URLhaus Database

You are currently viewing the URLhaus database entry for http://ones.net.br/wp-content/uploads/personal-array/external-j9mgrwpf5-3btir5lz3kmgk3/066511221910-liXD9ojuC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:437763
URL: http://ones.net.br/wp-content/uploads/personal-array/external-j9mgrwpf5-3btir5lz3kmgk3/066511221910-liXD9ojuC/
URL Status:Offline
Host: ones.net.br
Date added:2020-08-21 00:01:09 UTC
Last online:2020-08-21 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-21 00:02:02 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 52 minutes Good (down since 2020-08-21 02:54:41 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21List 2020_08_21 9665030.docdoc 4fa671e7978d7f0c9015dd93cccf6d046f1015d97e182d6692bf5ed9a23035e7Virustotal results 31.67%Heodo
2020-08-21ARC 774205.docdoc 07108d19c9ebaac8f7dc6c7259296014f7bd6f4f8df85c582b156900b6af3ea1Virustotal results 30.00%Heodo
2020-08-21list.docdoc fb8874145efad97ec5b7ceb9979d73d17c2d424985d4474f4982ad4ef72b54feVirustotal results 28.33%Heodo
2020-08-21Rep_2020_08_21_659727.docdoc 2fb4d27ecf72a41fb9d7eedc6e4dd2b7a3028de206c728c23575284c734fca60Virustotal results 30.00%Heodo
2020-08-21Rep-20200821-6289036.docdoc 387e73e8b041a7eadb9503b7cd1f194ec03c786ba1d81b2c895fa324e27e7866Virustotal results 30.51%Heodo
2020-08-21Mes 6493.docdoc 4110ff6fd94e12036973899b93449ae19fa8f38a35133ea442c8418c6f7721ffVirustotal results 28.33%Heodo
2020-08-21Arc 2020_08_21 125.docdoc 07ddcb80960052bf42117eff7367436d37f023ec1cbd9c1e266f89181839dcd6Virustotal results 28.81%Heodo
2020-08-21Arc 20200821 M30504.docdoc 28b77aebdcbdcae80bd92aa279f603c7089575bcd0dcb2eba95d6a0bd1e0aab3Virustotal results 30.00%Heodo
2020-08-21List_20200821.docdoc f700afeb2595f93fbd20330874105e21d152a8e2e257093a2435de4294cddc8eVirustotal results 31.67%Heodo
2020-08-21MES 2020_08_21 0442.docdoc 86b2e2bb47bbbea1a01f03f9d4a2d191f0f9ca40c688f6b06378db262cb20e3cVirustotal results 31.67%Heodo