URLhaus Database

You are currently viewing the URLhaus database entry for http://laschuk.com.br/default/En_us/Open-invoices/INV585276516386013/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:42330
URL: http://laschuk.com.br/default/En_us/Open-invoices/INV585276516386013/
URL Status:Offline
Host: laschuk.com.br
Date added:2018-08-14 04:25:32 UTC
Last online:2018-09-10 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-09-07 17:46:18 UTC to abuse{at}hospedagem[dot]net)
Takedown time:3 days, 1 hours, 15 minutes Bad (down since 2018-09-10 19:01:49 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-15Invoice.docdoc e88024b1820e48d500576aabfc1e9e9b9464df554be0ba08cdde7eb6d4e95e12Virustotal results 26.67% Heodo
2018-08-15Invoice Query.docdoc 8c4ce35dda3d110f5e6e6bac50cfbb34751f5db03188170d1680144fcca1267cn/a Heodo
2018-08-15Invoice.docdoc 9b0839baa0922196d1c9af88985487b24298e62fca519d58ff03d46cba49c7c4Virustotal results 32.20% Heodo
2018-08-15Invoice Confirmation VI06501.docdoc 61f8679f1af61e12535ddedacd965dbb1f745d85d67e597f97df64c2947e35f9Virustotal results 30.00% Heodo
2018-08-15Invoice Confirmation 5C429199.docdoc 7f58976b59ff4dd80cc39c62c8850e4db6b83da1ea613cd9480321a0484c6153Virustotal results 37.29% Heodo
2018-08-15Invoice Query.docdoc 72a9605fb3bb77cde5b3fb2d1355df6707e0fb3c7fe4d0ee20e561354234d15bVirustotal results 37.93% Heodo
2018-08-15Invoice Confirmation QB5730.docdoc def44d5e8f11965378f2059cd4978fc4e46ce26f785fd2ef5a6359e8c81cfbean/a Heodo
2018-08-15Accounts - Invoice.docdoc 23d5a27e14c1441567e38b6a14485082e88f56133f18d60a4d42e5ce9a60d743n/a Heodo
2018-08-15Customer No 6643864.docdoc c12e3138da25045d878e6c577cba65ed3b25e0100035fc9fcb2992da77ab8531Virustotal results 33.33% Heodo
2018-08-15New invoice 43095785173.docdoc 78c8459629d6d186b8e344e1361540ea66dca3285057643cbfb8fe77a3440fbdn/a Heodo
2018-08-14Invoice as at 15/08/2018.docdoc 6c46e7e208b58ab8e3a2f519e571a96a77a64f934bd2609bbdd09755f868a48dVirustotal results 30.51% Heodo
2018-08-14Invoice.docdoc 5c6d9f00e6fcf35631b4b45573b5ef3523be605ddb1d3e34213838821686ff2dVirustotal results 26.67% Heodo
2018-08-14Customer No 318390.docdoc 75c75abfb68fa9ad3ba70008aa74974e0125be70764678d86e51f1ca37d0d918n/a Heodo
2018-08-14Final notice.docdoc 98d4c036aa8edc94b6e508adcbec57c4c507a5ecdf481cc30aee66f3a9057b11Virustotal results 29.31% Heodo
2018-08-14Latest invoice - 361284.docdoc 56bbc15741d9dd380655a3c68f355e081ad4efb4a4f0979d3e9696ecfd745e7bVirustotal results 29.31% Heodo
2018-08-14Review invoice required.docdoc 3ca142d99be06a2f5cbef86ee38bce1c530cbf157848da57bdb433651f387650Virustotal results 29.31% Heodo
2018-08-14Final notice.docdoc 624cd190286fdbf40b32768f2fd330f7ba4ec4824a38fef7894d24708c52411fVirustotal results 32.20% Heodo
2018-08-14Month notice.docdoc 20f4771fc95bb5e7d9a371334784a1f92b9b7f124f03daa095b429b370e0ae5bVirustotal results 31.67% Heodo
2018-08-14Invoice Query.docdoc 875d6972e93a4f285ec3b123f7138336981472fa7535d716b9a330db526e33e0Virustotal results 26.67% Heodo