URLhaus Database

You are currently viewing the URLhaus database entry for http://www.lojajosemar.com.br/site/hdg-gux-5698/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421770
URL: http://www.lojajosemar.com.br/site/hdg-gux-5698/
URL Status:Offline
Host: www.lojajosemar.com.br
Date added:2020-07-30 02:59:16 UTC
Last online:2020-07-30 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 03:00:03 UTC to abuse{at}dimenoc[dot]com)
Takedown time:20 hours, 12 minutes Good (down since 2020-07-30 23:12:46 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30Invoice 27_736452122.docdoc 1c8026d6bd75a1ea091d6a6676d3a7e3bcba3b17717e21607488b9fdb762fba7Virustotal results 49.18%Heodo
2020-07-30invoice-8849 9648453.docdoc c83969e81859c8ba427abffea78663dfe0ea99293074096f42edd85903e45876Virustotal results 47.54% Heodo
2020-07-30invoice_ZEH349{:REGEX:.docdoc 2ccfe3cb5c9044e383e930aa33fb0e74fed092845982048455384c26475e9149n/a Heodo
2020-07-30Inv_VCWN89-323118774.docdoc 4bae1b817b5f647d1da6fa839d95dc1a747069f8cb885d0a402df30d268b6b5cVirustotal results 48.33% Heodo
2020-07-30Inv_XB5881 43711527.docdoc 01663b94d847370d937c017344092fb204b3fef3bca2c0d26c9f49ebac946525n/a Heodo
2020-07-30invoice-4-959677.docdoc 780b3f3f5e407a4aab5ab78b0cdc4c76bce67d3e2383fb03dc140e846a10e74eVirustotal results 47.54% Heodo
2020-07-30Invoice-R874-230930317.docdoc bae2af6b9665e503d04df2d1ac30e8b31685c948f248a3aaecdeceabfa1ff9ceVirustotal results 47.54% Heodo
2020-07-30INVOICE-J8-81993120.docdoc 5f4b06fe51e7558cd72e9897ab224919503ec18ea12c8352431db819b74e252bVirustotal results 47.54% Heodo
2020-07-30INVOICE_5-538886.docdoc cafd2c780bab54f0e196d1960af4f5ea207d883461efe818b373828eb21e92dfVirustotal results 47.54% Heodo
2020-07-30INVOICE-W3 5891131.docdoc f2a8be2190fc82926a24c1d0bc6cd8f554949ebd1fba55ec585b40896ef68bbdn/a Heodo
2020-07-30Invoice FX3 58709714.docdoc d7ddeb76f38f0832acc1fc181ab104abb4c0e329c167f5f38a7b89a9947971fdn/a Heodo
2020-07-30invoice68-010159.docdoc dbc64153efaed9d70d1daa4c4099f517617754890fa39854eeefd1fa0e595625Virustotal results 44.83% Heodo
2020-07-30invoice 37{:REGEX:.docdoc c80234a1aae152d166a2463362aac041e4dad5993185be3024f752b9232b2089Virustotal results 44.83% Heodo
2020-07-30INVOICE-ZOZ5102_485338.docdoc 57cd3c6667afd66293fe85bc6632764caa8217677ecf64f34c72677367fd9472Virustotal results 46.67%Heodo
2020-07-30invoice_FYNQ94{:REGEX:.docdoc 1b6fd0e9210a891184b54f0482b18998204e81b7c6a03338edb3811eb2701fd3Virustotal results 41.67% Heodo
2020-07-30Invoice_IKA2946{:REGEX:.docdoc 8690dc05c6bd67731c6c21fb590d0ac09b96580085deb9e386f2ba7030eb61ecn/a Heodo
2020-07-30invoice-CVTB028{:REGEX:.docdoc 0e25884739bb6556faa119b33345a33b6afd85c8a4d796afb136becb9ffd5078Virustotal results 40.00% Heodo
2020-07-30Invoice-JT88-379562476.docdoc 1a4043602dcd5e5f442a5d9e911aed05f79b21aef9caa80b4b147d9c6f937e28Virustotal results 41.67% Heodo
2020-07-30invoiceJQ17-4137778.docdoc 21a222d08e717f2970e877f333986711cd59ef25eae1bc0baf053d003df59f25n/a Heodo
2020-07-30invoiceVTZL70-515463539.docdoc 24cdf8b366b0eac10b89d7613809bc9297d51e9bc8f69019000225739d5516e2Virustotal results 40.98% Heodo
2020-07-30invoiceMAF5-3845394.docdoc 58c6a8e6e3a76f2f6eb9d5ba4fc17cca3947ef189398f696f10aa06120b711c5Virustotal results 40.00%Heodo
2020-07-30INVOICE-OHBS1829 541020160.docdoc 36cf8d664d59d9193e5db213e948b3aa6be4577b234635408c7d2b8f434f0257Virustotal results 41.38%Heodo
2020-07-30Inv_AP336-988606.docdoc c9555544657e175bf5dffdf80f7243fd0d98daaaadb245105852b7ad94c52fd5Virustotal results 40.00% Heodo
2020-07-30Inv-GN0908_673577.docdoc 9d5e80345bca0f052faf183924106f9a155eafd9ebf9d09de2d82de4c35830c7Virustotal results 40.00% Heodo
2020-07-30Inv-WVN1_12965894.docdoc 917e50fdd6263927050a585d76924748310f1cb1fb4e7612e7c5a385f0c373d0Virustotal results 41.67% Heodo
2020-07-30INVOICE-S1_43784498.docdoc 84f1793acc6d7c229aed03c0334fcb223eb89415c1d96b08822e988c1a5652afVirustotal results 45.90%Heodo
2020-07-30invoiceGWU47_602055.docdoc e66e3c05c9813a7da90cb5090c3b35bd492b557b83580d7f5f7592f0dee64d90n/a Heodo
2020-07-30INVOICE V38-460914627.docdoc fd4e7761b18405677fc5c8737a34ace11283a0c1503a19a20120c9f36af7c004n/a Heodo
2020-07-30Inv-KPHN50{:REGEX:.docdoc aa6bbf739a15097060f35839f8bedf662f371e5d1f27dfacd0bd8863b46ab1dbVirustotal results 46.67% Heodo
2020-07-30INVOICE_EEXU0{:REGEX:.docdoc d7f5fca8f5de440dff815ea87b1b67a6d1a22028f8b39363240ebdb3cc43479eVirustotal results 45.90%Heodo
2020-07-30INVOICE-HNEQ0684_95215041.docdoc 7579d4a1d6d4da73019950ba9cd7de417560465889ccbc12fffbebff6b87ca3cVirustotal results 45.16% Heodo
2020-07-30invoice-MS648-6718842.docdoc fcc525f6dd0c743849afb4e000a0829d47f24999eea8c8689721e2afd70df51bVirustotal results 44.07% Heodo
2020-07-30Inv RFKH931_33695303.docdoc 35dfa0b9a11dcd3a2920e7da86c66da6b2b94ab67c9aac6e3743e53bd3346f80Virustotal results 46.67% Heodo
2020-07-30invoice-TMC8556 542907249.docdoc 1a36bd245a9053a5742fb8aca3169f91382921c429bc62eaef3471cb4bfc743eVirustotal results 46.67% Heodo
2020-07-30InvoiceMUBV98-1014925.docdoc 133d58f3c65e1886b5480e277bb845f9d97a7177d1da22625c6a977553b374cbVirustotal results 47.46% Heodo
2020-07-30Inv-A69-8129561.docdoc c444016d70224a2cb4808352f39232719d705243dbaf2321c3aed6cee511890fn/a Heodo
2020-07-30invoice-SX38-9028156.docdoc 434275c04e5ac65d4e763e14aa5291f8e9e7b344fb8e4768dcdfbdeea9af06b5Virustotal results 45.90%Heodo