URLhaus Database

You are currently viewing the URLhaus database entry for http://lupusalimentos.com.br/assinatura/lgswgttc-flpkz-93501/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421593
URL: http://lupusalimentos.com.br/assinatura/lgswgttc-flpkz-93501/
URL Status:Offline
Host: lupusalimentos.com.br
Date added:2020-07-29 18:35:07 UTC
Last online:2020-07-29 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-29 18:36:06 UTC to abuse{at}locaweb[dot]com[dot]br)
Takedown time:2 hours, 30 minutes Good (down since 2020-07-29 21:06:20 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-29Invoice_ZB786{:REGEX:.docdoc 4ece79e02379040355a4ff12f9b622c675a9910c6f10d98c393b790dc0c9536bVirustotal results 36.67% Heodo
2020-07-29INVOICE IY3137-741841516.docdoc 9031e6db6e2296c8de8b8f71f6e03e3251e9b3497acb57e52ef2a1a1a6b646e1Virustotal results 36.07% Heodo
2020-07-29INVOICE UVF118_947211899.docdoc c9908873e05408d13895e8545fd5b9e3eb95032f5e363086b19e6a14a8ed7075Virustotal results 35.48% Heodo
2020-07-29InvEK1890-810849.docdoc ef939c6757486356eebfdc09af29303c9ac05ba4e54bc6f98ca1206664792a81n/a Heodo
2020-07-29Invoice-P264-04833690.docdoc cbf7197df6cd966772e966e4e8a67f74d1b090ade41e58f80f706a071ac64286Virustotal results 36.07% Heodo
2020-07-29invoice-WEVY2935{:REGEX:.docdoc a19deec65bef4fe1030b463be94b414c4b4b1bad207acfc2fd8df6bb5bbbefdbVirustotal results 35.48%Heodo
2020-07-29INVOICELW9775 252858.docdoc c65c81e1a76fdf4122271da9b47b9b45e0a45519719f468e7539eba8ab8f9d5fVirustotal results 35.00% Heodo
2020-07-29INVOICE_A19{:REGEX:.docdoc aebd20f5f33a243e226932532fcb08c7f948d679ac4c6df277aebcc4f0571894Virustotal results 36.07% Heodo
2020-07-29Invoice-BT7008-20560927.docdoc 1506ac2044400ad8ef962e4a6869f6691adf13c46c27733f26bd8eede6136244Virustotal results 36.67% Heodo
2020-07-29Invoice_ECJE194-33560454.docdoc 1b23e6893b349fd94640f1425a5ffebe9b61b4d3e21ad8f8ab5117384f0ffc0dVirustotal results 36.07% Heodo
2020-07-29Invoice NASO01-6230855.docdoc 0028341f11b512a3b80bb54598e61666379dffaaab8a08ddc7d9a92fd029233bVirustotal results 35.00%Heodo