URLhaus Database

You are currently viewing the URLhaus database entry for http://efetiva.net.br/cgi-bin/OCT/qx0gp2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438154
URL: http://efetiva.net.br/cgi-bin/OCT/qx0gp2/
URL Status:Offline
Host: efetiva.net.br
Date added:2020-08-21 11:36:07 UTC
Last online:2020-08-24 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-21 11:38:02 UTC to abuse{at}pt[dot]clara[dot]net)
Takedown time:3 days, 4 hours, 1 minutes Bad (down since 2020-08-24 15:39:43 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-23DOC_86812651920.docdoc 493fbab43b8eaf0772394866842fa9474e8e54a84894498828af06590dff1cbdVirustotal results 59.65%Heodo
2020-08-2211820374.docdoc a82a505dc341da5731aa8aeba61771b3532f82d5aca83c80332ce01516be6ca9Virustotal results 55.93%Heodo
2020-08-22FILE_31419822.docdoc db6ba79a4a1de58ab33b517ace62dfe2363d93ec437fa43c2ed976b32ad70742Virustotal results 54.24%Heodo
2020-08-22F_PO_08222020EX.docdoc d3234eae40e4f920d7de37b21c236482a003b5c808619c7b3bc1c06a2efb9ce5Virustotal results 44.83%Heodo
2020-08-22INV_01667273339689753882.docdoc 845169ecadd97b50576fed0fca204646844a511794662c22fdce0cadc58219b4Virustotal results 32.76%Heodo
2020-08-21B_PO_08222020EX.docdoc e58f047fe04cae788a4aecc9507bf22d1c090e44f2181a4d57f2d7c5d7535f75Virustotal results 32.76%Heodo
2020-08-21V_NHK_080120_XEH_082220.docdoc b2306568f439c9bb88412afa55d141605046cb3775f8fcb124d3695ca2d70d68Virustotal results 32.76%Heodo
2020-08-21X_7165021134730.docdoc 656cc3eb3438badf2ad21a9aa6c6a7b35ef4279cc9469344dabb0878569757b3n/aHeodo
2020-08-21B_WC39W32.docdoc 3c81352c8209acf1d2f6a5cf507c64c492c720fc76a53a5fa83424c4e90603a7n/aHeodo
2020-08-21BAL_ONJ_080120_XMW_082220.docdoc 7bce0d97de6cec75813a540c08e2d525272f48d346ed73c9c776125fbe166cb4n/aHeodo
2020-08-21INV_47159737.docdoc f916381df1861ea591a02695d5c3c47c0f322c985d141897e6b8da198a94c718Virustotal results 32.76%Heodo
2020-08-21FILE_90895656469899593555100.docdoc 6a83ed449dd2b7d39a4f6460c27a4b834b4b2d620d9336fda16a828f29336f8fVirustotal results 25.42%Heodo
2020-08-21REP_LZ3S8X2U4Z22.docdoc 48b6551e86b81eed2eee275cf1d833e44580745dc6f578ee3fe8c139e0c205d7n/aHeodo
2020-08-21AJ_LN6529005902TN.docdoc 4515983abea28fd6da7bd8991a47916f0a226647eae1305d1aa554af62144d8cn/aHeodo
2020-08-21ILW_080120_NKN_082120.docdoc 53f0d7676b1c0fc626262382eb82665ba178ba84fd2afbf658e5acb5996a5a7eVirustotal results 22.41%Heodo
2020-08-21BAL_EAI_080120_TPE_082120.docdoc b9867ead986e6afb8337409a0b509cac26e3d383deb83f38f1cfcde8eaf3ab01n/aHeodo