URLhaus Database

You are currently viewing the URLhaus database entry for https://www.duosite.com.br/host/1pot-cmh-08014/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422502
URL: https://www.duosite.com.br/host/1pot-cmh-08014/
URL Status:Offline
Host: www.duosite.com.br
Date added:2020-07-31 00:21:07 UTC
Last online:2020-07-31 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-31 00:22:02 UTC to abuse{at}hospedagem[dot]net)
Takedown time:12 hours, 54 minutes Good (down since 2020-07-31 13:16:41 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31Inv1{:REGEX:.docdoc 3d8ef147ca84e9943fdc850171e2de9c05b0db3472cd05901e4f109e7fbe07f1Virustotal results 50.85%Heodo
2020-07-31Invoice-OXIG9-895672086.docdoc c7ed06b6f4284ba3fd857f03875187654aad78683efa88d3ed984fe057d484abVirustotal results 50.85% Heodo
2020-07-31invoice-LVK021_720124.docdoc c66fa17e4f5d76079707aa28d126feaef92ac1245b1ecb420e7e632e8eeb76a2Virustotal results 50.00% Heodo
2020-07-31Inv_NO78 01571195.docdoc e3c6519f7b0b581bc58ccec2a76f8bce09e09658d05624ef33b7c5cce0197b6bVirustotal results 50.00% Heodo
2020-07-31Invoice GVRS84{:REGEX:.docdoc 9d87ada7dcb70d012d66826ec3f4f26a2f853edce07b15282c119048283a80edVirustotal results 50.00% Heodo
2020-07-31InvPI8{:REGEX:.docdoc cb27bed9b173d425693fe6c19d0d7502d62645a8fff074790841a362952e9936Virustotal results 50.82% Heodo
2020-07-31Inv_O7567{:REGEX:.docdoc 1e253d59d5ef3aaf08431b406cd5c024476603459b847f6b40dd0f86827492c1n/a Heodo
2020-07-31Invoice_YCWY6128_6036050.docdoc c8e498b47aef6cfa8fe5259b40faf397127d496992e126c2f4f6026f7945813bVirustotal results 50.00% Heodo
2020-07-31Inv_M632{:REGEX:.docdoc e5e54d832fa5fb735e145e940936d4fa7a472c5f0de5133cfd4c0581e764c313n/a Heodo
2020-07-31invoice 42-90458704.docdoc ea4ec66d739ec6c93a0e5890743a01a5283b804889147308ba45d35ee1f2247dVirustotal results 50.00% Heodo
2020-07-31Invoice DDHB96-378704.docdoc 2ab3a5f443403e9ed1928d27e4e551ab95a6532d540b98d5103f0ed8a45a75cbVirustotal results 50.00% Heodo
2020-07-31INVOICE UCCZ8136-43324427.docdoc 1c8fbd8d6b61b142ce1cf7b436685ddcbd703b2c47224db9fef379f5b3815eebVirustotal results 50.85% Heodo