URLhaus Database

You are currently viewing the URLhaus database entry for http://dujua.ind.br/antigo/public/5465/RDbMJv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:443973
URL: http://dujua.ind.br/antigo/public/5465/RDbMJv/
URL Status:Offline
Host: dujua.ind.br
Date added:2020-08-25 21:43:09 UTC
Last online:2020-08-26 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-25 21:44:05 UTC to abuse{at}hospedagem[dot]net)
Takedown time:15 hours, 44 minutes Good (down since 2020-08-26 13:28:16 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-26Invoice #0652.docdoc 726851d13c68bded8ced4904841817ce37f6bde1a4921825deeba3fe687e78b9Virustotal results 28.07%Heodo
2020-08-26Payment.docdoc d5c549eee018841e8c99ea2b6fdb5d625863689a0758458bed6ce909cf5e3e28Virustotal results 30.51%Heodo
2020-08-26Payment.docdoc 56cd053d222934a2bbdb1eab5e5569773d827f68e41571d46e6edeeb7fc10058n/aHeodo
2020-08-26V135 invoicing.docdoc dd2484c23d966107f9a26cf3adf938cfb0cd6178dd2d7f7bb6885cfc35177828Virustotal results 31.03%Heodo
2020-08-26Invoice.docdoc a653ed7fc7b44191a6e35885e211f29497f5a16fe3bf716c6ee745cbe315614dVirustotal results 29.82%Heodo
2020-08-26Invoice 0077664.docdoc b7dac0948c8280e5a66995fda2abb63e73fe0ebe41c4a3f10ca736d9558e9cbdn/aHeodo
2020-08-26invoices 98951 & 17569.docdoc 7b4347c2ddd660563142667857fe50faea6e8a1bd78a81dc2ab502e5b286cc44n/aHeodo
2020-08-26Invoice.docdoc dc6646ccdc79497c62390c8411eac6291fcf522ee18a3bc6d05d142c75ad30ben/aHeodo
2020-08-26Copy invoice #4445.docdoc 4f28bcb0c2d54cffc2810fbd3d3e10b0d2dbc20e043c476526947e9e7e7ee7c8Virustotal results 30.00%Heodo
2020-08-26Payment status.docdoc edf042c7f48eeca9b83d2f316eaa34a7274b386a0ace0c3dd4a97227852a64cdVirustotal results 31.58%Heodo
2020-08-26Invoice #882902371.docdoc cd6816d2aa0cf74845a993d21eeaee85e28d9480bd6c1322d7880b0640bd8248Virustotal results 30.51%Heodo
2020-08-26PO# 08262020.docdoc 012064617c3b69bcf41076e01a3ae44346db3ef00153e7f114c0850e7863324dVirustotal results 31.03%Heodo
2020-08-26Payment status.docdoc e9017cc8b425ecc8518bb34458a30045dcd446e2ace97b4e0209d0ac3a13de53Virustotal results 31.03%Heodo
2020-08-26Invoice #00060301.docdoc 391b29bbfeca47bf67b0fc05596c5c478efe548b39e530b8cb8d32b3f4ae6df9Virustotal results 31.58%Heodo
2020-08-26Inv. 083277578.docdoc da31dd9726bc4aff67976a72360ce783753f92f2036c0453ce46a0b7fdc99bb1n/aHeodo
2020-08-26P1619972755SM.docdoc 6e6592776210c618525c5b5caf06d29e8c25d2177b3f7dfd1a86deace9520dcdn/aHeodo
2020-08-26August Invoice.docdoc ad4c1465a9c3713992b6fd761417e5c47a9986ad08c70f4551ed239fc9376219Virustotal results 31.03%Heodo
2020-08-26INV_05949.docdoc 02b772df112f40ad435b9b0abba31d1918394f14f5cadf7cce0b73a1fca06053n/aHeodo
2020-08-26August Invoice.docdoc 43ea239dfae5a4b79c29b5ab2e18e6e2bb2456d1912663dbbf6762ab93a53694Virustotal results 31.03%Heodo
2020-08-26Form.docdoc d9501951fc4a9f05142eeb935e40f705bb839c1005a1a1beecfd7cb5ca5bd636n/aHeodo
2020-08-26Inv_495717.docdoc d897abf4abbb70845e61775f409d37276cf220d2a1974fba7eafe0415e89ed2cn/aHeodo
2020-08-26FY-080120 KVKH-082620.docdoc f1e8c8ed894dab23c0dc79fea7ede95c07d0db4022fae65dd650a7884fc165f4Virustotal results 31.03%Heodo
2020-08-25Payment.docdoc d9837b1903f0cc74cedf8b2bc7a74da61ae878ce54cfd439816af5919b5e846fVirustotal results 31.03%Heodo
2020-08-25O00144 invoicing.docdoc 5caf6a0047706e0e584daa8e6a31c7e7ab30bebf4be51d8aa72f9629794a8386Virustotal results 31.03%Heodo
2020-08-25Invoice.docdoc 787e426fa820bdeb365b0848eb4416fae5e3e15969c0931509f88db6f8724d4eVirustotal results 31.03%Heodo
2020-08-25Form - Aug 26, 2020.docdoc c3cc0dfb5610c9471dbd5fb17ab32ac8717a152d218db675e89fe5929c91442cVirustotal results 31.03%Heodo
2020-08-25Inv_06455.docdoc 481687ed49cd8f8a3d87484048c7ef7ed5398b4bbfce5dc0d8afd8c86d0b67e1Virustotal results 42.37% Heodo
2020-08-25Inv. 55519297.docdoc d20011bcfb209e6b0f23255c75907a43cd4cf4bb1a007736331854d8d5bb8abcn/aHeodo
2020-08-25form.docdoc 5266fb5179fc40c9b032f6b38213aa59dbbe2df76ab0a3ebb44bfccbb2d0d997Virustotal results 43.10%Heodo