URLhaus Database

You are currently viewing the URLhaus database entry for https://cearacultural.com.br/turismo/jREpILbQm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427274
URL: https://cearacultural.com.br/turismo/jREpILbQm/
URL Status:Offline
Host: cearacultural.com.br
Date added:2020-08-07 16:00:06 UTC
Last online:2020-08-09 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 16:02:04 UTC to abuse{at}hospedagem[dot]net)
Takedown time:2 days, 3 hours, 37 minutes Poor (down since 2020-08-09 19:39:15 UTC)
Tags:doc emotet link epoch3 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08invoice-WHE70-0598143.docdoc 5d7f4b905c268a16b873261ceb5f2bca434dbaa45ad6c5b20a3d43091709ace2Virustotal results 39.66% QuakBot
2020-08-08InvHXV336311952.docdoc f2ac567d25e6c1c3423309a6ee7158f3740d1f4b648a3d0b162b83cf1dd3b6b2Virustotal results 38.33% QuakBot
2020-08-08INVOICE WMH194 180391.docdoc 06b06f3b9576ce114f9443f1eda165be0ffdf8182d26b478bd9110a5528639ben/a Heodo
2020-08-08Inv_4793_16233010.docdoc 04f64fdd071b6dd1efc0123b08f8609929e91ec16d51b955461d9d1454d8bfcaVirustotal results 39.34% Heodo
2020-08-08invoice_SC553_357497765.docdoc 7e6769ef042d11235ccb92f40d7ee699bd81ef995b00f66e10ddd3b5bb5e92dfn/a QuakBot
2020-08-08Invoice_N413_96837607.docdoc 4c353ef6b7ce0abc18d802dc5869a0c6bb88a63e31585b98f518d10fedb62428Virustotal results 39.34% Heodo
2020-08-08INVOICE PLMI00 8265324.docdoc db215901595eb9e3359f679ea0018582715a7a540043a00d9417558895ffa6dan/a Heodo
2020-08-08invoice-582-433759708.docdoc 09e2172af9c38a6d8145f2bc5f71ef35e7aa2fa507c32d432b76fbd3e07e6c11n/a QuakBot
2020-08-08Invoice-UQ28-517996.docdoc 2af8a3cbd38150acd1e45a77f8814c1f1e674f022cf22133a4a7f1c978c3db72Virustotal results 39.34% Heodo
2020-08-08Invoice7360399212556.docdoc 1128152d7cc44f3e7408942d4122b0978e20afe325fd67f0be4738570c4f5600Virustotal results 42.86% QuakBot
2020-08-08Invoice-KTJ2-216493.docdoc 4230abaf305c2ba58db88a37cafe4fd78fccc75c521116a664286870179be682Virustotal results 40.98% Heodo
2020-08-08Inv_OXLR66_7331626.docdoc c9bdce375621af7dd83001e09e95fa17ae125b59423cda4a4499fb3f31fc1adeVirustotal results 40.98% Heodo
2020-08-08Inv-H43-855545398.docdoc 181a73930d18db229ad4ae73c4132a6cf281b75283d8f25c2674bfa2294e9152Virustotal results 40.00% Heodo
2020-08-07INVOICE_89_21224302.docdoc d91731a4dfcfb45b578cde0a57e35273bdc0eecf426e738a1f52a32e989c9fb9Virustotal results 37.29% Heodo
2020-08-07INVOICE MGNB6895 669305.docdoc a4b97280b1cceda62816b36b8b40327eea965a74334cd171eeca03b3158d3177Virustotal results 37.29% QuakBot
2020-08-07INVOICEG72396099.docdoc 522dfd2bd5983277254467284eb5cb1ae79a0957444adbd473462cfee3599c4dVirustotal results 37.70% Heodo
2020-08-07invoice-HBBI935-90739165.docdoc dd693242b7c4ea00e3edc941a1b92d17d7effee6af390cd0abda5da40e5f4367n/a QuakBot
2020-08-07invoice_OO2477_819317080.docdoc 3d2f7bb83fc1e0ff00062b026e00645a1f25b5538f799fc47cb8f1878d8d9c39Virustotal results 35.48% QuakBot
2020-08-07Inv-D138-01516378.docdoc d8ed4fd8240d522ca6a6f60b17cc639ad6dfdb93ef50a62987c6091b7c80c56dn/a Heodo
2020-08-07INVOICE-RGOA853-7371682.docdoc 66762226f0f7bab8acf658aaf69557223a227f9225671446d93e502b6d221fd0Virustotal results 30.65% QuakBot
2020-08-07invoice-27-180651687.docdoc a1d3c10648113856a54d5142939fddfc547781a277390386c2c66731226e65d7Virustotal results 31.67% Heodo
2020-08-07Invoice 77 60524799.docdoc 2232504c5ac6d12d0c0acc9590c5957289d5177e41c502d10797f7bfcf436fe4Virustotal results 27.42% Heodo
2020-08-07InvoiceRCIW49158453.docdoc d43e6eec7587cc038fd92be0d45b18cbd948a9d927fcb5d378e47e1c1ef141c6Virustotal results 27.87% QuakBot