URLhaus Database

You are currently viewing the URLhaus database entry for http://bmfestas.com.br/wp-includes/u7j4k8pt-w7o-293/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421693
URL: http://bmfestas.com.br/wp-includes/u7j4k8pt-w7o-293/
URL Status:Offline
Host: bmfestas.com.br
Date added:2020-07-29 21:45:08 UTC
Last online:2020-07-30 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-29 21:46:03 UTC to abuse{at}hospedagem[dot]net)
Takedown time:16 hours, 28 minutes Good (down since 2020-07-30 14:14:28 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30INVOICE-LH428 9411822.docdoc 31e02df81ef4d7cd44122b4d0d8b07c239132dfdc5dbaed717a55ebb94882921Virustotal results 41.67% Heodo
2020-07-30InvSOO550 175909.docdoc 8690dc05c6bd67731c6c21fb590d0ac09b96580085deb9e386f2ba7030eb61ecn/a Heodo
2020-07-30InvP8844-2438447.docdoc 0e25884739bb6556faa119b33345a33b6afd85c8a4d796afb136becb9ffd5078n/a Heodo
2020-07-30invoice_MP7-410349.docdoc 1a4043602dcd5e5f442a5d9e911aed05f79b21aef9caa80b4b147d9c6f937e28Virustotal results 41.67% Heodo
2020-07-30InvoiceGXZG5 396758253.docdoc 21a222d08e717f2970e877f333986711cd59ef25eae1bc0baf053d003df59f25n/a Heodo
2020-07-30Invoice 77_453903.docdoc 24cdf8b366b0eac10b89d7613809bc9297d51e9bc8f69019000225739d5516e2Virustotal results 40.98% Heodo
2020-07-30Inv-V7_57378816.docdoc 58c6a8e6e3a76f2f6eb9d5ba4fc17cca3947ef189398f696f10aa06120b711c5Virustotal results 40.00%Heodo
2020-07-30INVOICE_CYZD5 08851622.docdoc 36cf8d664d59d9193e5db213e948b3aa6be4577b234635408c7d2b8f434f0257Virustotal results 41.38%Heodo
2020-07-30INVOICE-X7333{:REGEX:.docdoc c9555544657e175bf5dffdf80f7243fd0d98daaaadb245105852b7ad94c52fd5Virustotal results 40.00% Heodo
2020-07-30invoiceKUX652-6187225.docdoc 9d5e80345bca0f052faf183924106f9a155eafd9ebf9d09de2d82de4c35830c7Virustotal results 40.00% Heodo
2020-07-30INVOICEK06{:REGEX:.docdoc 917e50fdd6263927050a585d76924748310f1cb1fb4e7612e7c5a385f0c373d0Virustotal results 41.67% Heodo
2020-07-30invoice ASM875-745773.docdoc 84f1793acc6d7c229aed03c0334fcb223eb89415c1d96b08822e988c1a5652afVirustotal results 45.90%Heodo
2020-07-30InvSIOX43_4668272.docdoc e66e3c05c9813a7da90cb5090c3b35bd492b557b83580d7f5f7592f0dee64d90n/a Heodo
2020-07-30Inv_SDF2-142363739.docdoc bdc1e8081137db7607848b3b7d546b6cf36935eef3c38a07a97116868093afd3Virustotal results 45.90% Heodo
2020-07-30INVOICE-XNBN3-62720540.docdoc aa6bbf739a15097060f35839f8bedf662f371e5d1f27dfacd0bd8863b46ab1dbVirustotal results 46.67% Heodo
2020-07-30Invoice-T1393{:REGEX:.docdoc a99c7d681efd2f154e47e585cda75103f5e9abbffee3f7e86dc9da37260624ddVirustotal results 46.67%Heodo
2020-07-30Inv_982-929262.docdoc bb1ea695fd37f791eca7abf169e0ddd46b0a4b880ca51f0f8c55607e800a316cn/a Heodo
2020-07-30Invoice C1 4834339.docdoc 201be4f7a7d31a69ca92f73a75c5a4df9eedda88e619a35fc83f3b9d318a4703Virustotal results 47.46% Heodo
2020-07-30Invoice AAR0034_5636562.docdoc 1212a1ce970bdd52e4385228d90f2db5a5a3a3958bec83f80593a344b1ac9c96Virustotal results 47.46% Heodo
2020-07-30INVOICE_S02-525864.docdoc 1a36bd245a9053a5742fb8aca3169f91382921c429bc62eaef3471cb4bfc743eVirustotal results 46.67% Heodo
2020-07-30INVOICE-MMQ0 8756962.docdoc df1063c155004f08777c7bf91d18f44c2529b0736a80bee492c957f99efb23bdVirustotal results 46.67% Heodo
2020-07-30InvoiceM6434-94192467.docdoc 9a8f438d67fc21b41ed272e536678baf70653b5c7c55986ca9d59569ee046e49Virustotal results 47.46%Heodo
2020-07-30INVOICEKT405-09724210.docdoc 0cfa9d40b08e00ae686376bd8a2c6f038a0bdb6ad27e953b94f1b1643cf54d5bVirustotal results 45.90% Heodo
2020-07-30Invoice E31_232863286.docdoc 981ce108681f9a7d192ab87f86b3442976f338e3118d533037a965c0cf00e601Virustotal results 45.16% Heodo
2020-07-30Invoice_IHD6{:REGEX:.docdoc d39ce67865da7efb2895401ef8d8f54bdd3a7d09784d012b1068d4b5ceaf44cfVirustotal results 45.16% Heodo
2020-07-30invoice_OZSE1668-913469475.docdoc b56bf0f5aef789b7a05528c971f8f709495c67e7b3025fb13dba152446d9c197Virustotal results 46.67% Heodo
2020-07-30INVOICE_VPPS4_5482629.docdoc 7688a4e7b3c2bb471069c2fe4c7fb3d3be6046d6e9d338972d3f586139f7e057n/a Heodo
2020-07-30INVOICECRQ05{:REGEX:.docdoc 35eca265c89361dfa2669720c5fe3ad75c2da020651d95c95782896fbf299c3dVirustotal results 45.00% Heodo
2020-07-30Invoice-U95-38508903.docdoc cf7363d569abe51412e602a505dbb2d3604aaf97ee7c71db42e66b09224dce54Virustotal results 44.26%Heodo
2020-07-30invoice-NP3 3443985.docdoc e4b250743b33a9f2c4d7d065280244cd367b366d401f781c2a99eb69eaad51a3n/a Heodo
2020-07-29invoice_FGME8695-0326967.docdoc 9682cb3fed20b168899452201908168de9b2c2d82530d7227a4474b8b2587eb8Virustotal results 43.55%Heodo
2020-07-29Invoice-OAW40-768932014.docdoc 7fe243f4aba911b068c05e32e50c8063c2ba9a9f350d5bcb8539a74e6f282df2Virustotal results 45.00% Heodo
2020-07-29Invoice OPY2310 91506297.docdoc 1a509a842e1a24c4ffe665706fc677197002dad72cf5ba4a2711e9aace8dcd70Virustotal results 44.26% Heodo
2020-07-29INVOICE_E7540-305435.docdoc 504c84d3083058366a68b164b12c19ae0a928586ff465b3f5199ee572d5ff953Virustotal results 44.26% Heodo
2020-07-29Inv-70{:REGEX:.docdoc 7f5a5cc7f1b7bcbf396b957f3f6600eaf0913662c78d5b2f87d30113aafdd155n/a Heodo