URLhaus Database

You are currently viewing the URLhaus database entry for http://localnet.srv.br/WJVwDSQQzP/whriB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429983
URL: http://localnet.srv.br/WJVwDSQQzP/whriB/
URL Status:Offline
Host: localnet.srv.br
Date added:2020-08-12 06:47:05 UTC
Last online:2020-08-19 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-12 06:48:09 UTC to abuse{at}lacnic[dot]net)
Takedown time:6 days, 22 hours, 2 minutes Bad (down since 2020-08-19 04:50:53 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13Invoice_M80_1143591.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 26.67%Heodo
2020-08-13Inv R7303 172081.docdoc 267245def36dc107de0213044013ec67b837c68ed109267f13728319263b5664Virustotal results 25.00%Heodo
2020-08-13Inv-C5568-014401.docdoc 335ffaa3c9914aabf84fec4cf13a891465b4c0c3700777b1fa2877df708b4c7eVirustotal results 25.00%Heodo
2020-08-13Invoice-F1101-454781.docdoc 906423a8a219d85fee1c58feac18a6bc8689504a672ec96d5df2e61079f60672Virustotal results 25.42%Heodo
2020-08-13invoice_NHPS146_92187279.docdoc 53aa63c2bd135d388b8e04488a7c9ae94867bdb6d13388bd623b3c988500e59aVirustotal results 25.00%Heodo
2020-08-13invoice_BH426_4858303.docdoc 0b9983bedd5702a9bf94c237a85fdcf11a637f0212b8ab32dc746da8a2a62148Virustotal results 25.00%Heodo
2020-08-13Invoice_O5_89619839.docdoc f844331d28cf2533981a9e753d6df2e9677efadaeea9b2c014266991ae78280fVirustotal results 26.23%Heodo
2020-08-13Invoice-ISD4-956595.docdoc 0026fed9eb774358f3bf6e17eb2425a7938b206b5841334c137edefa4c249bf5Virustotal results 25.42%Heodo
2020-08-13Invoice-O6356-44557476.docdoc cdb381f78364b3a519d51aa70490c2a66f26062664a172c82b15f14a70297bb2n/aHeodo
2020-08-13INVOICE-Z7424-8646120.docdoc 5478e4974b64a8471ba220eb079a7dec82a9ceba893c8d56e165235a8df47f25Virustotal results 25.42%Heodo
2020-08-13INVOICEWPJ65757666.docdoc 46b21be022edbd1e3c421e00b0f0fb17b33ff686feb8309c819c817da38d7fe6Virustotal results 53.33%Heodo
2020-08-13invoice 10 727184.docdoc 10531f315432369a9c0706bc00ac1405445316044a9ec07b03de6606a6a9f9fbVirustotal results 55.00%Heodo
2020-08-13Invoice B2 619660.docdoc cd0aaf460944efd580dcc39bc1dd0460f88f2c3c17e303694ffa1eae5020eab2Virustotal results 53.33%Heodo
2020-08-13Inv_6_671569.docdoc e1c720ebaa0f446a16ce18dac61a138b0d4c73a1e59236ae3c91c6cb73da5a1en/aHeodo
2020-08-13invoiceKKLP1366205198125.docdoc 90452e3bfaf3cae36b9bfcc2e98684fbabbc11074887533175a04b41b2a8734bVirustotal results 54.24%Heodo
2020-08-13INVOICE-6071-9167422.docdoc 97e52709f1f9169fb2a3d0cfc7852f811d067999ed1bdc700c6b66bc7dc23765Virustotal results 52.54%Heodo
2020-08-13INVOICE-VTI33-748601967.docdoc c879a18b84d48cbe14f846e68b905beb462461008fb0a1706d9899acb7b11871Virustotal results 50.00%Heodo
2020-08-12Invoice-7-540036379.docdoc b858572fbe695215c2aa6ade7ada24c980392ad2f5c9e3564d4e6446ef424383n/aHeodo
2020-08-12invoice-EOMZ9-56225033.docdoc 8feb19a7e4447548ee33b791936bba0f89689bce34033420d3b05995e8126a6eVirustotal results 48.33%Heodo
2020-08-12Inv-J2-633707.docdoc d60d130c4369c7d41edf041927897b2ceb6b845a66b97bfeb0cf7d60575fe399Virustotal results 47.46%Heodo
2020-08-12Inv-LS143-4879215.docdoc 86f28a02ba775b0ca41c9b11ecbe4455335eeb3a3e6e0c3860098aace208a315Virustotal results 50.00%Heodo
2020-08-12INVOICE-ZOQ262-616480959.docdoc 24b41c6091602c0f9df9cc64905ce9dac977a04f700ae0607de467c101a093dcVirustotal results 49.15%Heodo
2020-08-12InvoiceAFQ627474078742.docdoc 0c7d085dc88b57e56819a0a9319e1aa089ad9851a0ea21137aab6309395ed039Virustotal results 49.15%Heodo
2020-08-12Inv-B58-564958.docdoc ff563f0125c05e1a24c111ca5306fc7394a4a705167d272704bb0c2067a96b4fn/aHeodo
2020-08-12INVOICE-WQR838-2840499.docdoc d1ce5170f24fdb09f187ca0e3e0f6e689fa2c73fc6953ff18ecc123bb8eed49cVirustotal results 50.00%Heodo
2020-08-12InvG3420155.docdoc 95fe4603a20fce976fa2b80fe19e89a3a8f0df85029a1cfbc4a05990aaa78a3en/aHeodo
2020-08-12invoice-LHN5-21397257.docdoc f2414110e5d69a3653a43f580b5a599f99245d0492065654a44a6d46529eed3eVirustotal results 45.00%Heodo
2020-08-12INVOICE CN0 260243399.docdoc 1bf7159812124e19faf31cbed4b558aa9fa78b5f1a0562cad0dac81865d03094Virustotal results 43.10%Heodo
2020-08-12invoice 1680 627965064.docdoc 70d733ec6924d4c286296e2c705aa1f21c9f1f8d9085d4b2ff6dbbba1e5766dcVirustotal results 40.00%Heodo
2020-08-12INVOICE-X4477-050530832.docdoc 8961a6a26ad05af0256bc2ddd21efba0fd0e1d1900a73c736fbd7b749dde0357Virustotal results 38.33%Heodo
2020-08-12invoice_W3694_6624102.docdoc 3f5261f4d28c39abec2986a50be9436202150bee5188fda8a1d52e186a7423caVirustotal results 32.79%Heodo
2020-08-12invoice_INP363_9597018.docdoc 7e80fbe683372b02372090968d9795df4d7683ce0f8691fc8a8efc25e49364d2Virustotal results 30.00%Heodo
2020-08-12Invoice-G297-375426658.docdoc 449f416c3f2657eb8b2df9c66efefcffdaa3528103658aa9e8de03e9197a666bVirustotal results 30.51%Heodo
2020-08-12invoice UWFY7607 630479.docdoc 6f17ffc6e968596bcc7554237206467a43c24b88c81433a41add7c3c3b4d6803Virustotal results 30.51%Heodo
2020-08-12INVOICE-CSSU98-433420087.docdoc 4b643a7d7cf8515411aea4ce9d9a11893c50ef4b9cf3978396183d562ec90c14Virustotal results 30.51%Heodo
2020-08-12Inv-MY1-4770513.docdoc f03c7d0d70435e0776be04c92e918456dca44144b09ac5b8e65a6269352e5e31Virustotal results 29.51%Heodo
2020-08-12invoice Z6 172816.docdoc 6610beb62b2916d0194d87458804ec7ae2e18e6efd800866b9d65db7a6e6b361Virustotal results 30.00%Heodo
2020-08-12INVOICE_GTZE9_319205642.docdoc a89386d411d6224956ba5504820bddc5adb335c6d058756cbd1bb7b5fc9dce36n/aHeodo
2020-08-12InvYQ487047917161.docdoc 049dc856ae4474fbda10bd89613b8d85183f1a2336964cf7ab366a993c8b5631Virustotal results 30.51%Heodo
2020-08-12invoice-RG991-746128.docdoc 42355a35a2bf3d690fed99b24a34a5e6cd67fa3c21c20e7747d01a1f71d998ecVirustotal results 27.12%Heodo
2020-08-12invoice O1 11696635.docdoc 92891d0665902ca174cc6ebf4cca8fec9d9486730b7796e2c4c63b5a2f29ab8aVirustotal results 26.67%Heodo
2020-08-12Inv-BJ9576-91080495.docdoc aa93187017f9056d5cdc98302b5c41c322d54bdf3ce694c30d598140c4ab8ed6Virustotal results 29.31%Heodo
2020-08-12INVOICE_MJR4_2242017.docdoc d9cd9ae614caa6ef65cb4d5cffc16164132b1192251d7e8e0e12b8e4fc5f7dfdVirustotal results 28.33%Heodo
2020-08-12invoiceQUDY803379285.docdoc 32750365d68890d9071db244c4b3534a22dc90130e47ca9dfb21d81277678528Virustotal results 28.33%Heodo
2020-08-12INVOICE_T7_8476516.docdoc 3878a507270346a9cb72ef10f715fea30a403ceb12326e565fcf4e03abb874edVirustotal results 27.12%Heodo
2020-08-12invoice-I067-41743014.docdoc d8c9580c0c9f2bb8a4e50b71b6bf047c9a5aa42f2fbc76b4315fc8b2bd90fef1Virustotal results 27.59%Heodo