URLhaus Database

You are currently viewing the URLhaus database entry for http://bemnessa.com.br/available_resource/FILE/9045/qygGXZHB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438022
URL: http://bemnessa.com.br/available_resource/FILE/9045/qygGXZHB/
URL Status:Offline
Host: bemnessa.com.br
Date added:2020-08-21 07:57:05 UTC
Last online:2020-08-21 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-21 07:58:02 UTC to abuse{at}hospedagem[dot]net)
Takedown time:5 hours, 14 minutes Good (down since 2020-08-21 13:12:09 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21AD0860765025IA.docdoc 7f2c8c4b7894e6d7e260f4f48034312a7fb96c9728c9c9fe0e4afd9866daabf3n/aHeodo
2020-08-21X672 invoicing.docdoc 3e4b8326cfd9bfaeb2956b955bf3644032eb675cfd32a6284f371b2d6f68a47bVirustotal results 22.81%Heodo
2020-08-21Inv. 0849157.docdoc 69eab92915bca8074c0e4c4a14a6d4532a6d4162923b7c51799ae872c647ee21Virustotal results 21.05%Heodo
2020-08-21invoice #290153.docdoc 403c11dfcd14c01cf91b6fc45cb7ef0a55919e8e5e0292399e1cbe734bb9d2a3Virustotal results 20.69%Heodo
2020-08-21August Invoice.docdoc f31012ac78ab2a6de1fdb75aed9cee6eb69e6222f724303a66da51fe0c29cd0en/aHeodo
2020-08-21RA00823 invoicing.docdoc ebf536cc3ab147667e77823b5feaa2f72da1042d653ad11a26298800a7a86d77n/aHeodo
2020-08-21Payment status.docdoc 4da5e980866878da930be670800361fd6b9b6ec73983dd60cdba9eb29bd09ab6Virustotal results 22.03%Heodo
2020-08-21Payment.docdoc 9da9694a1d52b592d84be3c64b9cbccadfa602164ebe526c2a1223438384e7f7n/aHeodo
2020-08-21Inv_8999.docdoc 787b14bfeb8561a5053f8ef91cecff83bea99a6acf52f2aea33414fa780bc5den/aHeodo