URLhaus Database

You are currently viewing the URLhaus database entry for http://efetiva.net.br/cgi-bin/o8n-097z-980/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427202
URL: http://efetiva.net.br/cgi-bin/o8n-097z-980/
URL Status:Offline
Host: efetiva.net.br
Date added:2020-08-07 13:24:06 UTC
Last online:2020-08-09 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 13:26:02 UTC to abuse{at}pt[dot]clara[dot]net)
Takedown time:1 day, 21 hours, 30 minutes Poor (down since 2020-08-09 10:56:37 UTC)
Tags:doc emotet link epoch3 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08Invoice CFJZ9698 297580.docdoc 5d7f4b905c268a16b873261ceb5f2bca434dbaa45ad6c5b20a3d43091709ace2Virustotal results 39.66% QuakBot
2020-08-08INVOICE-021-195390.docdoc 8ee784204fc5d7cb096a234e69f593cb6807f74e01a2393e1d1f9a8e99f22b74Virustotal results 37.10% QuakBot
2020-08-07invoice_ZMHM075_3607530.docdoc d91731a4dfcfb45b578cde0a57e35273bdc0eecf426e738a1f52a32e989c9fb9Virustotal results 37.29% Heodo
2020-08-07Inv_1_102250733.docdoc a4b97280b1cceda62816b36b8b40327eea965a74334cd171eeca03b3158d3177Virustotal results 37.29% QuakBot
2020-08-07INVOICE_368_882110000.docdoc 522dfd2bd5983277254467284eb5cb1ae79a0957444adbd473462cfee3599c4dVirustotal results 37.70% Heodo
2020-08-07INVOICE_STU4253_20349319.docdoc 1647229d0a492df5ee794a4a799c66da98a76da48e6accede91ddb08a694be01Virustotal results 36.07% Heodo
2020-08-07INVOICELC89656611332.docdoc e8035bcb217908bb414bb819f5f71f6745ab19ee1348c122ced77fff342930d5Virustotal results 34.43% QuakBot
2020-08-07Inv-107-2314400.docdoc d8ed4fd8240d522ca6a6f60b17cc639ad6dfdb93ef50a62987c6091b7c80c56dn/a Heodo
2020-08-07INVOICEN45989004.docdoc ebdda6969778acca315a17e1505c60c3ebbf9c13ca2b43a5092c7a32341f06acVirustotal results 29.51% Heodo
2020-08-07Inv-QZUJ583-240157.docdoc 737d96d343a18d4739a12d2b949eb31e758fb5e24c17b0c706997154731ac07fVirustotal results 30.65% Heodo
2020-08-07Inv-648-521748.docdoc 23f821e6c9ca56b683bf96dc9e8d6d19094c60ea1223073f466278f12a2745edVirustotal results 29.03% QuakBot
2020-08-07InvARHU546809982770.docdoc 3a7e162433ba4372c7e49ee5cb6bd4afb23cde7bc0f19d39edc30aa22473994en/a Heodo
2020-08-07INVOICE-F9839-082916271.docdoc c2ecd3419f71d51acb56c7f02e685cdd46ec96514b459545a931768e2141ae58Virustotal results 27.42% Heodo
2020-08-07InvWFX3647184293.docdoc d0cf81816d667ed017c8fcff606f72dd98ccdbd4ab1c740d6e93822bdb303188Virustotal results 25.81% Heodo
2020-08-07INVOICE RTLO0 5988390.docdoc 288bcc48727e2eed9e8b0c26b5c3e04a3856769d65bfd4065bba4a533237bf36n/a Heodo
2020-08-07invoiceWCGF966433529.docdoc f2f9d8844e0ea0472349e17048e353522a138927c4b88802535845aa231f0833Virustotal results 24.59% Heodo
2020-08-07INVOICE CV7 84985933.docdoc 03ebc44cfbcccf33f186b7fa2350c9b7043d031b274921de003e30d9d999dfb8n/a Heodo