9e282149fb32fa202c75dd95063951b237bdcb3Virustotal results 38.98% 
2020-07-22file 2075110.docdoc 409beb51fac1a78625ed196de393acddba74b4fcfa22b4902a09fe284781761fVirustotal results 44.26% Heodo
2020-07-22rep-2020_07_22-Y645907.docdoc 5640ce8953e2e40022d391ed9d738bdd8a8bcd4b746db9c5739e130e4863a0f1n/a 
2020-07-22List 20200722 6513.docdoc aa7523ce6f985896168053604865601a6537f096f85d21d211b1c8d69f3a70a3Virustotal results 42.62% 
2020-07-22rep 2020_07_22 25834.docdoc a4730c2913b245ccb77ed0c4a10031a10360828ea6681eb4f9831c502bf0c2dcVirustotal results 43.33%Heodo
2020-07-22file 20200722.rtfdoc 795044c1b058f69d80c2881d9c40cf390e5854d4cc4bfbb69e34a6f4b9e2076aVirustotal results 43.33% 
2020-07-22INF 20200722 2939.rtfdoc 521db82f79a63c6544a1d96f8e9ab77b66899943ddfc3392c49b05b8b6793758Virustotal results 44.07%