URLhaus Database

You are currently viewing the URLhaus database entry for http://schenckel.com.br/covid19/statement/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:426310
URL: http://schenckel.com.br/covid19/statement/
URL Status:flame Online (spreading malware for 5 years, 10 months, 20 days, 13 hours, 27 minutes)
Host: schenckel.com.br
Date added:2020-08-06 13:46:05 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2025-04-28 19:51:06 UTC to abuse{at}hospedagem[dot]net)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-28PO_08062020EX.docdoc aeea4cdac6fa009191f99f62bbd8237072af76c1610e0de58cec687b4ff6fe42Virustotal results 69.49% Heodo
2020-08-06DOC_3701714115.docdoc ee6ffd9c87664f86e2f91b10610e4f72151b303e110685cb0a76baca60d43695n/a Heodo
2020-08-0640061270.docdoc 86ce98ee6a09dd1c7c6624e70decfc961385aa91b973c4f19f3f9dbb6091ec24n/a Heodo
2020-08-06INV_OEL_080120_KPY_080620.docdoc 05c72e97f5d458c6490496c4ac646b9555bc470d63b6bbea42875e5adb1a1549Virustotal results 20.97% Heodo
2020-08-06KT_92891244168558.docdoc a552cde24f4002ea256a95334cf7b942868010a6946ab81f3cc5b7e8fcbc57d9Virustotal results 19.67% Heodo