URLhaus Database

You are currently viewing the URLhaus database entry for http://frisa.com.br/lixo/gpuqebwh-7rw5n-72/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432750
URL: http://frisa.com.br/lixo/gpuqebwh-7rw5n-72/
URL Status:Offline
Host: frisa.com.br
Date added:2020-08-14 01:47:09 UTC
Last online:2020-08-14 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002867191 created on 2020-08-14 01:48:06 UTC)
Takedown time:14 hours, 52 minutes Good (down since 2020-08-14 16:40:14 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14Invoice-836-673477370.docdoc 3faefaec25266917cdada868fc8076b16e9b42382e82bfb5018562978d0085a1Virustotal results 31.15%Heodo
2020-08-14InvoiceTJD099014587964.docdoc 022cf3a8bcb181e5218ff3a6b7e759e94462df01ff93902560371dfa2ffc0950Virustotal results 28.81%Heodo
2020-08-14invoice-MEFK1-870619.docdoc 47e583738beea94617d095118319318193630be4e2ddf5ae8ce66ebb131df7ffVirustotal results 27.87%Heodo
2020-08-14Invoice FB98 201164.docdoc 8668a5aae3e7db513fdb925e16313049037536bc67a86ed756b682c98b7f6f09Virustotal results 25.86%Heodo
2020-08-14Invoice_LJXG1768_587847369.docdoc 946ce7bab4b96c0fd40f3bb134b7d616880bc04dc8eacdf9d4cf10f4c0287cb5Virustotal results 26.23%Heodo
2020-08-14Invoice-OU632-0488331.docdoc fe58e66ba70c6c395732f2c817dbd2c6454463fc5104633ec022c7d1fac1bed9Virustotal results 25.00%Heodo
2020-08-14invoice DHAI0 79413961.docdoc 4828a6c7692c1ca3bee53f0c8dd1ff26f21faaf8cb2c66e0c4c460c6dc9f6dfaVirustotal results 25.00%Heodo
2020-08-14Inv1967423999.docdoc 31fd17ea13411b2b4c8a726012b7e3390527519bfcb805d9d895877a627c8f7eVirustotal results 26.23%Heodo
2020-08-14Inv_106_983734471.docdoc b3ffd34596fe613e60507fc3754eb284d3bdf1968ea939014bb5c3efcdefedaeVirustotal results 25.00%Heodo
2020-08-14Invoice 67 756338.docdoc b580ef15f157d6c19b61810ddb5f085007685d55693d05cb54782cb52bac7e2bVirustotal results 24.14%Heodo
2020-08-14INVOICE-STA1-680301.docdoc 0aeb7a7ccd5f0a664f6955eaf500b29020c82c40acd8b9d14cff49c6a9377f72Virustotal results 25.00%Heodo
2020-08-14invoice-51-97052963.docdoc e8d602a059428b4576239097eede7757ab616eb16521eb1f2b2b6795621f4c50Virustotal results 24.59%Heodo
2020-08-14Inv-88-1074100.docdoc c8491294ace5a6682e374787541ec78d155b4e288f143a086cb3320328782317Virustotal results 24.59%Heodo
2020-08-14INVOICE-P055-511964114.docdoc 495ebea1fd0ea1d5d47a3696aa58045c06311416da9f715ead1bc2809b8732b9Virustotal results 24.59%Heodo
2020-08-14invoice-YLX68-1346661.docdoc b873855abe6ecb687a4df753ed5f4882475ca551c53ffc20ef18b3c896115a91Virustotal results 23.73%Heodo
2020-08-14invoice-VDDR444-76045831.docdoc 538aec1c87a88d78a75a417c253579be5fa18cefce592109122505cf70f2eea9Virustotal results 40.68%Heodo
2020-08-14Invoice-WQNR2-78037776.docdoc 57fb3ca3dbdd2ae95d6f78eaa993bebc8011a01ffcbcdf2ef5398996e781d532Virustotal results 40.68%Heodo
2020-08-14INVOICE-MI4230-626559775.docdoc 3132acbb0aa02f175f2e8bf589a53e732564cf73f1f003cb64c842ba52d3c889Virustotal results 41.67% Heodo
2020-08-14INVOICEGJZ595369596720.docdoc c32ebf07a4f2324cc33cf6e7c975c375621c519fa654fc27303c9a812293fd7fVirustotal results 39.66%Heodo
2020-08-14Invoice-9742-6135684.docdoc 382eeb05e0b37509916697e88d5f58e00cfd17db07cf9b27240fd84aa4bcd26eVirustotal results 40.00%Heodo
2020-08-14invoiceG950230284132.docdoc d77766273a903661def8286676499fd3cf8f2a337cd8fa867e5788e5509db0e6Virustotal results 40.00%Heodo
2020-08-14INVOICE-Q41-1151910.docdoc a5cebe26ebd797b743940f94cd3b74255ae3864a8042734c1b430e3da0198e2bVirustotal results 40.00%Heodo
2020-08-14INVOICE-711-933246585.docdoc f740ad05fe75e146443ce0776602fc5828a534f28e1e2f34a1d785083de85bd1Virustotal results 38.60%Heodo
2020-08-14Invoice-11-40914074.docdoc ad1c63f07f872f3b37453d29dce7654dc1b79e4f3e875dd8090977c30093b6f6Virustotal results 37.93%Heodo
2020-08-14INVOICE720947347.docdoc c7d8be22d5926e4e9ac2070fb940ff3e1018005732ba84890fdb1dc9a9cef1c5Virustotal results 37.29%Heodo