URLhaus Database

You are currently viewing the URLhaus database entry for https://comunicacaovertical.com.br/agencia/cTNJNsnhz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427154
URL: https://comunicacaovertical.com.br/agencia/cTNJNsnhz/
URL Status:Offline
Host: comunicacaovertical.com.br
Date added:2020-08-07 12:18:36 UTC
Last online:2020-08-09 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 12:20:03 UTC to abuse{at}hospedagem[dot]net)
Takedown time:2 days, 7 hours, 8 minutes Poor (down since 2020-08-09 19:28:18 UTC)
Tags:doc emotet link epoch3 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08invoice WPT8 1929679.docdoc 5d7f4b905c268a16b873261ceb5f2bca434dbaa45ad6c5b20a3d43091709ace2Virustotal results 39.66% QuakBot
2020-08-08Invoice UGQY4 68757513.docdoc 6c1e2497b23d20655d8eef924d28c3fd28db1fa7cb11126fb9079c8e65c11010n/a Heodo
2020-08-08Inv YI1754 944843651.docdoc eb283960353efbf54aa5fea1afd72a13e16ffb3e86b9230aeac43d3e2c346e17Virustotal results 40.00% Heodo
2020-08-08Invoice_4232_264315.docdoc c3d556b58967b1957a9c5b9e5465e6af4230e6f94ed8b1109d30445a86d2fb9fVirustotal results 40.00% QuakBot
2020-08-08Inv CKN98 682054.docdoc 795144410d184d35fd61e5d83a0b3a1bb669ef7c4ed028eb1b315a78e4ddd9bcn/a QuakBot
2020-08-08Inv_ZGV4077_57143262.docdoc c620f32017dc5a093d19d6362b34657906e156082ffac1c93df403171a2fcc32Virustotal results 38.33% QuakBot
2020-08-08Invoice-S8-6905307.docdoc c8451a4260d26137a6dc3200a2290e14f2210f03417e39e58ad95052ec6b0de7Virustotal results 39.34% Heodo
2020-08-08invoice 4 50196299.docdoc 51d32641c97d78c53640cc9fec84f1b150eb754042a74ce028d92f70bcf7544an/a Heodo
2020-08-08InvoiceHIHD50929993.docdoc e2f4571846f5b8e17a5481779757851f78f2853f6734ce6ef4a92db0cd0c5de2Virustotal results 38.71% Heodo
2020-08-08Invoice-OW8547-9036486.docdoc b5b0dab6e7d7a2fc66a0947ad16fc1b6de4d68b73d5d071459ed06b18a96a8a0Virustotal results 38.33% Heodo
2020-08-08Invoice-XQON8-6302962.docdoc c9bdce375621af7dd83001e09e95fa17ae125b59423cda4a4499fb3f31fc1adeVirustotal results 40.98% Heodo
2020-08-08INVOICEU2112221386.docdoc 8ee784204fc5d7cb096a234e69f593cb6807f74e01a2393e1d1f9a8e99f22b74Virustotal results 37.10% QuakBot
2020-08-07Inv_QG9702_504359.docdoc d91731a4dfcfb45b578cde0a57e35273bdc0eecf426e738a1f52a32e989c9fb9Virustotal results 37.29% Heodo
2020-08-07Invoice-XJP659-42607582.docdoc 346b0ed5db257c2bf541ae37f57e3971a19bc69310811cbe7fa037768f2136a1Virustotal results 38.33% Heodo
2020-08-07INVOICE_YDI1_13603732.docdoc 96c2710133ec54c60394683f148a94ba31cda1182b21b8f0f3285d78c92c0336Virustotal results 35.48% Heodo
2020-08-07InvL7672559972.docdoc 7ce67620298aa7d0fe5e7f2bab8e052f4a4ce937c3300c92875e33d7b466acc0Virustotal results 36.07% Heodo
2020-08-07Inv_MMMF1477_64171250.docdoc 7db00665e2dd62c48b6e8e1e088ceef5fc94a2e95aa2ea549139c049842d2b7cVirustotal results 36.07% Heodo
2020-08-07invoice-Q3-707404400.docdoc bb196956c5e57876daf8c64828c2b0cff8f83fc540f7ff492ecd7632f8a235dcVirustotal results 36.07% QuakBot
2020-08-07invoice-O7635-292759766.docdoc ebdda6969778acca315a17e1505c60c3ebbf9c13ca2b43a5092c7a32341f06acVirustotal results 29.51% Heodo
2020-08-07Inv1959504.docdoc 737d96d343a18d4739a12d2b949eb31e758fb5e24c17b0c706997154731ac07fVirustotal results 30.65% Heodo
2020-08-07INVOICE-I49-967722770.docdoc d5bff5a6b9e1f13e2206aadbb6ff705b7eb29882299b70d8f97205264cb1c04eVirustotal results 27.42% QuakBot
2020-08-07invoice-WJOY75-37387465.docdoc 3a7e162433ba4372c7e49ee5cb6bd4afb23cde7bc0f19d39edc30aa22473994en/a Heodo
2020-08-07Inv 590 0263457.docdoc c2ecd3419f71d51acb56c7f02e685cdd46ec96514b459545a931768e2141ae58Virustotal results 27.42% Heodo
2020-08-07invoice-1267-55045300.docdoc ab1f576293cc70428b0adcadcbb453c1525ff8bf2fa71d650e52b83ff4092f81Virustotal results 26.67% Heodo
2020-08-07invoice_O93_3406152.docdoc cd0a8f71f9191062a85d74dcd5321d7882e38ba58e3f04468a7e5b2c1aa32209Virustotal results 25.81% Heodo
2020-08-07Invoice BVZI83 0992026.docdoc 67067a83cf054c8deccf1e31d09a2d8ed82469b2e27884e87aefef248019b89aVirustotal results 26.67% Heodo
2020-08-07invoice 4712 05664960.docdoc 0a4b53e2bf7608fe93c60618cf50a657598aa4fc95b947cc7fa7b8fb0331d561Virustotal results 25.81% Heodo
2020-08-07Inv_XWYT18_1635592.docdoc 97ccb1a0753548a9218edd2f6a16265d2f479d1114c5f378772d768a89f52309Virustotal results 26.67% Heodo